xsspresso
xsspresso

CTF Writeups

144 writeups across 7 categories

Platform
CTF Events
OS
Category
Difficulty
Showing 144 of 144 writeups
WebMediumLinux

HTB — Facts

Cacti LFI via CVE-2024-46987 reads configuration files and credentials. Sudo abuse on a custom binary escalates to root.

#Cacti#LFI#CVE-2024-46987
Mar 8, 2026HackTheBox
WebMedium

Wiz Bug Bounty

Bug bounty masterclass covering exposed databases, SSRF, subdomain takeover, blind XSS, GitHub secret leaks, Spring Boot heapdump, and session confusion ATO.

#Bug Bounty#SSRF#Subdomain Takeover
Jan 24, 2026Wiz Bug Bounty
ADMediumWindows

HTB — Haze

Splunk misconfiguration leaks credentials. Active Directory enumeration reveals a privilege escalation path through ACL abuse to Domain Admin.

#Splunk#AD#ACL Abuse
Jan 10, 2026HackTheBox
ADMediumWindows

HTB — TombWatcher

Active Directory with ADCS misconfiguration. ESC1 certificate template abuse allows requesting a certificate as Domain Admin for full compromise.

#AD#ADCS#ESC1
Dec 1, 2025HackTheBox
ADMediumWindows

HTB — Signed

MSSQL with xp_cmdshell for initial RCE. Active Directory certificate abuse (ADCS) to impersonate Domain Admin.

#AD#MSSQL#ADCS
Nov 20, 2025HackTheBox
MiscMediumLinux

HTB — Giveback

Custom network service with an authentication logic flaw. Protocol reverse engineering reveals a bypass path to root.

#Protocol Analysis#Auth Bypass#Reverse Engineering
Nov 8, 2025HackTheBox
ADMediumWindows

HTB — NanoCorp

MSSQL enumeration with credential discovery, followed by Active Directory privilege escalation through ACL misconfigurations.

#MSSQL#AD#ACL Abuse
Nov 8, 2025HackTheBox
WebMediumLinux

HTB — Conversor

Unit conversion web app vulnerable to server-side formula injection, leading to arbitrary OS command execution.

#Formula Injection#SSTI#RCE
Oct 25, 2025HackTheBox
MiscMediumWindows

HTB — Hercules

Windows machine leveraging MSSQL linked server abuse and xp_cmdshell to gain initial foothold, then DPAPI credential decryption for escalation.

#MSSQL#Linked Servers#xp_cmdshell
Oct 20, 2025HackTheBox
ADMediumWindows

HTB — DarkZero

Active Directory environment with Shadow Credentials and Resource-Based Constrained Delegation abuse to achieve full domain compromise.

#AD#Shadow Credentials#RBCD
Oct 6, 2025HackTheBox
WebMediumLinux

HTB — Imagery

ImageMagick policy bypass enables SSRF and local file read to steal credentials. Sudo misconfiguration grants root access.

#ImageMagick#SSRF#File Read
Oct 4, 2025HackTheBox
WebMediumLinux

HTB — Expressway

Express.js prototype pollution vulnerability leads to remote code execution via deserialization of a crafted payload.

#Prototype Pollution#Node.js#Deserialization
Sep 27, 2025HackTheBox
WebMedium

Amazon CTF

Multi-challenge CTF covering AI chatbot prompt injection, LLM priority bypass, web vulnerabilities, and information disclosure across several themed web apps.

#AI#Prompt Injection#LLM
Sep 11, 2025Amazon CTF
WebEasyLinux

HTB — Planning

Grafana SSRF pivots to an internal Grafana instance. Credential reuse for SSH, then environment variable injection via root cron.

#Grafana#SSRF#Cron
May 31, 2025HackTheBox
MiscEasyWindows

HTB — Fluffy

CVE-2025-24071 abuses .searchConnector-ms files to capture NTLMv2 hashes. Relay attack and ADCS ESC4 escalate to Domain Admin.

#NTLM Relay#ADCS#CVE-2025-24071
May 28, 2025HackTheBox
WebEasyLinux

HTB — Nocturnal

ISP file manager path traversal leaks app config with credentials. ISPConfig adduser API abuse leads to root.

#Path Traversal#ISPConfig#Config Disclosure
May 24, 2025HackTheBox
ADEasyWindows

HTB — Puppy

AD enumeration with BloodHound reveals a password reset path. HR share credential reuse and GenericWrite abuse to reach Domain Admin.

#AD#BloodHound#GenericWrite
May 21, 2025HackTheBox
WebEasyLinux

HTB — Code

Python code sandbox escape via restricted eval bypass reads SSH keys. Root via path traversal in the backy backup tool.

