# ElnurBDa > Elnur Badalov's personal blog. I hack, automate and self-host, and I write about security, Linux and infrastructure. Written by Elnur Badalov. Hands-on notes rather than documentation: what was run, what it returned, and what it meant. Reuse is welcome under CC BY 4.0, which means attribution is expected, so please cite the page URL. ## Articles - [The AI Becomes the "I"](https://elnurbda.com/posts/65-ai-becomes-i.md): An essay on AI shifting the 'I' leftward: its effect on IT careers, society, and why Asimov's science fiction is becoming reality. - [The way I do productivity](https://elnurbda.com/posts/64-productivity.md): How I organize my life for productivity - note-taking, todos, a calendar, a diary, plain-text accounting, and Linux. - [HashiCorp Certified: Vault Associate (003) Review](https://elnurbda.com/posts/63-hcvao.md): HashiCorp Certified: Vault Associate (003) exam review - how I studied, which resources worked, and what the exam itself is like. - [Ledger CLI: Plain Text Accounting](https://elnurbda.com/posts/62-ledger-cli.md): Why I log every transaction in one plain text file with Ledger CLI: double-entry basics, the account tree, multi-currency metals and stocks, daily queries. - [A NixOS Control Plane and OpenBao in HA](https://elnurbda.com/posts/61-nixos-openbao-ha.md): Build a declarative NixOS control plane that deploys a fleet over SSH, then run OpenBao on it - single node first, then a raft HA cluster. - [HashiCorp Vault Lab: Auto-unseal, LDAP Auth, and Team Policies](https://elnurbda.com/posts/60-vault-autounseal-ldap.md): HashiCorp Vault auto-unseal (Azure HSM + Transit), LDAP auth mapped to team policies, and a KV v2 ACL design - a hands-on three-VM lab. - [Secret Management with OpenBao and GitLab CI/CD](https://elnurbda.com/posts/59-openbao-gitlab.md): Five ways to get secrets into a deployed app with GitLab CI and OpenBao (Vault), from plain .env files to JWT/AppRole auth, a Vault Agent on the host, and live SDK fetches, plus the full self-hosted GitLab and OpenBao setup. - [Certified Kubernetes Administrator (CKA) Review](https://elnurbda.com/posts/58-cka.md): An honest CKA exam review covering what it really takes to pass - from hands-on lab practice to the resources and mindset that actually make the difference. - [Access Kubernetes NodePort Services with Subdomains](https://elnurbda.com/posts/46-k8s-nodeport-subdomain.md): Expose Kubernetes NodePort services via subdomains using wildcard DNS and NGINX, without an Ingress controller. - [Presenterm](https://elnurbda.com/posts/45-presenterm.md): Why I like Presenterm for tech talks: write slides in Markdown, keep them in git, get code highlighting, diagrams and images, and present everything directly from the terminal. - [01 - a GNU Core Utility - ls](https://elnurbda.com/posts/44-gnu-ls.md): Master the Linux ls command with this complete guide covering basic to advanced options, hidden features, and modern alternatives to boost your terminal productivity. - [Pentest Tools TLDR](https://elnurbda.com/posts/33-pentest-tools-tldr.md): In this post, there will be a set of **TLDR**s (too long; didn't read) for categorized Penetration Testing tools. - [Настройка Компонентов Обеспечения Информационной Безопасности](https://elnurbda.com/posts/42-it-planeta-task.md): В этом отчете изложены все шаги по настройке Компонентов Обеспечения Информационной Безопасности. Это задание было одним из этапов сореванования по Кибербезопасности на платформе "IT PLANETA". - [Deploy a Free Self-Hosted Gist Website on GCP’s e2-micro using Cloudflared](https://elnurbda.com/posts/40-e2-micro-cloudflared.md): Set up a free GCP e2-micro VM to host a self-hosted Gist with Opengist, secured via Cloudflare Tunnel — no cost, no open ports, fully controlled by you. - [Certified Red Team Operator (CRTO) Review](https://elnurbda.com/posts/38-crto.md): Short review of the Certified Red Team Operator certification: course quality, lab environment, exam format and the AD/red teaming skills I realistically gained from it. - [Setup ELK and monitor App's Logs](https://elnurbda.com/posts/36-app-log-es.md): How I wired a simple blog app’s logs into Elasticsearch: quick ELK + Nginx setup and a Winston + winston-elasticsearch logger inside a TypeScript ElysiaJS/Bun backend. - [SSH Certificate Authentication](https://elnurbda.com/posts/31-ssh-cert-auth.md): Minimal SSH certificate authentication lab: three Docker containers (CA, client, server) where we create a CA key, sign a user key and test SSH logins with certificates. - [High Available ELK Stack](https://elnurbda.com/posts/26-high-available-elk.md): Guest post by Telman: detailed walkthrough for building a highly available ELK stack on GCP with three Elasticsearch nodes, Logstash, Kibana and Filebeat sending logs. - [Ngrok Use Cases](https://elnurbda.com/posts/25-ngrok-use-cases.md): Ngrok examples I actually use: exposing local web servers, getting reverse shells, pivoting with chisel, bypassing restrictions and quickly sharing demos with others. - [Certified Professional Penetration Tester (eCPPTv3) Review](https://elnurbda.com/posts/19-ecpptv3.md): Honest eCPPTv3 review: what the exam looks like, why I failed the first attempt, how I fixed my prep with AD labs, and whether I recommend spending money on it now. - [Good Google Dorks](https://elnurbda.com/posts/13-good-google-dorks.md): A small set of Google dorks I actually reuse: for CTFs, tech events, startup slides, coupons and giveaways—mostly tuned for .az but easy to adapt to other countries. - [Named Pipe](https://elnurbda.com/posts/12-named-pipe.md): Short explanation of named pipes (FIFOs) on Linux and how they differ from regular pipes, plus a small netcat example that turns them into a simple bidirectional TCP proxy. - [Every Developer Should Know](https://elnurbda.com/posts/11-every-dev-aware.md): Short list of free technologies and perks every developer or IT person should know: GitHub Student Pack, cloud credits, free domains and a few ways I actually used them. - [React Cheat Sheet](https://elnurbda.com/posts/09-react-cheat-sheet.md): React cheat sheet made from my notes: hooks, small snippets for data fetching, routing, Redux, Supabase and React Native so I can quickly recall patterns I use in projects. - [PTArch](https://elnurbda.com/posts/08-ptarch.md): PTArch: my Arch-based pentesting environment. Starting from a plain VM, I add Budgie, terminal tweaks and a hand-picked toolset to get a lighter Kali-style lab. - [Linux Capabilities and PrivEsc](https://elnurbda.com/posts/05-linux-capabilities-privesc.md): How Linux capabilities work in practice and how a misconfigured capability (CAP_SYS_ADMIN, CAP_DAC_READ_SEARCH, etc.) can lead to local privilege escalation, with hands-on examples. - [Cinema Server - Jellyfin](https://elnurbda.com/posts/02-cinema-server.md): Run your own Jellyfin cinema server: start it with Docker, mount your media, add nginx as a reverse proxy and stream movies from a simple self-hosted setup. - [Setup Arch Linux as a Virtual Machine](https://elnurbda.com/posts/01-arch-linux-vm.md): Step-by-step guide to installing Arch Linux as a VMware virtual machine: simple UEFI setup, partitioning, base system, SSH access, user creation, and basic GUI. - [Alternative way to run Windows VM on Linux (Docker)](https://elnurbda.com/posts/03-windows-on-docker.md): Alternative way to run Windows on Linux: use Docker with a Windows image, web UI and RDP support instead of heavy VMs, and get a smoother desktop experience. ## CTF write-ups - [PG • CTF • Jacko • Write-Up](https://elnurbda.com/posts/57-pg-ctf-jacko.md): Proving Grounds CTF - Jacko. H2 database misconfiguration, RCE, and DLL hijacking in PaperStream IP. - [PG • CTF • Internal • Write-Up](https://elnurbda.com/posts/56-pg-ctf-internal.md): Proving Grounds Internal write-up: very old Windows Server 2008 box where we find SMBv2 CVE-2009-3103 with nmap and use Metasploit to pop a SYSTEM meterpreter. - [PG • CTF • DVR4 • Write-Up](https://elnurbda.com/posts/55-pg-ctf-dvr4.md): Proving Grounds DVR4 write-up: use Argus DVR path traversal to steal SSH keys and flags, then break its weak password encryption to log in as Administrator on the host. - [PG • CTF • Authby • Write-Up](https://elnurbda.com/posts/54-pg-ctf-authby.md): Proving Grounds CTF - Authby. Anonymous FTP, credential deduction, and MS11-046 privilege escalation. - [PG • CTF • Algernon • Write-Up](https://elnurbda.com/posts/53-pg-ctf-algernon.md): Proving Grounds Algernon write-up: exploit the SmarterMail Build 6985 RCE bug on port 9998 to get a SYSTEM shell on Windows with almost no extra steps. - [PG • CTF • Vault • Write-Up](https://elnurbda.com/posts/52-pg-ctf-vault.md): Proving Grounds Vault write-up: drop a malicious URL/SCF file into a writable SMB share, capture a domain user hash, get a WinRM shell and abuse SeRestorePrivilege with Utilman. - [PG • CTF • Resourced • Write-Up](https://elnurbda.com/posts/51-pg-ctf-resourced.md): Proving Grounds Resourced: domain recon, password spraying, dumping LSA secrets, and abusing Resource-Based Constrained Delegation (RBCD) to compromise the host. - [PG • CTF • Nagoya • Write-Up](https://elnurbda.com/posts/50-pg-ctf-nagoya.md): Proving Grounds Nagoya: SMB and MSSQL enumeration, Kerberoasting a service account, forging a Silver Ticket, and abusing impersonation tokens to land SYSTEM. - [PG • CTF • Hutch • Write-Up](https://elnurbda.com/posts/49-pg-ctf-hutch.md): Proving Grounds Hutch write-up: from LDAP user discovery to abusing WebDAV uploads for ASPX RCE, and finally using LAPS to read back the local Administrator password. - [PG • CTF • Heist • Write-Up](https://elnurbda.com/posts/48-pg-ctf-heist.md): Proving Grounds Heist write-up: turn a URL feature into SSRF, capture an NTLMv2 hash with Responder, abuse a gMSA password reader and finish with SeRestorePrivilege. - [PG • CTF • Access • Write-Up](https://elnurbda.com/posts/47-pg-ctf-access.md): Proving Grounds CTF - Access. File upload vulnerability, Kerberoasting, and SeManageVolumePrivilege abuse. - [HTB • CTF • Administrator • Write-Up](https://elnurbda.com/posts/41-htb-ctf-administrator.md): Hack The Box Administrator: chain BloodHound-discovered ACL abuses (GenericAll → ForceChangePassword → GenericWrite) into DCSync, then crack the recovered Password Safe vault. - [HTB • CTF • EscapeTwo • Write-Up](https://elnurbda.com/posts/39-htb-ctf-escapetwo.md): Hack The Box EscapeTwo: MSSQL `xp_cmdshell` foothold, plaintext creds in config files, ESC4 certificate abuse, and a WriteOwner ACL chain to Domain Admin. - [HTB • CTF • Cicada • Write-Up](https://elnurbda.com/posts/37-htb-ctf-cicada.md): Hack The Box CTF - Cicada. SMB shares, password spraying, RID brute-forcing, PrivEsc via Token Abuse - [HTB • CTF • Chemistry • Write-Up](https://elnurbda.com/posts/35-htb-ctf-chemistry.md): Hack The Box CTF - Chemistry. Pymatgen CIF parser RCE, Credentials from SQLite database, Python aiohttp app vulnerable to path traversal (CVE-2024-23334). - [Mr. Windoclin - ICSD2024](https://elnurbda.com/posts/32-icsd-mr-windoclin.md): Mr. Windoclin — Challenge №12 from the ICSD 2024 'Who am I' CTF. Walkthrough of the Windows-themed challenge I authored, with the intended solution path. - [HTB • CTF • MonitorsThree • Write-Up](https://elnurbda.com/posts/30-htb-ctf-monitorsthree.md): Hack The Box MonitorsThree: error-based SQLi to admin, Cacti RCE for foothold, Duplicati auth bypass, and a Docker volume misconfiguration to escape to root. - [HTB • CTF • Sea • Write-Up](https://elnurbda.com/posts/27-htb-ctf-sea.md): Hack The Box Sea write-up: use XSS to get RCE in WonderCMS, pivot into a user shell, then abuse a log-viewer LFI behind HTTP Basic auth to read /root/root.txt directly. - [HTB • CTF • Resource • Write-Up](https://elnurbda.com/posts/24-htb-ctf-resource.md): Hack The Box Resource write-up: PHAR-based ZIP upload to get RCE, MySQL creds from the app, secrets in a HAR file, and SSH certificates to move from containers to the host. - [HTB • CTF • Lantern • Write-Up](https://elnurbda.com/posts/29-htb-ctf-lantern.md): Hack The Box CTF - Lantern. SSRF, DLL Information Disclosure, File Upload Vulnerability, Execution of malicious DLL, PrivEsc with write process monitoring. - [HTB • CTF • Editorial • Write-Up](https://elnurbda.com/posts/23-htb-ctf-editorial.md): Hack The Box Editorial write-up: turn the upload + URL feature into SSRF, grab internal API credentials, then abuse a Git history leak and a Python clone helper to get root. - [HTB • CTF • Sauna • Write-Up](https://elnurbda.com/posts/22-htb-ctf-sauna.md): Hack The Box Sauna write-up: AS-REP roast fsmith, steal Autologon credentials