45 writeups

> Filter Writeups

Machines Hack The Box Locked

Hack The Box - Management

Pre-auth Java deserialization in OpenAM (CVE-2026-33439) yields a shell as the service account, a GLPI-stored LDAP bind secret decrypts to a password the desktop user reuses, and a sudo rdiff-backup wildcard with a parser quirk mirrors /root.

Linux Medium #cve-2026-33439 #deserialization #glpi #java #openam #opendj #rdiff-backup #sudo 4 views · 2026-09-27
Machines Hack The Box Locked

Hack The Box - DanglingTree

DanglingTree (Windows/AD): CVE-2026-23760 turns the loopback-only SmarterMail API into RCE as svc_mail, DPAPI from the Credential Manager hides a second account, and a deleted ESC1 certificate template is recreated all the way to a Domain Admin certificate and root.txt.

Windows Medium #active-directory #adcs #cve-2026-23760 #cve-2026-26119 #dpapi #esc1 #hackthebox #windows 4 views · 2026-09-27
Machines Hack The Box Locked

Hack The Box - Cohort

Easy Linux chain: SSRF filter checks hostname strings instead of addresses - decimal loopback opens the internal port map, /status leaks the notebook vhost, marimo's unauthenticated /terminal/ws (CVE-2026-39987) gives the shell, PackageKit TOCTOU (CVE-2026-41651) the root.

Linux Easy #easy #hackthebox #linux #ssrf #web 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - Bedside

PDF upload meets pdfminer.six pickle RCE (CVE-2025-64512): CMap path injection gives a shell in the container, a Vite dev server with path traversal leaks the developer SSH key, and a NOPASSWD trainer with torch.load turns into a root shell.

Linux Medium #cve-2025-31125 #cve-2025-64512 #path-traversal #pdfminer #pickle #sudo #torch #vite 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - Cobblestone

Second-order SQLi with FILE privilege, an AppArmor hat that only forbids exec, Cobbler-XMLRPC as root on loopback: CVE-2024-47533 plus Cheetah-SSTI turns it into root RCE.

Linux Insane #apparmor #cobbler #hackthebox #insane #linux #sqli #ssti 1 views · 2026-09-09
Machines Hack The Box Locked

Hack The Box - DarkZeroReturns

Double-forest AD chain with a Linux edge host: Handlebars AST injection (CVE-2026-33937) turns into RCE, a Gitea preinstall hook runs as svc-runner, a planted AD user root gets ksu to uid 0, DCSync and a golden ticket with SID history cross the forest trust, until PtH ends on the Hyper-V host.

Windows Hard #active-directory #hackthebox #hard #kerberos #windows 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Garfield

RODC-focused AD chain: time-sync drift detection, RODC password PRP enumeration, writable-attribute abuse on the RODC account, key list and trust account rebuild, a group-managed account escape, and a SID history trick at the end.

Windows Hard #active-directory #hackthebox #hard #rodc #windows 9 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Checkpoint

Medium AD chain on Server 2025: supplied creds plus faketime for the 7h-skewed DC, a Deleted-Object restore grants a second user, a malicious VSIX (CVE-2025-55319) gives user shell, BadSuccessor (CVE-2025-53779) takes over svc_deploy, and VMkatz on a backup-share snapshot extracts Administrator.

Windows Medium #active-directory #hackthebox #medium #windows 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Connected

CentOS 7 / FreePBX 16.0.40.7: unauthenticated web RCE through the admin app, a DB error chain, an asterisk webshell, a wired user-flag drop, a lock artifact in the DAG, and at the end it hands root the box too.

Linux Medium #asterisk #freepbx #hackthebox #linux #medium 10 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Nimbus

AWS-style lab chain: SSRF blocklist bypass to a fake IMDS, STS and SQS message injection, unsafe yaml.load in the worker for RCE, a privileged CodeBuild container, and a core_pattern host escape at the end.

Linux Medium #aws #hackthebox #linux #medium #ssrf #yaml 15 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - MakeSense

WordPress 7.0: stored XSS via the audio transcription pipeline creates an admin-bot user, the plugin editor becomes a webshell, wp-config creds get SSH as walter, and the local OCR service runs as root, with password reuse again tying the whole chain together.

