30 writeups

> Filter Writeups

Machines Hack The Box Locked

Hack The Box - Fireflow

Medium Linux chain: a public Langflow flow_id opens an unauthenticated build endpoint running an attacker Component as www-data; the .env password reuses to SSH as nightfall; the MCP registry in its home accepts alg=none admin JWTs; and a kubelet exec into a host-mounted node-exporter reads the

Linux Medium #hackthebox #jwt #kubernetes #langflow #linux #mcp #medium 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Nexus

Easy Linux box: CVE-2026-38526 turns a CRM installer's AJAX-only middleware check into an unauthenticated admin overwrite, a TinyMCE upload drops a webshell, the .env password reuses to jones over SSH, and a root systemd timer joining git ls-tree names unsanitized writes an authorized_keys to /root.

Linux Easy #easy #gitea #hackthebox #krayin #laravel #linux #traversal 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - TwoMillion

Easy Linux replica of the old HTB platform: the invite code is one API call, a hidden PUT /admin/settings/update self-assigns is_admin from the body, the VPN generator takes a username command injection, and the leaked .env password reuses to SSH before the kernel falls to CVE-2023-0386.

Linux Easy #command-injection #cve-2023-0386 #easy #hackthebox #linux #mass-assignment #overlayfs 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Zero

Insane Linux hosting portal: .htaccess ErrorDocument overrides become an arbitrary file read, leaked web-environment credentials rehash into an SSH login as uid 666, and a cron-checked Apache config lets a confcheck script drop setuid-root bash for the root flag.

Linux Insane #hackthebox #htaccess #insane #linux #setuid #sftp 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Anubis

Insane Windows AD chain: ASP template injection in a hosted page gives SYSTEM inside a container, a Responder hash cracks to localadmin, a malicious Jamovi file rides an SMB share to host shell, and a writable Web certificate template is the ESC1/ESC4 bridge to Domain Admin.

Windows Insane #active-directory #adcs #esc1 #esc4 #hackthebox #insane #jamovi #windows 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Coder

Insane Windows box: an SMB dev share leaks an encrypted TeamCity build file whose timestamp field decrypts a KeePass key, admin remote-run twists into RCE as svc_teamcity, reused credentials climb to e.black, and an ADCS ESC1 template signs the way to Domain Admin.

Windows Insane #adcs #esc1 #hackthebox #insane #keepass #teamcity #windows 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - University

Insane Windows university chain: an xhtml2pdf file:/ write becomes a shell as the reviewer account, forged professor certificates and a CVE-2023-36025 .url shortcut cross the next trust boundary, and relay to RBCD plus a gMSA read ends with Domain Admin and the DC flag.

Windows Insane #active-directory #adcs #gmsa #hackthebox #insane #s4u #windows 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Forgotten

Easy Linux VulnLab box: an exposed LimeSurvey installer accepts an attacker-controlled MariaDB and hands over admin access, a malicious plugin upload is RCE inside the container, and a host-mounted env variable plus a setuid-drop pivot from the container lands a host root shell.

Linux Easy #docker #easy #hackthebox #limesurvey #linux #sudo 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Pterodactyl

Medium Linux chain on openSUSE: CVE-2025-49132 turns the Pterodactyl panel's locale endpoint into an LFI that reads database credentials and writes a PHP shell via pearcmd, then CVE-2025-6018/6019 forge an active seat and ride udisks into a SUID-root bash.

Linux Medium #hackthebox #linux #medium #opensuse #polkit #pterodactyl #udisks 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Snapped

Hard Linux chain: CVE-2026-27944 in Nginx UI's unauthenticated /api/backup leaks its AES key and IV in a response header; the decrypted SQLite cracks to an SSH login, and a snap-confine TOCTOU race (CVE-2026-3888) drops a SUID-root shell.

Linux Hard #hackthebox #hard #linux #nginx-ui #race-condition #snapd #toctou 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Editor

Easy Linux XWiki 15.10.8 chain: CVE-2025-24893 Groovy injection through the SolrSearch RSS feed gives code execution as the service user, a reused datasource password drops SSH as oliver, and Netdata's SUID ndsudo resolving nvme through a caller-controlled PATH (CVE-2024-32019) finishes as root.

Linux Easy #easy #groovy #hackthebox #linux #ndsudo #netdata #xwiki 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Cap

Easy Linux dashboard with an IDOR in its packet-capture feature: the capture downloader takes a global counter ID with no ownership check, leaking a plaintext FTP login that reuses to SSH; file capabilities on python3.8 turn a setuid interpreter into a root shell via os.setuid(0).

