45 writeups

> Filter Writeups

Challenges Hack The Box Locked

Hack The Box - The Puppet Master

OSINT challenge: briefing promises a BreachScope corporate DB, the deploy is a Vite SPA with 3 API routes and a real NZDF photo. Identify the Bushmaster, dodge the 2004-vs-1997 service-date trap, pull the flag.

OSINT Easy #challenge #hackthebox #osint #trainee 2 views · 2026-09-08
Challenges Hack The Box Locked

Hack The Box - Flagportation

HTB's QTT terminal teleports the flag one qubit per round with QuTiP but delegates the feed-forward correction to us and prints the Bell-measurement bits — send the Pauli correction back and read the teleported state.

Quantum Very Easy #ctf #easy #hackthebox #misc #quantum #qutip #teleportation 7 views · 2026-09-07
Challenges Hack The Box Locked

Hack The Box - Global Hyperlink Zone

5-qubit quantum circuit challenge: GHZ entanglement and anti-correlation to forge a valid hyperlink across 256 simulation shots.

Quantum Very Easy #circuit #entanglement #hackthebox #qiskit #quantum 3 views · 2026-09-07
Challenges Locked

Hack The Box - Magical Palindrome

Bypass a 75-byte nginx body limit and a 1000-character palindrome check by abusing JavaScript type coercion between string length comparison and Array() construction.

Web Very Easy #challenge #hackthebox #javascript #type-coercion #web 3 views · 2026-09-07
Challenges Locked

Hack The Box - ReactOOPS

Unauthenticated RCE via CVE-2025-55182 (React2Shell) — prototype pollution in the React Server Components Flight protocol deserializer on Next.js 16.0.6.

Web Very Easy #cve #hackthebox #nextjs #prototype-pollution #rce #react #web 5 views · 2026-09-07
Challenges Locked

Hack The Box - EncoDecept

Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.

Web Medium #cache-poisoning #deserialization #hackthebox #medium #orm-injection #university-ctf-2024 #web #xss 3 views · 2026-09-06
Challenges Locked

Hack The Box - Ether Tag

Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.

ICS Very Easy #challenges #cip #ethernet-ip #hackthebox #ics #scada 3 views · 2026-09-06
Challenges Locked

Hack The Box - OpenSecret

Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.

Web Very Easy #hackthebox #holme #jwt #web 2 views · 2026-09-06
Challenges Locked

Hack The Box - Lucky Dice

Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.

Misc Very Easy #automation #hackthebox #misc #parsing #python 6 views · 2026-09-06
Challenges Locked

Hack The Box - Espresso

ESP32 firmware reverse engineering: the XOR-0x42 flag blob in DROM is located and decoded via literal-pool cross-referencing and Xtensa disassembly, no emulation needed.

Hardware Very Easy #easy #esp32 #firmware #hackthebox #hardware #reverse-engineering 4 views · 2026-09-06
Challenges Locked

Hack The Box - Flag Command

Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.

Web Very Easy #api-enumeration #easy #hackthebox #source-code-analysis #web 4 views · 2026-09-06
Challenges Locked

Hack The Box - SpookyPass

A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.

Reversing Very Easy #easy #hackthebox #reversing 3 views · 2026-09-06
Challenges Hack The Box Locked

Hack The Box - Baby Frame

A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.

Satellite Very Easy #ccsds #challenge #hack the box #misc #space packet protocol #tc space data link 7 views · 2026-09-04