43 writeups

> Filter Writeups

Machines Hack The Box Locked

Hack The Box - Cohort

Easy-Linux-Kette: ein SSRF-Filter prüft Hostname-Strings statt Adressen — dezimale Loopback-Schreibweise öffnet die interne Portkarte, /status verrät den Notebook-Vhost, marimos /terminal/ws ohne Auth (CVE-2026-39987) gibt die Shell, PackageKit-TOCTOU (CVE-2026-41651) den Root.

Linux Easy #easy #hackthebox #linux #ssrf #web 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - Bedside

PDF-Upload trifft pdfminer.six Pickle-RCE (CVE-2025-64512): CMap-Path-Injection gibt eine Shell im Container, ein Vite-Dev-Server mit Path Traversal den Developer-SSH-Key — und ein NOPASSWD-Trainer mit torch.load wird zur Root-Shell.

Linux Medium #cve-2025-31125 #cve-2025-64512 #path-traversal #pdfminer #pickle #sudo #torch #vite 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - Cobblestone

Second-order SQLi mit FILE-Privileg, eine AppArmor-Hut die nur exec verbietet, Cobbler-XMLRPC als root auf loopback: CVE-2024-47533 plus Cheetah-SSTI macht daraus Root-RCE.

Linux Insane #apparmor #cobbler #hackthebox #insane #linux #sqli #ssti 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - DarkZeroReturns

Doppel-Forest-AD-Kette mit Edge-Linux: Handlebars-AST-Injection (CVE-2026-33937) wird zur RCE, ein Gitea-Preinstall-Hook Exec-svc-runner, ein gepflanzter AD-User root bringt ksu zu uid 0, DCSync und Golden Ticket mit SID-History überqueren den Forest-Trust, bis PtH am Hyper-V-Host endet.

Windows Hard #active-directory #hackthebox #hard #kerberos #windows 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Garfield

RodC-fokussierte AD-Kette: Zeit-Sync-Drift-Erkennung, RODC-Password-PRP-Enum, writable-Attribute-Abuse am RODC-Konto, Key-List und Trust-Account-Rebuild, ein Group-Managed-Konto-Escape und ein SID-History-Trick am Ende.

Windows Hard #active-directory #hackthebox #hard #rodc #windows 9 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Checkpoint

Medium-AD-Kette auf Server 2025: eigener Sysvol-Drop wird per alter GPO-Registry-Artefakt-Kette zur RCE, destruktive Objekte werden über LAPS-Rotation recycelt, und ein Push-Restore am ADCS-End beholden kein Cert-Pinning, bis der Admin-Rotations-Loop zum Root-Zwilling wird.

Windows Medium #active-directory #hackthebox #medium #windows 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Connected

CentOS 7 / FreePBX 16.0.40.7: unauthentifizierte Web-RCE über die Admin-App, Dysfun-DB-Fehlerkette, Asterisk-Recorder-Shell, ein verdrahteter Ansage-Usertropfen und ein DisplayManager-Lockartefakt, das am Ende auch root das Mikrofon reicht.

Linux Medium #asterisk #freepbx #hackthebox #linux #medium 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Nimbus

AWS-ähnliche Lab-Kette: SSRF über die Blacklist zur Fake-IMDS, STS- und SQS-Nachrichtenbündel, unsichere yaml.load im Worker zur RCE, ein privilegierter CodeBuild-Container und ein core_pattern-Host-Escape am Ende.

Linux Medium #aws #hackthebox #linux #medium #ssrf #yaml 15 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - MakeSense

WordPress 7.0: Stored-XSS über die Audio-Transkriptions-Pipeline erzeugt einen Admin-Bot-Nutzer, der Plugin-Editor wird zur Webshell, wp-config-Creds reichen zur SSH als walter, und der lokale OCR-Dienst läuft als root — bis auch hier eine Passwort-Wiederverwendung endet.

Linux Medium #hackthebox #linux #medium #wordpress #xss 11 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - DevHub

Drei Service-Schichten, drei Sprünge: unauth MCP Inspector (6274) spawnt stdio-Prozesse, der Jupyter-Startbefehl leakt seinen Token, und der OpsMCP-Server als root enthüllt über ops._admin_dump den id_rsa, bis der SSH-Login als root endet.

Linux Medium #hackthebox #jupyter #linux #mcp #medium 12 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Paperwork

Hand-geschriebener RFC-1179-Druckdämon: Der LPD-Jobname spritzt per shell=True in die echo-Zeile, JetDirect/PJL-Traversal pflanzt einen SSH-Schlüssel als archivist, ein SCM_RIGHTS-FD-Leak des root-Dämons liest admin_pins.conf — Password-Reuse hired hier root.

Linux Easy #easy #hackthebox #linux #lpd #scm-rights 17 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - SmartHire

Versteckter MLflow-Vhost mit Default-Creds: Model-Registry-Poisoning via model_code_path wird zur RCE als svcweb, das sudo-Python-Tool erweitert die Suche via site.addsitedir() auf gruppenbeschreibbare Plugin-Verzeichnisse, und ein .pth-Hijack führt zu root.