#Python#Sandbox Escape#eval
Mar 29, 2025HackTheBox
ADMediumWindows

HTB — TheFrizz

Active Directory machine exploiting misconfigured LAPS and ACL abuse chain to escalate from low-privileged user to Domain Admin.

#AD#LAPS#ACL Abuse
Mar 18, 2025HackTheBox
WebEasyLinux

HTB — Dog

Backdrop CMS with exposed .git repository leaks DB credentials. Password reuse for SSH. SUID bee binary grants root.

#CMS#Git Disclosure#Password Reuse
Mar 15, 2025HackTheBox
WebMediumLinux

HTB — Cypher

Neo4j Cypher injection bypasses authentication. APOC procedure abuse executes OS commands for initial access and privesc.

#Cypher Injection#Neo4j#APOC
Mar 8, 2025HackTheBox
WebHardLinux

HTB — Checker

TeamCity authentication bypass combined with Bookstack SSRF to read internal files and chain into remote code execution.

#TeamCity#SSRF#Bookstack
Feb 22, 2025HackTheBox
WebMediumLinux

VHL — Tracker

MantisBT bug tracker on Debian with POP3. Credential enumeration via mail service and MantisBT RCE for shell access.

#MantisBT#POP3#Dovecot
Feb 19, 2025Virtual Hacking Labs
WebMediumLinux

VHL — PMV02

b2evolution blog CMS on Ubuntu. Authenticated file manager abuse and PHP filter injection lead to remote code execution.

#b2evolution#File Manager#PHP
Feb 17, 2025Virtual Hacking Labs
WebEasyLinux

HTB — Titanic

Flask app path traversal via download endpoint reads arbitrary files including admin credentials. Magick ImageMagick CVE-2024-41817 for root shell.

#Path Traversal#Flask#ImageMagick
Feb 16, 2025HackTheBox
MiscEasyLinux

VHL — Core

Legacy Ubuntu server with Apache 2.2 and Dovecot POP3. Enumerated mail service for credentials enabling SSH access to root.

#Apache#POP3#Dovecot
Feb 16, 2025Virtual Hacking Labs
MiscMediumLinux

VHL — FW01

IPFire firewall appliance with DNSmasq on port 53. Default/weak credentials on the admin panel lead to command execution.

#IPFire#Firewall#DNSmasq
Feb 16, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Graphs01

Cacti network monitoring on Ubuntu. Exploited CVE-2022-46169 unauthenticated RCE in Cacti for initial shell access.

#Cacti#CVE-2022-46169#RCE
Feb 16, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Mon02

Centreon IT monitoring platform on Red Hat. Default credentials lead to authenticated RCE via malicious poller command injection.

#Centreon#Default Creds#Command Injection
Feb 16, 2025Virtual Hacking Labs
MiscMediumLinux

VHL — Websrv01

Food Magazine site on Ubuntu with Exim 4.91 SMTP. Exploited CVE-2019-10149 Exim privilege escalation (GHOSTCAT) for root.

#Exim#CVE-2019-10149#SMTP
Feb 16, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS101

Joomla CMS on CentOS with ProFTPD. Exploited a known Joomla CVE for unauthenticated RCE via the com_media upload component.

#Joomla#CVE#RCE
Feb 15, 2025Virtual Hacking Labs
MiscMediumLinux

VHL — Teamspeak

TeamSpeak 3 server on CentOS. Enumerated FTP for credentials and exploited a vulnerable web application for system access.

#TeamSpeak#FTP#CentOS
Feb 15, 2025Virtual Hacking Labs
WebMediumWindows

VHL — Trace

IIS 10.0 running Kartris eCommerce on Windows. SQL injection and .NET deserialization chain leads to code execution and privilege escalation.

#IIS#Kartris#SQLi
Feb 15, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Code

Self-hosted GitLab CE on CentOS. Exploited CVE-2021-22205 unauthenticated RCE via image upload to the GitLab instance.

#GitLab#CVE-2021-22205#RCE
Feb 14, 2025Virtual Hacking Labs
WebEasyLinux

VHL — JS01

Jenkins CI/CD server with no authentication. Exploited the Groovy script console to execute commands and gain a root shell.

#Jenkins#Groovy#Script Console
Feb 14, 2025Virtual Hacking Labs
MiscMediumLinux

VHL — PBX

FreePBX/Asterisk VoIP server on Ubuntu. Exploited FreePBX RCE CVE via the admin panel to gain a reverse shell and escalate.

