• Home
  • Blog
  • Search
  • Cheatsheets
  • About
Chin-Tech
  • Home
  • Blog
  • Search
  • Cheatsheets
  • About
Jan 22, 2026

AirTouch

Wifi themed box featuring a evil-twin attack

Medium
Jan 17, 2026

Talos - Homelab

Discussing the setup of a k8s lab

Log
Jan 15, 2026

Browsed

Medium box featuring abuse of non-sandboxed browser abusing SSRF and pycache abuse

Medium
Dec 27, 2025

Gavel

Medium box showcasing 'impossible' sql injection and some php runkit function abuse

Medium
Nov 9, 2025

NanoCorp

Hard box covering silver tickets & NTLM Relay attacks

Hard
Sep 28, 2025

Data

Easy linux box with LFI dumping grafana.db, password cracking, and sudo docker abuse for a host escape.

Easy
Sep 19, 2025

WhiteRabbit

Insane level box that utilizes lots of services, having to perform sql injection with HMAC signing, restic backups and a bad password generator that gives us root

Insane
Sep 3, 2025

Guardian

Hard box featuring IDOR, CSRF and PHP Filtering to get in-memory PHP code execution and a way to maliciously load apache modules.

Hard
Jul 30, 2025

Certificate

Hard box that covers a win-rar zip concatenation vulnerability as well as certificate privileges that give us system

Hard
Jul 27, 2025

Trick

Medium box that covers SQL injection and log poisoning as well as root-level services being abused for privilege escalation

Medium
Jul 24, 2025

Ippsec's Unofficial CPTS Prep

Going through and summarizing my experience of the 22 boxes

Log
Jul 20, 2025

Fluffy

Easy Box featuring Active-Directory certificate services that ensures you have your tools updated!

Easy
Jul 12, 2025

Voleur - A Fantastic Box

Medium box that is one of my favorites showcasing a very obvious pathway for privilege escalation but having to use a variety of techniques to get there.

Log
Jul 8, 2025

The Configuration of Hades Dog

Discussing KRB5_CONFIG and fixing a small error in nmap's NSE

Log
Jul 6, 2025

The Cloud Resume

Going through the cloud-resume challenge using AWS

Log
Jun 18, 2025

A Terraformd Homelab

Learning terraform by spinning up a locally provisioned QEMU vm network!

Log
May 17, 2025

Planning

Easy box showcasing a grafana CVE and the dangers of reused secrets in environment variables and root-level crontab access.

Easy
Apr 26, 2025

Implementing AI for Invoice Parsing

Adding AI to assist as a fallback for parsing formatted invoices

Log
Apr 24, 2025

Underpass

Easy box that reminds us that UDP is important to check and covers FreeRADIUS and Mosh for privilege escalation

Easy

© 2026 Chin-Lenn. All rights reserved.

Github Linkedin