Linux Medium #hackthebox #linux #medium #mlflow #python 19 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Silentium

Easy-Kette über zwei versteckte VHosts: Flowise-Auth-Bypass (CVE-2025-58434) zur Container-RCE, Password-Reuse von Container zu Host-Ben ben, und Gogs-Symlink-RCE (CVE-2025-8110) als root-Service liefert die Root-Shell.

Linux Easy #easy #flowise #gogs #hackthebox #linux 15 views · 2026-09-08
Machines Hack The Box

Hack The Box - Fireflow

Medium Linux chain: a public Langflow flow_id opens an unauthenticated build endpoint running an attacker Component as www-data; the .env password reuses to SSH as nightfall; the MCP registry in its home accepts alg=none admin JWTs; and a kubelet exec into a host-mounted node-exporter reads the

Linux Medium #hackthebox #jwt #kubernetes #langflow #linux #mcp #medium 32 views · 2026-09-08
Machines Hack The Box

Hack The Box - Nexus

Easy Linux box: CVE-2026-38526 turns a CRM installer's AJAX-only middleware check into an unauthenticated admin overwrite, a TinyMCE upload drops a webshell, the .env password reuses to jones over SSH, and a root systemd timer joining git ls-tree names unsanitized writes an authorized_keys to /root.

Linux Easy #easy #gitea #hackthebox #krayin #laravel #linux #traversal 64 views · 2026-09-08
Machines Hack The Box

Hack The Box - TwoMillion

Easy Linux replica of the old HTB platform: the invite code is one API call, a hidden PUT /admin/settings/update self-assigns is_admin from the body, the VPN generator takes a username command injection, and the leaked .env password reuses to SSH before the kernel falls to CVE-2023-0386.

Linux Easy #command-injection #cve-2023-0386 #easy #hackthebox #linux #mass-assignment #overlayfs 58 views · 2026-09-08
Machines Hack The Box

Hack The Box - Zero

Insane Linux hosting portal: .htaccess ErrorDocument overrides become an arbitrary file read, leaked web-environment credentials rehash into an SSH login as uid 666, and a cron-checked Apache config lets a confcheck script drop setuid-root bash for the root flag.

Linux Insane #hackthebox #htaccess #insane #linux #setuid #sftp 49 views · 2026-09-08
Machines Hack The Box

Hack The Box - Anubis

Insane Windows AD chain: ASP template injection in a hosted page gives SYSTEM inside a container, a Responder hash cracks to localadmin, a malicious Jamovi file rides an SMB share to host shell, and a writable Web certificate template is the ESC1/ESC4 bridge to Domain Admin.

Windows Insane #active-directory #adcs #esc1 #esc4 #hackthebox #insane #jamovi #windows 45 views · 2026-09-08
Machines Hack The Box

Hack The Box - Coder

Insane Windows box: an SMB dev share leaks an encrypted TeamCity build file whose timestamp field decrypts a KeePass key, admin remote-run twists into RCE as svc_teamcity, reused credentials climb to e.black, and an ADCS ESC1 template signs the way to Domain Admin.

Windows Insane #adcs #esc1 #hackthebox #insane #keepass #teamcity #windows 58 views · 2026-09-08
Machines Hack The Box

Hack The Box - University

Insane Windows university chain: an xhtml2pdf file:/ write becomes a shell as the reviewer account, forged professor certificates and a CVE-2023-36025 .url shortcut cross the next trust boundary, and relay to RBCD plus a gMSA read ends with Domain Admin and the DC flag.

Windows Insane #active-directory #adcs #gmsa #hackthebox #insane #s4u #windows 54 views · 2026-09-08
Machines Hack The Box

Hack The Box - Forgotten

Easy Linux VulnLab box: an exposed LimeSurvey installer accepts an attacker-controlled MariaDB and hands over admin access, a malicious plugin upload is RCE inside the container, and a host-mounted env variable plus a setuid-drop pivot from the container lands a host root shell.

Linux Easy #docker #easy #hackthebox #limesurvey #linux #sudo 38 views · 2026-09-08
Machines Hack The Box

Hack The Box - Pterodactyl

Medium Linux chain on openSUSE: CVE-2025-49132 turns the Pterodactyl panel's locale endpoint into an LFI that reads database credentials and writes a PHP shell via pearcmd, then CVE-2025-6018/6019 forge an active seat and ride udisks into a SUID-root bash.

Linux Medium #hackthebox #linux #medium #opensuse #polkit #pterodactyl #udisks 43 views · 2026-09-08
Machines Hack The Box

Hack The Box - Snapped

Hard Linux chain: CVE-2026-27944 in Nginx UI's unauthenticated /api/backup leaks its AES key and IV in a response header; the decrypted SQLite cracks to an SSH login, and a snap-confine TOCTOU race (CVE-2026-3888) drops a SUID-root shell.

Linux Hard #hackthebox #hard #linux #nginx-ui #race-condition #snapd #toctou 49 views · 2026-09-08
Machines Hack The Box

Hack The Box - Editor

Easy Linux XWiki 15.10.8 chain: CVE-2025-24893 Groovy injection through the SolrSearch RSS feed gives code execution as the service user, a reused datasource password drops SSH as oliver, and Netdata's SUID ndsudo resolving nvme through a caller-controlled PATH (CVE-2024-32019) finishes as root.