#FreePBX#Asterisk#VoIP
Feb 14, 2025Virtual Hacking Labs
MiscMediumWindows

VHL — React

Abyss Web Server on Windows with VNC exposed. Brute-forced VNC password to gain GUI access and escalated to SYSTEM via service abuse.

#VNC#Abyss Web Server#Brute Force
Feb 14, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS01

Joomla CMS on CentOS with anonymous FTP. Exploited a Joomla authenticated RCE CVE via the template editor for code execution.

#Joomla#RCE#FTP
Feb 13, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Tracking

Drupal 9 on Debian. Exploited an authenticated RCE vulnerability with compromised admin credentials found via enumeration.

#Drupal#RCE#Enumeration
Feb 13, 2025Virtual Hacking Labs
WebMediumWindows

VHL — AS45

Apache Tomcat 8.0.47 on Windows with AJP exposed. Exploited Ghostcat (CVE-2020-1938) via AJP connector to read sensitive files and gain RCE.

#Tomcat#Ghostcat#CVE-2020-1938
Feb 13, 2025Virtual Hacking Labs
WebEasyWindows

VHL — WinAS01

XAMPP 1.8.1 on Windows with Apache and SSL. Exploited outdated XAMPP configuration and weak credentials for web shell upload.

#XAMPP#Apache#Web Shell
Feb 13, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Crash

GravCMS on Ubuntu. Unauthenticated scheduler RCE CVE allows arbitrary command execution as the web user, then sudo privesc.

#GravCMS#Scheduler RCE#CVE
Feb 12, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Dolphin

Dolphin CMS with a WordPress instance on port 81. Admin credential brute-force leads to plugin RCE and privilege escalation.

#Dolphin CMS#WordPress#Brute Force
Feb 12, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Fed

Custom PHP forum on Fedora Linux with MariaDB. SQL injection bypasses authentication, leading to file write and shell upload.

#PHP#SQLi#MariaDB
Feb 12, 2025Virtual Hacking Labs
MiscMediumLinux

VHL — Mantis

MantisBT bug tracker with Samba shares on Ubuntu. Enumeration of SMB reveals credentials reused for MantisBT admin access.

#MantisBT#Samba#SMB
Feb 12, 2025Virtual Hacking Labs
MiscEasyLinux

VHL — Natural

FTP anonymous login exposes web application files. Abused file write via FTP to upload a PHP webshell for initial access.

#FTP#Anonymous Login#Web Shell
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Trails

Hiking Trails web application on Ubuntu. Directory traversal and file inclusion vulnerabilities lead to credentials and shell.

#LFI#Directory Traversal#Apache
Feb 12, 2025Virtual Hacking Labs
WebEasyWindows

VHL — Anthony

Windows 7 SP1 with Apache and multiple services. Enumerated web application vulnerabilities and exploited weak credentials for admin access.

#Apache#Windows 7#Credential Enum
Feb 12, 2025Virtual Hacking Labs
WebEasyWindows

VHL — Jennifer

Windows with FileZilla FTP and CMS Mini web app. FTP credential exposure and CMS RCE via file upload for initial foothold.

#FileZilla#FTP#CMS
Feb 12, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Records

OpenEMR medical records application. Exploited a pre-auth SQL injection CVE and file upload for shell access.

#OpenEMR#SQLi#File Upload
Feb 11, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS02

Drupal 8 on CentOS. Exploited Drupalgeddon2 (CVE-2018-7600) for unauthenticated RCE and escalated privileges via SUID binary.

#Drupal#Drupalgeddon2#CVE-2018-7600
Feb 11, 2025Virtual Hacking Labs
MiscEasyWindows

VHL — Aaron

Windows 10 Enterprise with SMB and RDP exposed. Credential brute-force via SMB leads to remote code execution and full system access.

#SMB#RDP#Brute Force
Feb 11, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Quick

Quick.CMS v6.7 with a known authenticated RCE vulnerability. Admin credentials discovered via enumeration for initial access.

#CMS#RCE#Quick.CMS
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Tiki

TikiWiki CMS Groupware on CentOS. Exploited a known CVE for unauthenticated remote code execution to gain a shell.

#TikiWiki#CMS#RCE
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — VPS1723

Webmin 1.991 on Ubuntu. CVE-2019-15107 arbitrary command execution via the password reset endpoint for instant root access.

#Webmin#CVE-2019-15107#RCE
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Helpdesk

FTP with anonymous access reveals helpdesk application credentials. SQL injection and file upload lead to remote code execution.

#FTP#SQLi#File Upload
Feb 10, 2025Virtual Hacking Labs
MiscEasyWindows

VHL — Steven

Wing FTP Server on Windows. Default admin credentials allow access to the web admin panel, leading to command execution via scheduled tasks.