Linux Medium #hackthebox #linux #medium #wordpress #xss 11 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - DevHub

Three service layers, three jumps: the unauth MCP Inspector (6274) spawns stdio processes, the Jupyter start command leaks its token, and the OpsMCP server running as root hands out id_rsa via ops._admin_dump, ending with SSH login as root.

Linux Medium #hackthebox #jupyter #linux #mcp #medium 12 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Paperwork

Hand-written RFC-1179 print daemon: the LPD job name injects via shell=True into the echo line, JetDirect/PJL traversal plants an SSH key as archivist, an SCM_RIGHTS fd leak from the root daemon reads admin_pins.conf, and password reuse lands root here.

Linux Easy #easy #hackthebox #linux #lpd #scm-rights 17 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - SmartHire

Hidden MLflow vhost with default creds: model registry poisoning via model_code_path gives RCE as svcweb, the sudo Python tool extends its search via site.addsitedir() to group-writable plugin dirs, and a .pth hijack gets root.

Linux Medium #hackthebox #linux #medium #mlflow #python 19 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Silentium

Easy chain through two hidden vhosts: Flowise auth bypass (CVE-2025-58434) to container RCE, password reuse from container to host user ben, and Gogs symlink RCE (CVE-2025-8110) on the root-run Gogs service yields the root shell.

Linux Easy #easy #flowise #gogs #hackthebox #linux 15 views · 2026-09-08
Machines Hack The Box

Hack The Box - Fireflow

Medium Linux chain: a public Langflow flow_id opens an unauth build endpoint running an attacker Component as www-data; the .env password reuses to SSH as nightfall; the MCP registry accepts alg=none admin JWTs; and kubelet exec into a host-mounted node-exporter reads /host/root/root.txt.

Linux Medium #hackthebox #jwt #kubernetes #langflow #linux #mcp #medium 667 views · 2026-09-08
Machines Hack The Box

Hack The Box - Nexus

Easy Linux box: CVE-2026-38526 turns a CRM installer's AJAX-only middleware check into an unauthenticated admin overwrite, a TinyMCE upload drops a webshell, the .env password reuses to jones over SSH, and a root systemd timer joining git ls-tree names unsanitized writes an authorized_keys to /root.

Linux Easy #easy #gitea #hackthebox #krayin #laravel #linux #traversal 598 views · 2026-09-08
Machines Hack The Box

Hack The Box - TwoMillion

Easy Linux replica of the old HTB platform: the invite code is one API call, a hidden PUT /admin/settings/update self-assigns is_admin from the body, the VPN generator takes a username command injection, and the leaked .env password reuses to SSH before the kernel falls to CVE-2023-0386.

Linux Easy #command-injection #cve-2023-0386 #easy #hackthebox #linux #mass-assignment #overlayfs 626 views · 2026-09-08
Machines Hack The Box

Hack The Box - Zero

Insane Linux hosting portal: .htaccess ErrorDocument overrides become an arbitrary file read, leaked web-environment credentials rehash into an SSH login as uid 666, and a cron-checked Apache config lets a confcheck script drop setuid-root bash for the root flag.

Linux Insane #hackthebox #htaccess #insane #linux #setuid #sftp 826 views · 2026-09-08
Machines Hack The Box

Hack The Box - Anubis

Insane Windows AD chain: ASP template injection in a hosted page gives SYSTEM inside a container, a Responder hash cracks to localadmin, a malicious Jamovi file rides an SMB share to host shell, and a writable Web certificate template is the ESC1/ESC4 bridge to Domain Admin.

Windows Insane #active-directory #adcs #esc1 #esc4 #hackthebox #insane #jamovi #windows 861 views · 2026-09-08
Machines Hack The Box

Hack The Box - Coder

Insane Windows box: an SMB dev share leaks an encrypted TeamCity build file whose timestamp field decrypts a KeePass key, admin remote-run twists into RCE as svc_teamcity, reused credentials climb to e.black, and an ADCS ESC1 template signs the way to Domain Admin.

