I just completed Room 404 room on TryHackMe! He booked the quiet room. It's not on the floor plan, not in the brochure, not on any door. But port 8080 is wide open, and the rooms it never lists are the ones worth finding. https://t.co/NtGSvq6AKv #tryhackme via @tryhackme
๐ Congratulations to @Byt3Ra1 , @TheCyberGuyZW and @_CyNjaX_
Don't forget to send us your email with the choice of exam at [email protected] so we can send you the exam link.
A round of applause for everyone who participated! ๐
Stay tuned for more opportunities and thanks to the incredible support from our community ๐๐
Cybersecurity isn't about making life harder...
It's about making it harder for Attackers!!
Be Cyber Safe. Be Cyber Smart
Protect your digital assets.
thecyberguyzwโ๏ธ
Nexus machine Unlocked #10
Join us for our next HTB Zimbabwe meetup as we explore Nexus, an easy Linux machine that showcases how seemingly small misconfigurations can be chained together into a full system compromise.
During this session, we'll discuss:
-Effective enumeration strategies
-Credential exposure and secrets management
-Web application security assessment
-Linux privilege escalation concepts
-Security lessons and defensive best practices
About Nexus
Nexus is an easy-difficulty Linux machine featuring an exposed Gitea repository that leaks credentials, alongside a job posting that reveals valid usernames. Those credentials provide access to a vulnerable Krayin CRM instance (CVE-2026-38526), illustrating how application vulnerabilities and exposed secrets can combine to expand access. Further enumeration uncovers additional credentials for SSH access, while a vulnerable Gitea template synchronization service demonstrates how directory traversal flaws can ultimately lead to root-level compromise.
Whether you're new to @hackthebox_eu or an experienced security professional, this meetup is a great opportunity to learn, share knowledge, and connect with Zimbabwe's growing cybersecurity community.
Date: 25 July 2025
Time: 16:00 CAT
Platform: Discord, on the Main-Stage. Check the link to the Discord in the comment section.
I hope to see you there. Another week, another machine to learn from.
https://t.co/O8DIR5MIri #Meetup via @Meetup
I completed the Web Security Academy lab:
User role can be modified in user profile:
I logged in using the provided credentials and navigated to my account page. After updating my email address, I intercepted the request and observed that the server's response contained several user attributes, including the username, email, apikey, and roleid. The presence of the roleid parameter suggested that it might be possible to manipulate the user's role.
I intercepted the request in Burp Suite and sent it to Repeater for further testing. To better observe the application's behavior, I also modified the URL in the browser from:
/my-account
to:
/my-account?roleid=2
After changing the roleid value to 2, the application treated my account as an administrator and displayed the Admin panel. This demonstrated that the application trusted a user-controlled parameter to determine authorization instead of enforcing role-based access controls on the server.
I then accessed the Admin panel, navigated to the Users section, and successfully deleted the carlos user account, confirming that administrative privileges had been obtained through parameter manipulation.
@WebSecAcademy
https://t.co/tgJMH9yxlN
โข๏ธ Reactor: Exploit the Core #9
Join the Hack The Box Zimbabwe community as we take on Reactor, an Easy Linux machine that explores modern web application security in the JavaScript ecosystem.
In this session, we'll analyze and exploit vulnerabilities involving JavaScript deserialization, investigate Node.js debugging misconfigurations, and walk through the attack path from initial access to privilege escalation. Along the way, we'll discuss practical detection strategies, secure development practices, and defensive techniques to help you recognize and mitigate similar issues in real-world environments.
RSVP: https://t.co/v5dZFUYsN3 #Meetup via @Meetup
I just completed SOC L2 Alert Triage room on TryHackMe! Learn how to triage escalated alerts and respond to cyber threats. https://t.co/A7AOgoKMlk #tryhackme via @tryhackme
Every community starts with a conversation, a shared passion, and people willing to show up.
Today, I'm grateful to have received the Hack The Box Meetups Ambassador Certification from @hackthebox_eu , a milestone that represents the journey of building and growing Hack The Box MeetUp Zimbabwe.
What has made this experience meaningful isn't the certification itself, but the opportunity to connect with cybersecurity enthusiasts, facilitate knowledge sharing, and watch our local community continue to grow with every meetup.
To everyone who has attended our events, presented a session, asked questions, volunteered, or supported us in any way thank you. Your passion and commitment are what make this community special.
A sincere thank you to Orestis-Konstantinos Fotou and Stella Vako for your continued support and for investing in cybersecurity communities around the world.
This recognition motivates me to keep creating spaces where we can learn, collaborate, and inspire...
The journey continues.
#HackTheBox #HackTheBoxMeetups #CyberSecurity #CommunityBuilding #Zimbabwe #InfoSec #ContinuousLearning
I just completed Grep room on TryHackMe! A challenge that tests your reconnaissance and OSINT skills. https://t.co/DF4V0yYZWy #tryhackme via @tryhackme
Todayโs session taught me that documentation is the backbone of any cybersecurity role. Itโs not just for getting certified itโs what helps you pick up where you left off and communicate clearly in a workspace.
I also learned that we should focus on truly understanding the work, not just chasing the CJCA certificate. The knowledge and experience matter more because thatโs what you rely on in real jobs.
It was a good reminder to take proper notes and write clear reports in every task.
HackTheBox Meetup Zimbabwe ๐ฟ๐ผ๐
Received "Part of 7M TryHackMe Users Club" mug today๐ฅน๐ค...
Getting the chance to work alongside @tryhackme as a small creator during Advent of Cyber 2025 was already something I'll never forget. Receiving this package makes it feel even more surreal.
Who would've thought?
@Bugcrowd Forecourt walkway of the TCL Chinese Theatre (historically known as Grauman's Chinese Theatre) located along the Hollywood Walk of Fame at 6925 Hollywood Boulevard in Los Angeles, California