for svc_loanmgr, then use DCSync and pass-the-hash to become Domain Admin. - [HTB • CTF • Active • Write-Up](https://elnurbda.com/posts/21-htb-ctf-active.md): Hack The Box Active write-up: use a GPP password in Groups.xml to get SVC_TGS, Kerberoast Administrator’s SPN and then pass the ticket to log in as Domain Admin. - [HTB • CTF • Forest • Write-Up](https://elnurbda.com/posts/20-htb-ctf-forest.md): Hack The Box Forest write-up: AS-REP roasting to get svc-alfresco, BloodHound to spot a DCSync path, and ACL abuse to dump Domain Admin credentials with secretsdump. - [HTB • CTF • WifineticTwo • Write-Up](https://elnurbda.com/posts/17-htb-ctf-wifinetictwo.md): Hack The Box WifineticTwo write-up: exploit WPS with OneShot to get Wi‑Fi access, pivot into the OpenWrt router and use chisel + proxychains to reach the internal flag. - [HTB • CTF • PermX • Write-Up](https://elnurbda.com/posts/18-htb-ctf-permx.md): Hack The Box PermX write-up: exploit Chamilo CVE-2023-4220, pivot with MySQL creds and password reuse, then abuse a symbolic-link based ACL helper for a clean root. - [HTB • CTF • BoardLight • Write-Up](https://elnurbda.com/posts/16-htb-ctf-boardlight.md): Hack The Box CTF - BoardLight. Subdomain fuzzing, Exploiting Dolibarr 17.0.0, password reuse and suid privesc (CVE-2022-37706). - [HTB • CTF • GreenHorn • Write-Up](https://elnurbda.com/posts/15-htb-ctf-greenhorn.md): Hack The Box GreenHorn write-up: from Gitea repo leaks and Pluck CMS RCE to deblurring a password in a PDF and reusing it to become root on the box. - [HTB • CTF • SolarLab • Write-Up](https://elnurbda.com/posts/14-htb-ctf-solarlab.md): Hack The Box SolarLab write-up: abuse a ReportLab PDF generator for RCE, pivot into Openfire, recover the admin password and use it to finish with full domain compromise. - [THM Buffer Overflow Rooms Write-Up: Brainpan 1 and Gatekeeper](https://elnurbda.com/posts/10-thm-ctf-buffer-overflow.md): Write-ups for the TryHackMe rooms Brainpan 1 and Gatekeeper, focusing on classic Windows buffer overflows: offsets, bad chars, shellcode and finishing with SYSTEM access. - [Pentester's Notes](https://elnurbda.com/posts/07-pentester-notes.md): My penetration testing cheat sheet: commands and one-liners I actually use for recon, web, SMB/RDP, Linux and Windows privesc, brute forcing and shell stabilization. - [HTB • CTF • Crafty • Write-Up](https://elnurbda.com/posts/06-htb-ctf-crafty.md): Hack The Box Crafty write-up: recon, identifying a Minecraft server, abusing Log4Shell for RCE, then reversing a plugin and using RunasCs to finish privesc on Windows. - [Tryhackme Write-up Collection](https://elnurbda.com/posts/04-thm-ctf-writeups.md): 20 TryHackMe CTF write-ups based on my own notes, mostly medium to hard rooms, focused on practical enumeration, exploitation steps and privilege escalation ideas. ## FAQ - [Which certification write-ups are on this blog?](https://elnurbda.com/faq/cert-reviews-on-blog/): Links to personal reviews of CKA, eCPPTv3, and CRTO—prep and honest takes, not official exam material. - [How can I reach you?](https://elnurbda.com/faq/how-to-contact/): Social and professional links for the author of ElnurBDa. - [How can I follow new posts?](https://elnurbda.com/faq/how-to-follow-updates/): Use the RSS feed or check the Articles and CTF listing pages for everything new. - [I found a mistake in a post. How do I tell you?](https://elnurbda.com/faq/report-mistake-in-post/): Reach out on GitHub or LinkedIn with the post URL and what should change. - [Can I reuse or cite your posts?](https://elnurbda.com/faq/reuse-and-license/): Licensing and attribution for ElnurBDa content. - [Where are CTF write-ups listed?](https://elnurbda.com/faq/where-are-ctf-writeups/): Machine walkthroughs and lab notes live on a dedicated CTF hub, separate from general articles. - [Who is ElnurBDa?](https://elnurbda.com/faq/who-is-elnurbda/): ElnurBDa is this site and brand; the author is Elnur Badalov—a technologist writing about security, Linux, web dev, and labs. ## Optional - [About the author](https://elnurbda.com/about/) - [All articles](https://elnurbda.com/posts/) - [All CTF write-ups](https://elnurbda.com/posts/ctf/) - [RSS feed](https://elnurbda.com/rss.xml)