45 writeups

> Filter Writeups

Machines Hack The Box Locked

Hack The Box - Management

Pre-auth Java deserialization in OpenAM (CVE-2026-33439) yields a shell as the service account, a GLPI-stored LDAP bind secret decrypts to a password the desktop user reuses, and a sudo rdiff-backup wildcard with a parser quirk mirrors /root.

Linux Medium #cve-2026-33439 #deserialization #glpi #java #openam #opendj #rdiff-backup #sudo 4 views · 2026-09-27
Machines Hack The Box Locked

Hack The Box - DanglingTree

DanglingTree (Windows/AD): CVE-2026-23760 turns the loopback-only SmarterMail API into RCE as svc_mail, DPAPI from the Credential Manager hides a second account, and a deleted ESC1 certificate template is recreated all the way to a Domain Admin certificate and root.txt.

Windows Medium #active-directory #adcs #cve-2026-23760 #cve-2026-26119 #dpapi #esc1 #hackthebox #windows 4 views · 2026-09-27
Machines Hack The Box Locked

Hack The Box - Cohort

Easy Linux chain: SSRF filter checks hostname strings instead of addresses - decimal loopback opens the internal port map, /status leaks the notebook vhost, marimo's unauthenticated /terminal/ws (CVE-2026-39987) gives the shell, PackageKit TOCTOU (CVE-2026-41651) the root.

Linux Easy #easy #hackthebox #linux #ssrf #web 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - Bedside

PDF upload meets pdfminer.six pickle RCE (CVE-2025-64512): CMap path injection gives a shell in the container, a Vite dev server with path traversal leaks the developer SSH key, and a NOPASSWD trainer with torch.load turns into a root shell.

Linux Medium #cve-2025-31125 #cve-2025-64512 #path-traversal #pdfminer #pickle #sudo #torch #vite 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - Cobblestone

Second-order SQLi with FILE privilege, an AppArmor hat that only forbids exec, Cobbler-XMLRPC as root on loopback: CVE-2024-47533 plus Cheetah-SSTI turns it into root RCE.

Linux Insane #apparmor #cobbler #hackthebox #insane #linux #sqli #ssti 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - DarkZeroReturns

Double-forest AD chain with a Linux edge host: Handlebars AST injection (CVE-2026-33937) turns into RCE, a Gitea preinstall hook runs as svc-runner, a planted AD user root gets ksu to uid 0, DCSync and a golden ticket with SID history cross the forest trust, until PtH ends on the Hyper-V host.

Windows Hard #active-directory #hackthebox #hard #kerberos #windows 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Garfield

RODC-focused AD chain: time-sync drift detection, RODC password PRP enumeration, writable-attribute abuse on the RODC account, key list and trust account rebuild, a group-managed account escape, and a SID history trick at the end.

Windows Hard #active-directory #hackthebox #hard #rodc #windows 9 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Checkpoint

Medium AD chain on Server 2025: supplied creds plus faketime for the 7h-skewed DC, a Deleted-Object restore grants a second user, a malicious VSIX (CVE-2025-55319) gives user shell, BadSuccessor (CVE-2025-53779) takes over svc_deploy, and VMkatz on a backup-share snapshot extracts Administrator.

Windows Medium #active-directory #hackthebox #medium #windows 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Connected

CentOS 7 / FreePBX 16.0.40.7: unauthenticated web RCE through the admin app, a DB error chain, an asterisk webshell, a wired user-flag drop, a lock artifact in the DAG, and at the end it hands root the box too.

Linux Medium #asterisk #freepbx #hackthebox #linux #medium 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Nimbus

AWS-style lab chain: SSRF blocklist bypass to a fake IMDS, STS and SQS message injection, unsafe yaml.load in the worker for RCE, a privileged CodeBuild container, and a core_pattern host escape at the end.

Linux Medium #aws #hackthebox #linux #medium #ssrf #yaml 15 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - MakeSense

WordPress 7.0: stored XSS via the audio transcription pipeline creates an admin-bot user, the plugin editor becomes a webshell, wp-config creds get SSH as walter, and the local OCR service runs as root, with password reuse again tying the whole chain together.

Linux Medium #hackthebox #linux #medium #wordpress #xss 11 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - DevHub

Three service layers, three jumps: the unauth MCP Inspector (6274) spawns stdio processes, the Jupyter start command leaks its token, and the OpsMCP server running as root hands out id_rsa via ops._admin_dump, ending with SSH login as root.

Linux Medium #hackthebox #jupyter #linux #mcp #medium 12 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Paperwork

Hand-written RFC-1179 print daemon: the LPD job name injects via shell=True into the echo line, JetDirect/PJL traversal plants an SSH key as archivist, an SCM_RIGHTS fd leak from the root daemon reads admin_pins.conf, and password reuse lands root here.

Linux Easy #easy #hackthebox #linux #lpd #scm-rights 17 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - SmartHire

Hidden MLflow vhost with default creds: model registry poisoning via model_code_path gives RCE as svcweb, the sudo Python tool extends its search via site.addsitedir() to group-writable plugin dirs, and a .pth hijack gets root.

