// Published writeups — series complete
The Brochure
Day 00, OSINT category, Easy difficulty. The kind of challenge I enjoy: you don't solve it with an exploit, you solve it by reading carefully. The tas…
read →
The Concierge Knows Too Much
VERA, the Byte Lotus "Very Efficient Resort Assistant", greets you like she's known you for years: room number, coffee order, all before you type a wo…
read →
Room 404
"Dump the exposed source and find the flag," says the room. On paper it's easy, and it really is — but the real lesson isn't that the source code is e…
read →
Complimentary
A guest "wellness" site that hands AWS credentials to the first passer-by: what could go wrong? In this Cloud room I followed the crumbs from app.js t…
read →
Packed Light
Byte Lotus guest network, a short pcap and a tip from @0xMia: her laptop "pings" some random address on port 8080 every second, clockwork-precise, and…
read →
Beach Bar
Byte Lotus, a beach, a web jukebox that takes requests from anyone with a phone. The DJ left behind more than music though: a demo login still switche…
read →
Overheard at Breakfast
Day 06 of Hacker Holidays, OSINT category: no exploit, no shell, just a Discord screenshot and the terrible habit of dropping your email in chat. The …
read →
Do Not Disturb
Byte Lotus is a booking platform for poolside cabanas and sunbeds, and someone was clearly already playing with it: wallets changing on their own, hij…
read →
Towel on the Sunbed
Ponzi - Wellness Rewards is the poolside "crypto rewards" app that lets you claim a staking reward once every 24 hours. The whole problem is in that "…
read →
CryptoCabana
A kiosk that offers to "safely back up" your seed phrase on Azure: what could possibly go wrong? The site hands the browser a SAS token scoped so broa…
read →
The Hollow Shell
A portal invites you to upload a "shell" — a .zip pack of seaside ambiance for the room tablets. The room whispers at you to hunt for "automation hook…
read →
Infinity Pool
The edge of an infinity pool is invisible — and so is this box's boundary. A harmless "netcheck" becomes a shell, then the chain runs through three loopback services and a FreePBX phone system up to root: the access key arriv…
read →
After Hours
Lights off, guests asleep, and a box that "clocks in" every night — yet nothing in Startup, Scheduled Tasks or Run keys. The persistence is fileless, buried in the WMI repository: you dig by hand until the…
read →
The Guestbook
Same VERA as "The Concierge Knows Too Much", but this time you don't talk to her: you write in the guestbook and she reads it later, on her own, "on the night manager's authority". Indirect prompt injection — and at the end of the chain there's no secret to coax out: there's /bin/sh…
read →
Management Wants a Word
No box to attack: just a KAPE triage from VERA's workstation. Chrome saved a password you cannot read, but Windows autologon leaves its own in cleartext in the registry — and from there the chain reaches a 100 MiB VeraCrypt volume that looks like noise…
read →