Everything, in order.
Posts, projects, CTFs, certifications and work, newest first.
2026
-
Carribean: Spectronas CTF 2026 B2R
The Caribbean B2R machine involves anonymous FTP enumeration, steganography, web directory discovery, cookie manipulation, and file upload exploitation to gain a shell. SSH keys recovered from an encrypted ZIP provide user access. Privilege escalation is achieved through a tar wildcard injection vulnerability in a custom backup script, leading to root access and the final flag.
-
Amongus: Spectronas CTF 2026 B2R
A complete walkthrough of the Amongus B2R machine, covering SMB and FTP enumeration, virtual host discovery, PHP Local File Inclusion (LFI), writable NFS exploitation for initial access, SSH credential discovery, and privilege escalation to root using PwnKit (CVE-2021-4034).
-
Spectronas CTF: Round 1
Cleared the full challenge set before the event ended. Writeups to follow.
-
Nexus: HTB Walkthrough
A penetration test of the Nexus HTB machine, covering port scanning, virtual host enumeration, credential discovery through a Gitea instance, and initial access via a vulnerable Krayin CRM installation. Privilege escalation to root was achieved by exploiting a path traversal weakness in a root-owned Gitea template synchronization service, allowing an SSH public key to be written to root's `authorized_keys` file.
-
H&L Labs
Hands-on web challenges with hints, solution and mitigation write-ups, and flag submission.
-
Honeypot Threat Dashboard
Cowrie honeypot on AWS EC2 feeding a dashboard of live attacker activity, including HASSH fingerprints.
-
VulnMart
An intentionally vulnerable Flask e-commerce app for pentest practice, covering the OWASP Top 10.
-
Hack With Jolu 2026
Organised the CTF and authored challenges for it.
-
Cybersecurity Analyst at Trinetlayer
Vulnerability assessment and penetration testing for client applications.
-
Implementing Repeating-key XOR cipher
Implementing a repeating-key XOR cipher in Python: a Cryptopals Set 1 Challenge 5 writeup covering XOR basics, strings and a full implementation.
-
Basic Pentesting 1 Walkthrough
Basic Pentesting 1 boot2root walkthrough: Nmap recon, exploiting a vulnerable FTP service with Metasploit, and web enumeration with Gobuster.
2025
-
Blue TryHackMe Walkthrough
TryHackMe Blue walkthrough: scanning a Windows 7 host with Nmap, confirming MS17-010 (EternalBlue) and gaining a Meterpreter session with Metasploit.
-
NetSec Challenge TryHackMe Walkthrough
TryHackMe NetSec Challenge walkthrough: using Nmap to find open ports, service versions and hidden services on a target host.
- Google Cybersecurity Professional Certificate
- TryHackMe Jr Pentester
- Tools of the Trade: Linux and SQL
- TryHackMe Pre Security
2024
-
QR Code Creator
A web application that generates QR codes for any text or URL you provide.
-
Started B.Tech in Computer Science and Engineering
Jalpaiguri Government Engineering College, 2024–2028.
-
Password Manager
A simple local password manager built with Python.
-
Simon Game
A browser-based Simon game built with HTML, CSS and JavaScript.
Nothing of that type yet.