Linux Medium #hackthebox #linux #medium #mlflow #python 19 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Silentium

Easy chain through two hidden vhosts: Flowise auth bypass (CVE-2025-58434) to container RCE, password reuse from container to host user ben, and Gogs symlink RCE (CVE-2025-8110) on the root-run Gogs service yields the root shell.

Linux Easy #easy #flowise #gogs #hackthebox #linux 15 views · 2026-09-08
Machines Hack The Box

Hack The Box - Fireflow

Medium Linux chain: a public Langflow flow_id opens an unauth build endpoint running an attacker Component as www-data; the .env password reuses to SSH as nightfall; the MCP registry accepts alg=none admin JWTs; and kubelet exec into a host-mounted node-exporter reads /host/root/root.txt.

Linux Medium #hackthebox #jwt #kubernetes #langflow #linux #mcp #medium 479 views · 2026-09-08
Machines Hack The Box

Hack The Box - Nexus

Easy Linux box: CVE-2026-38526 turns a CRM installer's AJAX-only middleware check into an unauthenticated admin overwrite, a TinyMCE upload drops a webshell, the .env password reuses to jones over SSH, and a root systemd timer joining git ls-tree names unsanitized writes an authorized_keys to /root.

Linux Easy #easy #gitea #hackthebox #krayin #laravel #linux #traversal 424 views · 2026-09-08
Machines Hack The Box

Hack The Box - TwoMillion

Easy Linux replica of the old HTB platform: the invite code is one API call, a hidden PUT /admin/settings/update self-assigns is_admin from the body, the VPN generator takes a username command injection, and the leaked .env password reuses to SSH before the kernel falls to CVE-2023-0386.

Linux Easy #command-injection #cve-2023-0386 #easy #hackthebox #linux #mass-assignment #overlayfs 429 views · 2026-09-08
Machines Hack The Box

Hack The Box - Zero

Insane Linux hosting portal: .htaccess ErrorDocument overrides become an arbitrary file read, leaked web-environment credentials rehash into an SSH login as uid 666, and a cron-checked Apache config lets a confcheck script drop setuid-root bash for the root flag.

Linux Insane #hackthebox #htaccess #insane #linux #setuid #sftp 565 views · 2026-09-08
Machines Hack The Box

Hack The Box - Anubis

Insane Windows AD chain: ASP template injection in a hosted page gives SYSTEM inside a container, a Responder hash cracks to localadmin, a malicious Jamovi file rides an SMB share to host shell, and a writable Web certificate template is the ESC1/ESC4 bridge to Domain Admin.

Windows Insane #active-directory #adcs #esc1 #esc4 #hackthebox #insane #jamovi #windows 531 views · 2026-09-08
Machines Hack The Box

Hack The Box - Coder

Insane Windows box: an SMB dev share leaks an encrypted TeamCity build file whose timestamp field decrypts a KeePass key, admin remote-run twists into RCE as svc_teamcity, reused credentials climb to e.black, and an ADCS ESC1 template signs the way to Domain Admin.

Windows Insane #adcs #esc1 #hackthebox #insane #keepass #teamcity #windows 696 views · 2026-09-08
Machines Hack The Box

Hack The Box - University

Insane Windows university chain: an xhtml2pdf file:/ write becomes a shell as the reviewer account, forged professor certificates and a CVE-2023-36025 .url shortcut cross the next trust boundary, and relay to RBCD plus a gMSA read ends with Domain Admin and the DC flag.

Windows Insane #active-directory #adcs #gmsa #hackthebox #insane #s4u #windows 638 views · 2026-09-08
Machines Hack The Box

Hack The Box - Forgotten

Easy Linux VulnLab box: an exposed LimeSurvey installer accepts an attacker-controlled MariaDB and hands over admin access, a malicious plugin upload is RCE inside the container, and a host-mounted env variable plus a setuid-drop pivot from the container lands a host root shell.

Linux Easy #docker #easy #hackthebox #limesurvey #linux #sudo 520 views · 2026-09-08
Machines Hack The Box

Hack The Box - Pterodactyl

Medium Linux chain on openSUSE: CVE-2025-49132 turns the Pterodactyl panel's locale endpoint into an LFI that reads database credentials and writes a PHP shell via pearcmd, then CVE-2025-6018/6019 forge an active seat and ride udisks into a SUID-root bash.

Linux Medium #hackthebox #linux #medium #opensuse #polkit #pterodactyl #udisks 596 views · 2026-09-08
Machines Hack The Box

Hack The Box - Snapped

Hard Linux chain: CVE-2026-27944 in Nginx UI's unauthenticated /api/backup leaks its AES key and IV in a response header; the decrypted SQLite cracks to an SSH login, and a snap-confine TOCTOU race (CVE-2026-3888) drops a SUID-root shell.

Linux Hard #hackthebox #hard #linux #nginx-ui #race-condition #snapd #toctou 538 views · 2026-09-08
Machines Hack The Box

Hack The Box - Editor

Easy Linux XWiki 15.10.8 chain: CVE-2025-24893 Groovy injection through the SolrSearch RSS feed gives code execution as the service user, a reused datasource password drops SSH as oliver, and Netdata's SUID ndsudo resolving nvme through a caller-controlled PATH (CVE-2024-32019) finishes as root.