Windows Insane #adcs #esc1 #hackthebox #insane #keepass #teamcity #windows 1010 views · 2026-09-08
Machines Hack The Box

Hack The Box - University

Insane Windows university chain: an xhtml2pdf file:/ write becomes a shell as the reviewer account, forged professor certificates and a CVE-2023-36025 .url shortcut cross the next trust boundary, and relay to RBCD plus a gMSA read ends with Domain Admin and the DC flag.

Windows Insane #active-directory #adcs #gmsa #hackthebox #insane #s4u #windows 923 views · 2026-09-08
Machines Hack The Box

Hack The Box - Forgotten

Easy Linux VulnLab box: an exposed LimeSurvey installer accepts an attacker-controlled MariaDB and hands over admin access, a malicious plugin upload is RCE inside the container, and a host-mounted env variable plus a setuid-drop pivot from the container lands a host root shell.

Linux Easy #docker #easy #hackthebox #limesurvey #linux #sudo 755 views · 2026-09-08
Machines Hack The Box

Hack The Box - Pterodactyl

Medium Linux chain on openSUSE: CVE-2025-49132 turns the Pterodactyl panel's locale endpoint into an LFI that reads database credentials and writes a PHP shell via pearcmd, then CVE-2025-6018/6019 forge an active seat and ride udisks into a SUID-root bash.

Linux Medium #hackthebox #linux #medium #opensuse #polkit #pterodactyl #udisks 832 views · 2026-09-08
Machines Hack The Box

Hack The Box - Snapped

Hard Linux chain: CVE-2026-27944 in Nginx UI's unauthenticated /api/backup leaks its AES key and IV in a response header; the decrypted SQLite cracks to an SSH login, and a snap-confine TOCTOU race (CVE-2026-3888) drops a SUID-root shell.

Linux Hard #hackthebox #hard #linux #nginx-ui #race-condition #snapd #toctou 777 views · 2026-09-08
Machines Hack The Box

Hack The Box - Editor

Easy Linux XWiki 15.10.8 chain: CVE-2025-24893 Groovy injection through the SolrSearch RSS feed gives code execution as the service user, a reused datasource password drops SSH as oliver, and Netdata's SUID ndsudo resolving nvme through a caller-controlled PATH (CVE-2024-32019) finishes as root.

Linux Easy #easy #groovy #hackthebox #linux #ndsudo #netdata #xwiki 667 views · 2026-09-08
Machines Hack The Box

Hack The Box - Cap

Easy Linux dashboard with an IDOR in its packet-capture feature: the capture downloader takes a global counter ID with no ownership check, leaking a plaintext FTP login that reuses to SSH; file capabilities on python3.8 turn a setuid interpreter into a root shell via os.setuid(0).

Linux Easy #capabilities #easy #hackthebox #idor #linux #pcap 432 views · 2026-09-08
Machines Hack The Box

Hack The Box - Jail

Insane CentOS tour of sandbox escapes: executable-stack overflow in the custom auth daemon, an NFS export without squash promoting nobody to frank, an rvim :py escape to adm, and Wiener's attack on a small-d RSA key turning the stolen root SSH public key into a root login.

Linux Insane #buffer-overflow #hackthebox #insane #linux #nfs #rsa #rvim #wiener 779 views · 2026-09-08
Machines Hack The Box Locked

Hack The Box - Eloquia

Insane Windows chain: OAuth2 CSRF makes the admin bot bind an attacker identity, a DLL rides the article banner through SQLite load_extension() to RCE as web, Edge DPAPI leaks Olivia.KAT's WinRM password, and an AppDomainManager injection in the auto-restarted Failure2Ban service lands SYSTEM.

Windows Insane #appdomainmanager #dpapi #hackthebox #insane #oauth #windows 7 views · 2026-09-08
Machines

Hack The Box - Pirate

Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.

#active-directory #hackthebox #hard #windows 869 views · 2026-09-05
Machines Hack The Box

Hack The Box - Legacy

A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.

Windows Easy #ctf #hack the box #walkthrough #legacy 1451 views · 2024-12-27
Machines Hack The Box

Hack The Box - Lame

An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.

Linux Easy #ctf #hack the box #walkthrough #samba 1516 views · 2024-12-17