Hack The Box - Layover
An RDP foothold leads through plaintext wireless credentials, Craft CMS authenticated RCE, application-secret recovery, internal SSH, and a CUPS local privilege escalation to root.
╔════════════════════════════════════════╗
║ TERMINAL TROUBLE - HTB WRITEUPS ║
║ > root@kali:~# cat /root/flag.txt ║
╚════════════════════════════════════════╝
46 writeups
An RDP foothold leads through plaintext wireless credentials, Craft CMS authenticated RCE, application-secret recovery, internal SSH, and a CUPS local privilege escalation to root.
Pre-auth Java deserialization in OpenAM (CVE-2026-33439) yields a shell as the service account, a GLPI-stored LDAP bind secret decrypts to a password the desktop user reuses, and a sudo rdiff-backup wildcard with a parser quirk mirrors /root.
DanglingTree (Windows/AD): CVE-2026-23760 turns the loopback-only SmarterMail API into RCE as svc_mail, DPAPI from the Credential Manager hides a second account, and a deleted ESC1 certificate template is recreated all the way to a Domain Admin certificate and root.txt.
Easy Linux chain: SSRF filter checks hostname strings instead of addresses - decimal loopback opens the internal port map, /status leaks the notebook vhost, marimo's unauthenticated /terminal/ws (CVE-2026-39987) gives the shell, PackageKit TOCTOU (CVE-2026-41651) the root.
PDF upload meets pdfminer.six pickle RCE (CVE-2025-64512): CMap path injection gives a shell in the container, a Vite dev server with path traversal leaks the developer SSH key, and a NOPASSWD trainer with torch.load turns into a root shell.
Second-order SQLi with FILE privilege, an AppArmor hat that only forbids exec, Cobbler-XMLRPC as root on loopback: CVE-2024-47533 plus Cheetah-SSTI turns it into root RCE.
Double-forest AD chain with a Linux edge host: Handlebars AST injection (CVE-2026-33937) turns into RCE, a Gitea preinstall hook runs as svc-runner, a planted AD user root gets ksu to uid 0, DCSync and a golden ticket with SID history cross the forest trust, until PtH ends on the Hyper-V host.
RODC-focused AD chain: time-sync drift detection, RODC password PRP enumeration, writable-attribute abuse on the RODC account, key list and trust account rebuild, a group-managed account escape, and a SID history trick at the end.
Medium AD chain on Server 2025: supplied creds plus faketime for the 7h-skewed DC, a Deleted-Object restore grants a second user, a malicious VSIX (CVE-2025-55319) gives user shell, BadSuccessor (CVE-2025-53779) takes over svc_deploy, and VMkatz on a backup-share snapshot extracts Administrator.
CentOS 7 / FreePBX 16.0.40.7: unauthenticated web RCE through the admin app, a DB error chain, an asterisk webshell, a wired user-flag drop, a lock artifact in the DAG, and at the end it hands root the box too.
AWS-style lab chain: SSRF blocklist bypass to a fake IMDS, STS and SQS message injection, unsafe yaml.load in the worker for RCE, a privileged CodeBuild container, and a core_pattern host escape at the end.
WordPress 7.0: stored XSS via the audio transcription pipeline creates an admin-bot user, the plugin editor becomes a webshell, wp-config creds get SSH as walter, and the local OCR service runs as root, with password reuse again tying the whole chain together.
Three service layers, three jumps: the unauth MCP Inspector (6274) spawns stdio processes, the Jupyter start command leaks its token, and the OpsMCP server running as root hands out id_rsa via ops._admin_dump, ending with SSH login as root.
Hand-written RFC-1179 print daemon: the LPD job name injects via shell=True into the echo line, JetDirect/PJL traversal plants an SSH key as archivist, an SCM_RIGHTS fd leak from the root daemon reads admin_pins.conf, and password reuse lands root here.
Hidden MLflow vhost with default creds: model registry poisoning via model_code_path gives RCE as svcweb, the sudo Python tool extends its search via site.addsitedir() to group-writable plugin dirs, and a .pth hijack gets root.
Easy chain through two hidden vhosts: Flowise auth bypass (CVE-2025-58434) to container RCE, password reuse from container to host user ben, and Gogs symlink RCE (CVE-2025-8110) on the root-run Gogs service yields the root shell.
Medium Linux chain: a public Langflow flow_id opens an unauth build endpoint running an attacker Component as www-data; the .env password reuses to SSH as nightfall; the MCP registry accepts alg=none admin JWTs; and kubelet exec into a host-mounted node-exporter reads /host/root/root.txt.