Linux Easy #easy #groovy #hackthebox #linux #ndsudo #netdata #xwiki 57 views · 2026-09-08
Machines Hack The Box

Hack The Box - Cap

Easy Linux dashboard with an IDOR in its packet-capture feature: the capture downloader takes a global counter ID with no ownership check, leaking a plaintext FTP login that reuses to SSH; file capabilities on python3.8 turn a setuid interpreter into a root shell via os.setuid(0).

Linux Easy #capabilities #easy #hackthebox #idor #linux #pcap 37 views · 2026-09-08
Machines Hack The Box

Hack The Box - Jail

Insane CentOS tour of sandbox escapes: executable-stack overflow in the custom auth daemon, an NFS export without squash promoting nobody to frank, an rvim :py escape to adm, and Wiener's attack on a small-d RSA key turning the stolen root SSH public key into a root login.

Linux Insane #buffer-overflow #hackthebox #insane #linux #nfs #rsa #rvim #wiener 62 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Eloquia

Insane Windows chain: OAuth2 CSRF makes the admin bot bind an attacker identity, a DLL rides the article banner through SQLite load_extension() to RCE as web, Edge DPAPI leaks Olivia.KAT's WinRM password, and an AppDomainManager injection in the auto-restarted Failure2Ban service lands SYSTEM.

Windows Insane #appdomainmanager #dpapi #hackthebox #insane #oauth #windows 7 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - The Puppet Master

OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.

OSINT Easy #challenge #hackthebox #osint #trainee 2 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - Flagportation

HTB's QTT terminal teleports the flag one qubit per round with QuTiP but delegates the feed-forward correction to us and prints the Bell-measurement bits — send the Pauli correction back and read the teleported state.

Quantum Very Easy #ctf #easy #hackthebox #misc #quantum #qutip #teleportation 7 views · 2026-09-07
Challenges Hack The Box Locked

Hack The Box - Global Hyperlink Zone

5-qubit quantum circuit challenge: GHZ entanglement and anti-correlation to forge a valid hyperlink across 256 simulation shots.

Quantum Very Easy #circuit #entanglement #hackthebox #qiskit #quantum 2 views · 2026-09-07
Challenges Locked

Hack The Box - Magical Palindrome

Bypass a 75-byte nginx body limit and a 1000-character palindrome check by abusing JavaScript type coercion between string length comparison and Array() construction.

Web Very Easy #challenge #hackthebox #javascript #type-coercion #web 3 views · 2026-09-07
Challenges Locked

Hack The Box - ReactOOPS

Unauthenticated RCE via CVE-2025-55182 (React2Shell) — prototype pollution in the React Server Components Flight protocol deserializer on Next.js 16.0.6.

Web Very Easy #cve #hackthebox #nextjs #prototype-pollution #rce #react #web 5 views · 2026-09-07
Challenges Locked

Hack The Box - EncoDecept

Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.

Web Medium #cache-poisoning #deserialization #hackthebox #medium #orm-injection #university-ctf-2024 #web #xss 3 views · 2026-09-06
Challenges Locked

Hack The Box - Ether Tag

Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.

ICS Very Easy #challenges #cip #ethernet-ip #hackthebox #ics #scada 3 views · 2026-09-06
Challenges Locked

Hack The Box - OpenSecret

Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.

Web Very Easy #hackthebox #holme #jwt #web 2 views · 2026-09-06
Challenges Locked

Hack The Box - Lucky Dice

Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.

Misc Very Easy #automation #hackthebox #misc #parsing #python 6 views · 2026-09-06
Challenges Locked

Hack The Box - Espresso

ESP32-Firmware-Reverse-Engineering: Der XOR-40h-Flag-Blob im DROM wird per Literal-Pool-Crossreference und Xtensa-Disassembly gefunden und dekodiert - ohne Emulation.

Hardware Very Easy #easy #esp32 #firmware #hackthebox #hardware #reverse-engineering 4 views · 2026-09-06
Challenges Locked

Hack The Box - Flag Command

Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.

Web Very Easy #api-enumeration #easy #hackthebox #source-code-analysis #web 4 views · 2026-09-06
Challenges Locked

HackTheBox - SpookyPass

A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.

Reversing Very Easy #easy #hackthebox #reversing 3 views · 2026-09-06
Machines

Hack The Box - Pirate

Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.

#active-directory #hackthebox #hard #windows 17 views · 2026-09-05
Challenges Hack The Box Locked

Hack The Box - Baby Frame

A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.

Satellite Very Easy #ccsds #challenge #hack the box #misc #space packet protocol #tc space data link 7 views · 2026-09-04
Machines Hack The Box

Hack The Box - Legacy

A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.

Windows Easy #ctf #hack the box #walkthrough #legacy 1065 views · 2024-12-27
Machines Hack The Box

Hack The Box - Lame

An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.

Linux Easy #ctf #hack the box #walkthrough #samba 1040 views · 2024-12-17