Sagnik Ghosh
/ TIMELINE

Everything, in order.

Posts, projects, CTFs, certifications and work, newest first.

2026

  1. POST Oct 9, 2026 · 8 min read
    Carribean: Spectronas CTF 2026 B2R

    The Caribbean B2R machine involves anonymous FTP enumeration, steganography, web directory discovery, cookie manipulation, and file upload exploitation to gain a shell. SSH keys recovered from an encrypted ZIP provide user access. Privilege escalation is achieved through a tar wildcard injection vulnerability in a custom backup script, leading to root access and the final flag.

  2. POST Oct 8, 2026 · 18 min read
    Amongus: Spectronas CTF 2026 B2R

    A complete walkthrough of the Amongus B2R machine, covering SMB and FTP enumeration, virtual host discovery, PHP Local File Inclusion (LFI), writable NFS exploitation for initial access, SSH credential discovery, and privilege escalation to root using PwnKit (CVE-2021-4034).

  3. CTF Oct 4–7, 2026
    Spectronas CTF: Round 1

    Cleared the full challenge set before the event ended. Writeups to follow.

  4. POST Jul 31, 2026 · 14 min read
    Nexus: HTB Walkthrough

    A penetration test of the Nexus HTB machine, covering port scanning, virtual host enumeration, credential discovery through a Gitea instance, and initial access via a vulnerable Krayin CRM installation. Privilege escalation to root was achieved by exploiting a path traversal weakness in a root-owned Gitea template synchronization service, allowing an SSH public key to be written to root's `authorized_keys` file.

  5. PROJECT 2026
    H&L Labs

    Hands-on web challenges with hints, solution and mitigation write-ups, and flag submission.

  6. PROJECT 2026
    Honeypot Threat Dashboard

    Cowrie honeypot on AWS EC2 feeding a dashboard of live attacker activity, including HASSH fingerprints.

  7. PROJECT 2026
    VulnMart

    An intentionally vulnerable Flask e-commerce app for pentest practice, covering the OWASP Top 10.

  8. CTF July 2026
    Hack With Jolu 2026

    Organised the CTF and authored challenges for it.

  9. WORK July - September 2026
    Cybersecurity Analyst at Trinetlayer

    Vulnerability assessment and penetration testing for client applications.

  10. POST Apr 3, 2026 · 2 min read
    Implementing Repeating-key XOR cipher

    Implementing a repeating-key XOR cipher in Python: a Cryptopals Set 1 Challenge 5 writeup covering XOR basics, strings and a full implementation.

  11. POST Mar 24, 2026 · 4 min read
    Basic Pentesting 1 Walkthrough

    Basic Pentesting 1 boot2root walkthrough: Nmap recon, exploiting a vulnerable FTP service with Metasploit, and web enumeration with Gobuster.

2025

  1. POST Oct 21, 2025 · 5 min read
    Blue TryHackMe Walkthrough

    TryHackMe Blue walkthrough: scanning a Windows 7 host with Nmap, confirming MS17-010 (EternalBlue) and gaining a Meterpreter session with Metasploit.

  2. POST Oct 21, 2025 · 4 min read
    NetSec Challenge TryHackMe Walkthrough

    TryHackMe NetSec Challenge walkthrough: using Nmap to find open ports, service versions and hidden services on a target host.

  3. CERT Oct 11, 2025
    Google Cybersecurity Professional Certificate
  4. CERT Sep 21, 2025
    TryHackMe Jr Pentester
  5. CERT Aug 20, 2025
    Tools of the Trade: Linux and SQL
  6. CERT Jul 7, 2025
    TryHackMe Pre Security

2024

  1. PROJECT Sep 26, 2024
    QR Code Creator

    A web application that generates QR codes for any text or URL you provide.

  2. EDUCATION 2024
    Started B.Tech in Computer Science and Engineering

    Jalpaiguri Government Engineering College, 2024–2028.

  3. PROJECT Jun 1, 2024
    Password Manager

    A simple local password manager built with Python.

  4. PROJECT Feb 20, 2024
    Simon Game

    A browser-based Simon game built with HTML, CSS and JavaScript.