Hack The Box - DarkZero Machine Write-up
這台 Machine 真的挺難的,光是拿 user flag 就花了我不少時間。官方難度定在 Hard 非常合理。
Discover a mix of what I’m into right now: web‑security write‑ups, proof‑of‑concept hacks, VFX projects I’m tinkering with, and the occasional late‑night ramble about news, tech, or whatever else pops into my head.
CheN.. space $ curl -i https://samchen.blog/etc/passwd
HTTP/2 200 accept‑ranges: bytes access‑control‑allow‑origin: * age: 8964 content-type: text/html; charset=utf-8 date: Sun, 04 Jun 1989 00:06:04 GMT server: Vercel
<!DOCTYPE html>
<html>
<head></head>
<body>
<!-- The Biggest Secret -->
</body>
</html>
Swipe the slider to see my VFX tweaks, then check out my latest exploit
write‑ups and what I’m learning along the way.
Whether you’re a researcher or company seeking guidance, let’s build safer systems together.
這台 Machine 真的挺難的,光是拿 user flag 就花了我不少時間。官方難度定在 Hard 非常合理。
打完這台 Machine 的唯一感想是有時候事情真的就是你想的這麼簡單,不要掉入兔子洞的陷阱裡。
不要看這台 Machine 是 Insane 就被嚇到,其實根本沒這麼誇張。思路、步驟繁多是真的,但打完回來整理攻擊鏈會發現每一步都不會到太難。
這台機器官方評級為 Medium,但個人感覺整體算是中偏易。發現 SQL Injection 注入點後面給的提示都很明顯。
Sense 也是一台很簡單的機器,有做好枚舉很快就可以找到利用點。
Got my first bounty when I was 18.(This write‑up is still in progress…)
待更新,文章還沒寫......
其實 Shocker 算是 HTB 裡面蠻簡單的 Machine,只要仔細觀察與枚舉,很容易就可以找到突破口。
待更新,文章還沒寫......
靈感源自於本人暑假即將年滿18歲,想先預約報名機車駕照考試。
Hi, I’m CheN.., an 18‑year‑old Taiwanese student passionate about web security. In my free time, my focus is on vulnerability discovery and document the path from bug to fix. I also explore VFX—mainly compositing—and enjoy recreating iconic scenes from films and games. New to the security scene, I’m driven by curiosity and committed to growing my expertise.
This website is maintained solely by me.
For issues or collaboration on vulnerability research, reach me at
samchen6666969@gmail.com