Hack The Box - The Puppet Master
OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.
╔════════════════════════════════════════╗
║ TERMINAL TROUBLE - HTB WRITEUPS ║
║ > root@kali:~# cat /root/flag.txt ║
╚════════════════════════════════════════╝
45 writeups
OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.
HTB's QTT terminal teleports the flag one qubit per round with QuTiP but delegates the feed-forward correction to us and prints the Bell-measurement bits — send the Pauli correction back and read the teleported state.
5-qubit quantum circuit challenge: GHZ entanglement and anti-correlation to forge a valid hyperlink across 256 simulation shots.
Bypass a 75-byte nginx body limit and a 1000-character palindrome check by abusing JavaScript type coercion between string length comparison and Array() construction.
Unauthenticated RCE via CVE-2025-55182 (React2Shell) — prototype pollution in the React Server Components Flight protocol deserializer on Next.js 16.0.6.
Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.
Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.
Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.
Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.
ESP32 firmware reverse engineering: the XOR-0x42 flag blob in DROM is located and decoded via literal-pool cross-referencing and Xtensa disassembly, no emulation needed.
Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.
A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.
A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.