#Wing FTP#Default Creds#FTP
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Prd

Production web server with anonymous FTP access. Weak credentials and misconfigured permissions lead to full compromise.

#FTP#Anonymous Login#Misconfiguration
Feb 9, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Forum

uftpd FTP server with anonymous access. Forum application vulnerability exploited to obtain a shell and escalate to root.

#FTP#uftpd#Forum
Feb 9, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Techblog

WordPress 4.7.2 on CentOS. Exploited outdated plugin for remote code execution and escalated via sudo misconfiguration.

#WordPress#RCE#Sudo
Feb 8, 2025Virtual Hacking Labs
MiscEasyLinux

VHL — Backupadmin

FTP server with anonymous access exposes backup credentials. Password reuse leads to SSH login and privilege escalation.

#FTP#Anonymous Login#Password Reuse
Feb 8, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Dev

Development web server with FTP credentials leaked via anonymous login. Credential reuse and web shell upload for root.

#FTP#Web Shell#File Upload
Feb 8, 2025Virtual Hacking Labs
WebMediumLinux

HTB — Cat

Apache mod_rewrite CVE-2024-38472 XSS in redirect. Stored XSS steals admin cookie for Gitea access. SQLite injection and Gitea hook RCE for root.

#XSS#CVE-2024-38472#Gitea
Feb 1, 2025HackTheBox
ADMediumWindows

HTB — StreamIO

SQLi on login page, LFI reveals PHP source. MSSQL xp_cmdshell for shell. Firefox DPAPI credential decryption leads to Domain Admin via ADCS.

#AD#SQLi#LFI
Jan 31, 2025HackTheBox
MiscMediumLinux

HTB — Shibboleth

IPMI 2.0 cipher 0 authentication bypass via RAKP attack dumps password hash. MariaDB CVE-2021-27928 RCE and Zabbix for lateral movement.

#IPMI#RAKP#MariaDB
Jan 26, 2025HackTheBox
WebMediumLinux

HTB — BigBang

WordPress BuddyForms plugin SSRF for local file read. Grafana SQLite injection for credentials. Telescope log viewer arbitrary file read for root key.

#WordPress#SSRF#Grafana
Jan 26, 2025HackTheBox
ADHardWindows

HTB — Blackfield

ASREPRoasting yields crackable hash. ForceChangePassword on account via BloodHound. Volatility lsass dump reveals backup operator for DCSync.

#AD#ASREPRoasting#BloodHound
Jan 23, 2025HackTheBox
ADEasyWindows

HTB — Support

Custom .NET info collector binary contains obfuscated LDAP password. GenericAll on DC via Resource-Based Constrained Delegation for Domain Admin.

#AD#RBCD#BloodHound
Jan 23, 2025HackTheBox
ADEasyWindows

HTB — Return

Network printer admin panel LDAP credential exfiltration via attacker-controlled server. Server Operators group membership for domain privilege escalation.

#AD#LDAP#Server Operators
Jan 22, 2025HackTheBox
ADEasyWindows

HTB — Timelapse

SMB share contains ZIP with password-protected PFX certificate. Cracked PFX used for WinRM. LAPS password read via LDAP for Administrator.

#AD#LAPS#PFX
Jan 21, 2025HackTheBox
ADHardWindows

HTB — Flight

LFI via lang parameter captures NTLM hash with Responder. Password spray, IIS WebDAV shell upload, RunasCs for lateral movement to Domain Admin.

#AD#LFI#NTLM
Jan 21, 2025HackTheBox
WebEasyLinux

HTB — Help

HelpDeskZ GraphQL unauthenticated query exposes user creds. File upload bypass for PHP webshell. Kernel 4.4 exploit for root privilege escalation.

#GraphQL#File Upload#Kernel Exploit
Jan 20, 2025HackTheBox
WebMediumLinux

HTB — Magic

Magic Portfolio with SQLi bypass on login. File upload bypass with double extension for PHP webshell. mysqldump credential extraction and SUID sysinfo for root.

#SQLi#File Upload Bypass#SUID
Jan 20, 2025HackTheBox
ADEasyWindows

HTB — Sauna

ASREPRoasting on user names enumerated from the bank website. DCSync attack via GenericAll rights for Domain Admin hash dump.

#AD#ASREPRoasting#DCSync
Jan 20, 2025HackTheBox
ADMediumWindows

HTB — Monteverde

Azure AD Connect with user enumeration via RPC. Password spraying finds default creds. Azure AD Sync password extraction for Domain Admin.