Linux Easy #easy #groovy #hackthebox #linux #ndsudo #netdata #xwiki 470 views · 2026-09-08
Machines Hack The Box

Hack The Box - Cap

Easy Linux dashboard with an IDOR in its packet-capture feature: the capture downloader takes a global counter ID with no ownership check, leaking a plaintext FTP login that reuses to SSH; file capabilities on python3.8 turn a setuid interpreter into a root shell via os.setuid(0).

Linux Easy #capabilities #easy #hackthebox #idor #linux #pcap 310 views · 2026-09-08
Machines Hack The Box

Hack The Box - Jail

Insane CentOS tour of sandbox escapes: executable-stack overflow in the custom auth daemon, an NFS export without squash promoting nobody to frank, an rvim :py escape to adm, and Wiener's attack on a small-d RSA key turning the stolen root SSH public key into a root login.

Linux Insane #buffer-overflow #hackthebox #insane #linux #nfs #rsa #rvim #wiener 523 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Eloquia

Insane Windows chain: OAuth2 CSRF makes the admin bot bind an attacker identity, a DLL rides the article banner through SQLite load_extension() to RCE as web, Edge DPAPI leaks Olivia.KAT's WinRM password, and an AppDomainManager injection in the auto-restarted Failure2Ban service lands SYSTEM.

Windows Insane #appdomainmanager #dpapi #hackthebox #insane #oauth #windows 7 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - The Puppet Master

OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.

OSINT Easy #challenge #hackthebox #osint #trainee 2 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - Flagportation

HTB's QTT terminal teleports the flag one qubit per round with QuTiP but delegates the feed-forward correction to us and prints the Bell-measurement bits — send the Pauli correction back and read the teleported state.

Quantum Very Easy #ctf #easy #hackthebox #misc #quantum #qutip #teleportation 7 views · 2026-09-07
Challenges Hack The Box Locked

Hack The Box - Global Hyperlink Zone

5-qubit quantum circuit challenge: GHZ entanglement and anti-correlation to forge a valid hyperlink across 256 simulation shots.

Quantum Very Easy #circuit #entanglement #hackthebox #qiskit #quantum 2 views · 2026-09-07
Challenges Locked

Hack The Box - Magical Palindrome

Bypass a 75-byte nginx body limit and a 1000-character palindrome check by abusing JavaScript type coercion between string length comparison and Array() construction.

Web Very Easy #challenge #hackthebox #javascript #type-coercion #web 3 views · 2026-09-07
Challenges Locked

Hack The Box - ReactOOPS

Unauthenticated RCE via CVE-2025-55182 (React2Shell) — prototype pollution in the React Server Components Flight protocol deserializer on Next.js 16.0.6.

Web Very Easy #cve #hackthebox #nextjs #prototype-pollution #rce #react #web 5 views · 2026-09-07
Challenges Locked

Hack The Box - EncoDecept

Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.

Web Medium #cache-poisoning #deserialization #hackthebox #medium #orm-injection #university-ctf-2024 #web #xss 3 views · 2026-09-06
Challenges Locked

Hack The Box - Ether Tag

Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.

ICS Very Easy #challenges #cip #ethernet-ip #hackthebox #ics #scada 3 views · 2026-09-06
Challenges Locked

Hack The Box - OpenSecret

Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.

Web Very Easy #hackthebox #holme #jwt #web 2 views · 2026-09-06
Challenges Locked

Hack The Box - Lucky Dice

Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.

Misc Very Easy #automation #hackthebox #misc #parsing #python 6 views · 2026-09-06
Challenges Locked

Hack The Box - Espresso

ESP32 firmware reverse engineering: the XOR-0x42 flag blob in DROM is located and decoded via literal-pool cross-referencing and Xtensa disassembly, no emulation needed.

Hardware Very Easy #easy #esp32 #firmware #hackthebox #hardware #reverse-engineering 4 views · 2026-09-06
Challenges Locked

Hack The Box - Flag Command

Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.

Web Very Easy #api-enumeration #easy #hackthebox #source-code-analysis #web 4 views · 2026-09-06
Challenges Locked

Hack The Box - SpookyPass

A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.

Reversing Very Easy #easy #hackthebox #reversing 3 views · 2026-09-06
Machines

Hack The Box - Pirate

Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.

#active-directory #hackthebox #hard #windows 603 views · 2026-09-05
Challenges Hack The Box Locked

Hack The Box - Baby Frame

A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.

Satellite Very Easy #ccsds #challenge #hack the box #misc #space packet protocol #tc space data link 7 views · 2026-09-04
Machines Hack The Box

Hack The Box - Legacy

A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.

Windows Easy #ctf #hack the box #walkthrough #legacy 1335 views · 2024-12-27
Machines Hack The Box

Hack The Box - Lame

An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.

Linux Easy #ctf #hack the box #walkthrough #samba 1367 views · 2024-12-17