Linux Easy #capabilities #easy #hackthebox #idor #linux #pcap 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Jail

Insane CentOS tour of sandbox escapes: executable-stack overflow in the custom auth daemon, an NFS export without squash promoting nobody to frank, an rvim :py escape to adm, and Wiener's attack on a small-d RSA key turning the stolen root SSH public key into a root login.

Linux Insane #buffer-overflow #hackthebox #insane #linux #nfs #rsa #rvim #wiener 6 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Eloquia

Insane Windows chain: OAuth2 CSRF makes the admin bot bind an attacker identity, a DLL rides the article banner through SQLite load_extension() to RCE as web, Edge DPAPI leaks Olivia.KAT's WinRM password, and an AppDomainManager injection in the auto-restarted Failure2Ban service lands SYSTEM.

Windows Insane #appdomainmanager #dpapi #hackthebox #insane #oauth #windows 3 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - The Puppet Master

OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.

OSINT Easy #challenge #hackthebox #osint #trainee 2 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - Flagportation

HTB's QTT terminal teleports the flag one qubit per round with QuTiP but delegates the feed-forward correction to us and prints the Bell-measurement bits — send the Pauli correction back and read the teleported state.

Quantum Very Easy #ctf #easy #hackthebox #misc #quantum #qutip #teleportation 7 views · 2026-09-07
Challenges Hack The Box Locked

Hack The Box - Global Hyperlink Zone

5-qubit quantum circuit challenge: GHZ entanglement and anti-correlation to forge a valid hyperlink across 256 simulation shots.

Quantum Very Easy #circuit #entanglement #hackthebox #qiskit #quantum 2 views · 2026-09-07
Challenges Locked

Hack The Box - Magical Palindrome

Bypass a 75-byte nginx body limit and a 1000-character palindrome check by abusing JavaScript type coercion between string length comparison and Array() construction.

Web Very Easy #challenge #hackthebox #javascript #type-coercion #web 3 views · 2026-09-07
Challenges Locked

Hack The Box - ReactOOPS

Unauthenticated RCE via CVE-2025-55182 (React2Shell) — prototype pollution in the React Server Components Flight protocol deserializer on Next.js 16.0.6.

Web Very Easy #cve #hackthebox #nextjs #prototype-pollution #rce #react #web 5 views · 2026-09-07
Challenges Locked

Hack The Box - EncoDecept

Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.

Web Medium #cache-poisoning #deserialization #hackthebox #medium #orm-injection #university-ctf-2024 #web #xss 3 views · 2026-09-06
Challenges Locked

Hack The Box - Ether Tag

Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.

ICS Very Easy #challenges #cip #ethernet-ip #hackthebox #ics #scada 3 views · 2026-09-06
Challenges Locked

Hack The Box - OpenSecret

Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.

Web Very Easy #hackthebox #holme #jwt #web 2 views · 2026-09-06
Challenges Locked

Hack The Box - Lucky Dice

Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.

Misc Very Easy #automation #hackthebox #misc #parsing #python 6 views · 2026-09-06
Challenges Locked

Hack The Box - Espresso

ESP32-Firmware-Reverse-Engineering: Der XOR-40h-Flag-Blob im DROM wird per Literal-Pool-Crossreference und Xtensa-Disassembly gefunden und dekodiert - ohne Emulation.

Hardware Very Easy #easy #esp32 #firmware #hackthebox #hardware #reverse-engineering 4 views · 2026-09-06
Challenges Locked

Hack The Box - Flag Command

Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.

Web Very Easy #api-enumeration #easy #hackthebox #source-code-analysis #web 4 views · 2026-09-06
Challenges Locked

HackTheBox - SpookyPass

A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.

Reversing Very Easy #easy #hackthebox #reversing 3 views · 2026-09-06
Machines Locked

Hack The Box - Pirate

Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.

#active-directory #hackthebox #hard #windows 6 views · 2026-09-05
Challenges Hack The Box Locked

Hack The Box - Baby Frame

A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.

Satellite Very Easy #ccsds #challenge #hack the box #misc #space packet protocol #tc space data link 7 views · 2026-09-04
Machines Hack The Box

Hack The Box - Legacy

A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.

Windows Easy #ctf #hack the box #walkthrough #legacy 1060 views · 2024-12-27
Machines Hack The Box

Hack The Box - Lame

An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.

Linux Easy #ctf #hack the box #walkthrough #samba 1028 views · 2024-12-17