#AD#Azure AD#Password Spray
Jan 20, 2025HackTheBox
WebEasyLinux

HTB — BoardLight

Dolibarr CRM CVE-2023-30253 PHP injection for RCE. Enlightenment window manager SUID binary exploit for local privilege escalation to root.

#Dolibarr#CVE-2023-30253#SUID
Jan 19, 2025HackTheBox
WebMediumLinux

HTB — Monitored

Nagios XI SNMP credential leak, auth bypass CVE-2023-40931 for API key theft. SQL injection creates admin account for RCE via malicious script.

#Nagios#SNMP#SQLi
Jan 19, 2025HackTheBox
WebEasyLinux

HTB — Precious

Pdfkit CVE-2022-25765 SSRF/command injection via URL parameter in PDF generation endpoint. Ruby bundler YAML deserialization for root.

#Pdfkit#CVE-2022-25765#YAML Deserialization
Jan 19, 2025HackTheBox
WebEasyLinux

HTB — Analytics

Metabase pre-auth RCE CVE-2023-38646 via setup token SSRF for shell. Ubuntu OverlayFS CVE-2023-2640 local privilege escalation for root.

#Metabase#CVE-2023-38646#OverlayFS
Jan 18, 2025HackTheBox
MiscHardLinux

HTB — Backfire

HardHat C2 framework exposed via reverse proxy misconfiguration. JWT forgery for admin access, Sliver C2 implant exploitation for lateral movement.

#C2 Framework#JWT Forgery#Reverse Proxy
Jan 18, 2025HackTheBox
WebEasyLinux

HTB — Broker

Apache ActiveMQ CVE-2023-46604 unauthenticated RCE via ClassInfo deserialization. Sudo nginx misconfiguration for arbitrary file read and root access.

#ActiveMQ#CVE-2023-46604#Deserialization
Jan 18, 2025HackTheBox
WebEasyLinux

HTB — OpenAdmin

OpenNetAdmin 18.1.1 RCE via command injection in web console. Internal Apache vhost with SSH key in password-protected page for lateral movement.

#OpenNetAdmin#Command Injection#RCE
Jan 18, 2025HackTheBox
WebMediumLinux

HTB — Popcorn

File upload bypass on torrent hosting site via content-type manipulation for PHP webshell. Kernel exploit or DirtyCow for privilege escalation.

#File Upload Bypass#PHP Webshell#Kernel Exploit
Jan 18, 2025HackTheBox
MiscEasyWindows

HTB — Heist

Cisco IOS config file exposed via web portal with hashed passwords. Cracked hashes reused for RPC access, Looney Tunables for escalation.

#Cisco#Hash Cracking#RPC
Jan 18, 2025HackTheBox
WebEasyLinux

HTB — Devvortex

Joomla CVE-2023-23752 info disclosure leaks database creds. Authenticated template RCE for shell. Apport crash handler sudo exploit for root.

#Joomla#CVE-2023-23752#RCE
Jan 16, 2025HackTheBox
WebEasyWindows

HTB — Love

SSRF on a voting system bypasses firewall to reach internal file analysis service. PHP file upload for RCE, AlwaysInstallElevated for SYSTEM.

#SSRF#File Upload#AlwaysInstallElevated
Jan 16, 2025HackTheBox
MiscEasyWindows

HTB — Mailing

hMailServer path traversal leaks admin hash. Outlook CVE-2024-21413 moniker link attack for NTLM relay, WinPEAS finds privesc vector.

#hMailServer#NTLM Relay#CVE-2024-21413
Jan 16, 2025HackTheBox
MiscMediumLinux

HTB — Mentor

SNMP v3 credential brute-force yields API secret. Command injection in backup API endpoint. PostgreSQL password enables lateral movement and sudo root.

#SNMP#Command Injection#API
Jan 15, 2025HackTheBox
WebEasyLinux

HTB — Usage

Laravel admin panel SQL injection via search parameter. Malicious PNG for RCE via file upload. Wildcard file read on sudo binary for root flag.

#SQLi#Laravel#File Upload
Jan 15, 2025HackTheBox
WebEasyWindows

HTB — Buff

Gym Management Software RCE via unauthenticated file upload. CloudMe buffer overflow with port forwarding for privilege escalation.

#File Upload#RCE#Buffer Overflow
Jan 15, 2025HackTheBox
WebEasyLinux

HTB — Sea

WonderCMS CVE-2023-41425 XSS to RCE via theme upload. Credential reuse for lateral movement. Port-forwarded internal tool for command injection privesc.

#WonderCMS#XSS#RCE
Jan 14, 2025HackTheBox
WebEasyWindows

HTB — Remote

Umbraco CMS with anonymous NFS mount exposing credentials. Authenticated SXSS/RCE via template. TeamViewer 7 password decryption for SYSTEM.