Easy Linux box: CVE-2026-38526 turns a CRM installer's AJAX-only middleware check into an unauthenticated admin overwrite, a TinyMCE upload drops a webshell, the .env password reuses to jones over SSH, and a root systemd timer joining git ls-tree names unsanitized writes an authorized_keys to /root.
Easy Linux replica of the old HTB platform: the invite code is one API call, a hidden PUT /admin/settings/update self-assigns is_admin from the body, the VPN generator takes a username command injection, and the leaked .env password reuses to SSH before the kernel falls to CVE-2023-0386.
Insane Linux hosting portal: .htaccess ErrorDocument overrides become an arbitrary file read, leaked web-environment credentials rehash into an SSH login as uid 666, and a cron-checked Apache config lets a confcheck script drop setuid-root bash for the root flag.
Insane Windows AD chain: ASP template injection in a hosted page gives SYSTEM inside a container, a Responder hash cracks to localadmin, a malicious Jamovi file rides an SMB share to host shell, and a writable Web certificate template is the ESC1/ESC4 bridge to Domain Admin.
Insane Windows box: an SMB dev share leaks an encrypted TeamCity build file whose timestamp field decrypts a KeePass key, admin remote-run twists into RCE as svc_teamcity, reused credentials climb to e.black, and an ADCS ESC1 template signs the way to Domain Admin.
Insane Windows university chain: an xhtml2pdf file:/ write becomes a shell as the reviewer account, forged professor certificates and a CVE-2023-36025 .url shortcut cross the next trust boundary, and relay to RBCD plus a gMSA read ends with Domain Admin and the DC flag.
Easy Linux VulnLab box: an exposed LimeSurvey installer accepts an attacker-controlled MariaDB and hands over admin access, a malicious plugin upload is RCE inside the container, and a host-mounted env variable plus a setuid-drop pivot from the container lands a host root shell.
Medium Linux chain on openSUSE: CVE-2025-49132 turns the Pterodactyl panel's locale endpoint into an LFI that reads database credentials and writes a PHP shell via pearcmd, then CVE-2025-6018/6019 forge an active seat and ride udisks into a SUID-root bash.
Hard Linux chain: CVE-2026-27944 in Nginx UI's unauthenticated /api/backup leaks its AES key and IV in a response header; the decrypted SQLite cracks to an SSH login, and a snap-confine TOCTOU race (CVE-2026-3888) drops a SUID-root shell.
Easy Linux XWiki 15.10.8 chain: CVE-2025-24893 Groovy injection through the SolrSearch RSS feed gives code execution as the service user, a reused datasource password drops SSH as oliver, and Netdata's SUID ndsudo resolving nvme through a caller-controlled PATH (CVE-2024-32019) finishes as root.
Easy Linux dashboard with an IDOR in its packet-capture feature: the capture downloader takes a global counter ID with no ownership check, leaking a plaintext FTP login that reuses to SSH; file capabilities on python3.8 turn a setuid interpreter into a root shell via os.setuid(0).
Insane CentOS tour of sandbox escapes: executable-stack overflow in the custom auth daemon, an NFS export without squash promoting nobody to frank, an rvim :py escape to adm, and Wiener's attack on a small-d RSA key turning the stolen root SSH public key into a root login.
Insane Windows chain: OAuth2 CSRF makes the admin bot bind an attacker identity, a DLL rides the article banner through SQLite load_extension() to RCE as web, Edge DPAPI leaks Olivia.KAT's WinRM password, and an AppDomainManager injection in the auto-restarted Failure2Ban service lands SYSTEM.
OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.
HTB's QTT terminal teleports the flag one qubit per round with QuTiP but delegates the feed-forward correction to us and prints the Bell-measurement bits — send the Pauli correction back and read the teleported state.
5-qubit quantum circuit challenge: GHZ entanglement and anti-correlation to forge a valid hyperlink across 256 simulation shots.
Bypass a 75-byte nginx body limit and a 1000-character palindrome check by abusing JavaScript type coercion between string length comparison and Array() construction.
Unauthenticated RCE via CVE-2025-55182 (React2Shell) — prototype pollution in the React Server Components Flight protocol deserializer on Next.js 16.0.6.
Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.
Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.
Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.
Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.
ESP32 firmware reverse engineering: the XOR-0x42 flag blob in DROM is located and decoded via literal-pool cross-referencing and Xtensa disassembly, no emulation needed.
Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.
A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.
Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.
A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.
A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.
An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.