#Umbraco#NFS#RCE
Jan 14, 2025HackTheBox
MiscMediumLinux

HTB — Instant

APK reverse engineering reveals hardcoded API key for Swagger endpoint. Arbitrary file read on API leaks SSH key. Solar-PuTTY encrypted session cracking for root.

#APK#API Key#Swagger
Jan 13, 2025HackTheBox
ADMediumWindows

HTB — EscapeTwo

MSSQL with xp_cmdshell after credential spraying. ADCS ESC4 template modification for certificate impersonation to gain Domain Admin.

#AD#MSSQL#ADCS
Jan 13, 2025HackTheBox
WebMediumLinux

HTB — Heal

ResumeAI app with IDOR exposing all resumes. LimeSurvey RCE via authenticated plugin upload. Consul service token for SYSTEM shell via API exec.

#IDOR#LimeSurvey#Consul
Jan 11, 2025HackTheBox
WebEasyLinux

HTB — Alert

Markdown XSS for stored cross-site scripting. SSRF via file:// to leak local web app source code, exposed internal site with writable path for root.

#XSS#SSRF#Markdown
Jan 10, 2025HackTheBox
WebEasyLinux

HTB — Chemistry

CIF file parser RCE via pymatgen CVE-2024-23346 arbitrary code execution. aiohttp path traversal CVE-2024-23334 for credential theft and lateral movement.

#CIF Parser#CVE-2024-23346#aiohttp
Jan 10, 2025HackTheBox
ADEasyWindows

HTB — Cicada

SMB guest access reveals default password in HR note. User enumeration + password spray, SeBackupPrivilege abuse for NTDS.dit extraction.

#AD#SMB#SeBackupPrivilege
Jan 9, 2025HackTheBox
ADMediumWindows

HTB — Certified

Shadow Credentials attack via WriteProperty on user object. ADCS ESC9 certificate template abuse to impersonate a privileged account.

#AD#ADCS#Shadow Credentials
Jan 9, 2025HackTheBox
WebEasyLinux

HTB — LinkVortex

Ghost CMS CVE-2023-40028 arbitrary file read vulnerability. Symlink traversal via config reveals credentials for lateral movement and sudo privesc.

#Ghost CMS#CVE-2023-40028#Symlink
Jan 8, 2025HackTheBox
MiscEasyLinux

HTB — UnderPass

daloRADIUS web interface default credentials expose user hashes. Cracked MD5 hash for SSH. Mosh binary sudo privesc for root shell.

#daloRADIUS#Default Creds#MD5
Jan 8, 2025HackTheBox
ADMediumWindows

HTB — Administrator

FTP credentials from initial account. Targeted Kerberoasting via BloodHound paths, GenericWrite abuse, DCSync for Domain Admin hash.

#AD#Kerberoasting#BloodHound
Jan 8, 2025HackTheBox
MiscEasyLinux

HTB — Pilgrimage

ImageMagick CVE-2022-44268 arbitrary file read via malicious PNG. SQLite database exposes credentials. Binwalk CVE-2022-4510 for root shell.

#ImageMagick#CVE-2022-44268#Binwalk
Nov 26, 2024HackTheBox
WebEasyLinux

HTB — Tabby

LFI on Tomcat manager exposes credentials. WAR file deployed for RCE. ZIP password cracking, LXD container privilege escalation for root.

#LFI#Tomcat#WAR
Nov 26, 2024HackTheBox
WebEasyLinux

HTB — CozyHosting

Spring Boot Actuator exposes session cookies. Hijacked admin session to exploit command injection in SSH endpoint for reverse shell.

#Spring Boot#Actuator#Command Injection
Nov 26, 2024HackTheBox
MiscEasyLinux

HTB — Keeper

Request Tracker default credentials expose SSH public key in ticket. KeePass 2.x CVE-2023-32784 memory dump extracts master password for root SSH key.

#KeePass#CVE-2023-32784#Memory Dump
Nov 25, 2024HackTheBox
WebEasyLinux

HTB — Knife

PHP 8.1.0-dev backdoor via User-Agentt header for RCE. Sudo knife binary used as a GTFOBin for instant root shell.

#PHP Backdoor#RCE#GTFOBins
Nov 25, 2024HackTheBox
WebMediumWindows

HTB — Giddy

SQL injection via stored procedure triggers NTLM hash capture. Responder catches hash, crack for WinRM. Ubiquiti UniFi privesc via service abuse.

#SQLi#NTLM#Responder
Nov 25, 2024HackTheBox
WebMediumWindows

HTB — Sniper

PHP RFI via language parameter loads SMB share for RCE. Lateral movement via credential in web config. CHM file drops reverse shell as Administrator.

#RFI#SMB#CHM
Nov 21, 2024HackTheBox
MiscEasyWindows

HTB — ServMon

Anonymous FTP reveals NVMS-1000 path traversal note. LFI reads credentials file, SSH pivoting to access NSClient++ for SYSTEM.

#FTP#LFI#NVMS-1000
Nov 20, 2024HackTheBox
WebEasyLinux

HTB — Sau

Maltrail 0.53 SSRF on a request-basket service. CVE-2023-27163 chained to unauthenticated OS command injection for initial access, sudo privesc.

#SSRF#Command Injection#CVE-2023-27163
Nov 19, 2024HackTheBox
WebEasyLinux

HTB — Busqueda

Searchor 2.4.0 CLI eval() injection for code execution. Gitea instance found via Docker-compose, admin token for privileged script execution.

#Code Injection#eval()#Gitea
Nov 19, 2024HackTheBox
WebMediumLinux

HTB — UpDown

Site availability checker with .htaccess allowlist bypass. PHP phar deserialization for code execution, proc_open for shell, developer sudo suid binary.

#PHAR Deserialization#LFI#Bypass
Nov 19, 2024HackTheBox
ADMediumWindows

HTB — Escape

MSSQL Silver Ticket attack via SPN enumeration. Responder captures NTLMv2 hash from SQL query, certificate auth for Domain Admin.

#AD#MSSQL#Silver Ticket
Nov 19, 2024HackTheBox
ADEasyWindows

HTB — Active

SMB anonymous access to SYSVOL leaks GPP-encrypted password. Kerberoasting the Administrator SPN cracks the hash for full domain access.

#AD#GPP#Kerberoasting
Jan 10, 2023HackTheBox
MiscMediumWindows

HTB — Silo

Oracle Database 11g with default credentials. ODAT tool for OS command execution. Volatility on a memory dump recovers the admin password.

#Oracle DB#ODAT#Volatility
Jun 6, 2022HackTheBox
WebEasyWindows

HTB — Grandpa

IIS 6.0 WebDAV buffer overflow (CVE-2017-7269) for initial access. Token kidnapping / churrasco escalates to SYSTEM.

#IIS#WebDAV#CVE-2017-7269
Jun 3, 2022HackTheBox
WebEasyWindows

HTB — Artic

ColdFusion 8 arbitrary file upload RCE (CVE-2009-2265). MS10-059 (Chimichurri) token impersonation for privilege escalation.

#ColdFusion#CVE-2009-2265#File Upload
May 30, 2022HackTheBox
WebEasyWindows

HTB — Granny

WebDAV file upload with extension spoofing deploys an ASPX shell. Token impersonation via churrasco/juicy potato for SYSTEM.

#WebDAV#ASPX#Token Impersonation
May 26, 2022HackTheBox
WebMediumWindows

HTB — Bastard

Drupal 7 authenticated RCE via Services module REST endpoint. MS15-051 kernel exploit escalates to SYSTEM.

#Drupal#RCE#REST API
May 20, 2022HackTheBox
WebEasyWindows

HTB — Optimum

HttpFileServer 2.3 RCE (CVE-2014-6287) via Rejetto HFS. Windows kernel exploit (MS16-032) for privilege escalation to SYSTEM.

#HFS#CVE-2014-6287#RCE
May 16, 2022HackTheBox
WebEasyWindows

HTB — Devel

Anonymous FTP write access to IIS webroot allows ASPX webshell upload. Local kernel exploit for SYSTEM.

#FTP#IIS#ASPX
May 10, 2022HackTheBox
MiscEasyWindows

HTB — Blue

Demonstrates the full impact of EternalBlue (MS17-010). One Metasploit module gives SYSTEM on an unpatched Windows 7 SMB service.

#EternalBlue#MS17-010#SMB
May 6, 2022HackTheBox
MiscEasyWindows

HTB — Legacy

Classic beginner box. MS08-067 (Netapi) and MS17-010 (EternalBlue) both yield SYSTEM directly with no privilege escalation needed.

#SMB#MS08-067#EternalBlue
May 3, 2022HackTheBox
WebMediumLinux

HTB — Jarvis

SQL injection in hotel booking app. Sqlmap writes a PHP webshell. Sudo script with command injection, SUID systemctl for root.

#SQLi#Webshell#Sudo
Apr 30, 2022HackTheBox
WebEasyLinux

HTB — Networked

PHP file upload bypass with double extension and MIME spoofing. Cron-executed user script for lateral move, ifcfg privesc to root.

#File Upload#PHP#Cron
Apr 26, 2022HackTheBox
WebEasyLinux

HTB — Friendzone

DNS zone transfer reveals subdomains. SMB anonymous share leaks creds. LFI + PHP injection for RCE, Python lib hijack for root.

#SMB#LFI#DNS
Apr 23, 2022HackTheBox
MiscEasyLinux

HTB — Irked

UnrealIRCd 3.2.8.1 backdoor for foothold. Hidden steganography in an image reveals credentials. SUID viewuser binary abuse.

#IRC#Backdoor#Steganography
Apr 18, 2022HackTheBox
WebEasyLinux

HTB — Swagshop

Magento 1.9 SQLi creates an admin account; Magento Froghopper achieves RCE. Sudo vim executes a shell as root.

#Magento#SQLi#RCE
Apr 13, 2022HackTheBox
WebMediumLinux

HTB — Tartarsauce

Gwolle Guestbook WordPress RFI via robots.txt discovery. Lateral move through sudo tar with --checkpoint shell execution.

#WordPress#RFI#Sudo
Apr 13, 2022HackTheBox
MiscEasyLinux

HTB — Sunday

Finger service enumerates valid usernames. Weak SSH credentials, troll binary, sudo wget for arbitrary file write to root.

#Finger#Weak Credentials#Sudo
Apr 11, 2022HackTheBox
WebMediumLinux

HTB — Poison

PHP LFI escalated to RCE via Apache log poisoning. SSH tunneling exposes an internal VNC session running as root.

#LFI#Log Poisoning#VNC
Apr 10, 2022HackTheBox
WebMediumLinux

HTB — Valentine

Heartbleed (CVE-2014-0160) memory leak extracts a base64-encoded RSA key passphrase. Root via tmux session hijack.

#Heartbleed#OpenSSL#CVE-2014-0160
Apr 7, 2022HackTheBox
WebMediumLinux

HTB — Node

Node.js API endpoint exposes hashed admin credentials. MongoDB backup decryption and SUID binary analysis for root.

#Node.js#MongoDB#API
Apr 5, 2022HackTheBox
MiscMediumLinux

HTB — Solidstate

Apache James 2.3.2 arbitrary file read leaks user creds. Root via world-writable cron script executed by root.

#SMTP#James#File Read
Apr 2, 2022HackTheBox
WebMediumLinux

HTB — Sense

pfSense 2.1.3 authenticated command injection (CVE-2014-4688). Credentials found via directory fuzzing on the web interface.

#pfSense#Command Injection#CVE-2014-4688
Mar 29, 2022HackTheBox
WebMediumLinux

HTB — Nineveh

Brute-force phpLiteAdmin + LFI via chained PHP injection. Port knocking unlocks SSH, chkrootkit path hijack for root.

#Brute Force#LFI#Port Knocking
Mar 28, 2022HackTheBox
WebMediumLinux

HTB — Cronos

DNS zone transfer reveals hidden vhosts. SQL injection login bypass, OS command injection for shell, cron privesc.

#DNS#SQLi#Command Injection
Mar 27, 2022HackTheBox
MiscEasyLinux

HTB — Beep

Multiple valid paths: Elastix LFI to leak credentials, Webmin RCE, or Asterisk extension abuse. Great enumeration practice.

#Elastix#LFI#Webmin
Mar 26, 2022HackTheBox
WebEasyLinux

HTB — Nibbles

Nibbleblog CMS with guessable admin credentials leads to arbitrary PHP file upload and remote code execution.

#Nibbleblog#File Upload#RCE
Mar 25, 2022HackTheBox
WebEasyLinux

HTB — Bashed

phpbash webshell discovered via directory fuzzing. Lateral movement through sudo scriptmanager, cron-based root.

#Webshell#Fuzzing#Cron
Mar 24, 2022HackTheBox
WebEasyLinux

HTB — Shocker

Shellshock (CVE-2014-6271) via a CGI endpoint found with gobuster. Sudo perl for a trivial privilege escalation.

#Shellshock#CGI#Sudo
Mar 23, 2022HackTheBox
CryptoInsaneLinux

HTB — Brainfuck

Insane box chaining WordPress plugin creds, SMTP sniffing, RSA private key crack, and Vigenère cipher decode.

#WordPress#RSA#Vigenère
Mar 7, 2022HackTheBox
MiscEasyLinux

HTB — Lame

The first HTB machine. Single Samba 3.0.20 exploit (CVE-2007-2447) for an instant root shell via username map script.

#Samba#CVE-2007-2447#RCE
Mar 3, 2022HackTheBox