HackTheBox Writeups
Showing 1–24 of 45
Abducted Writeup - HackTheBox
Orion Writeup - HackTheBox
Ghostlink Writeup - HackTheBox
Odyssey Writeup - HackTheBox
Nexus Writeup - HackTheBox
SQL injection on a web app leads to credential extraction, enabling SSH access. Privilege escalation via misconfigured Linux permissions yields root.
FireFlow Writeup - HackTheBox
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
DanglingTree Writeup - HackTheBox
Cohort Writeup - HackTheBox
DarkZeroReturns Writeup - HackTheBox
Bedside Writeup - HackTheBox
Memory forensics challenge using Volatility to analyze a Linux memory dump, extracting artifacts to uncover hidden flags through process and file analysis.
Paperwork Writeup - HackTheBox
MakeSense Writeup - HackTheBox
Linear programming attack on a custom XOR-based encryption scheme to recover the flag by solving constraints derived from the cipher's operations.
Checkpoint Writeup - HackTheBox
Windows medium box involving checkpoint security mechanisms, requiring careful enumeration, privilege escalation, and bypassing security controls to gain root access.
Enigma Writeup - HackTheBox
Nimbus Writeup - HackTheBox
Exploiting a cloud misconfiguration in a hard Linux HackTheBox machine involving AWS/cloud enumeration, privilege escalation through misconfigured services.
Connected Writeup - HackTheBox
Exploit MongoDB misconfiguration with unauthenticated access to enumerate databases and retrieve credentials, ultimately gaining root on an easy Linux box.
DevHub Writeup - HackTheBox
Exploit a Flask SSTI vulnerability in a developer hub app to gain RCE, then escalate privileges via misconfigured sudo or SUID binaries on Linux.
Reactor Writeup - HackTheBox
SmartHire Writeup - HackTheBox
SSTI via resume upload, exploiting a Flask/Jinja2 template injection in a smart hiring app to achieve RCE and capture the flag.
Helix Writeup - HackTheBox
A writeup covering enumeration, initial access, lateral movement, and privilege escalation through misconfigurations and internal service abuse.
PingPong Writeup - HackTheBox
Logging Writeup - HackTheBox
Windows medium box involving log analysis and exploitation of logging mechanisms to gain foothold and escalate privileges through misconfigured services.
Support Writeup - HackTheBox
Easy Windows box involving LDAP enumeration, custom binary reverse engineering to extract credentials, and Kerberos resource-based constrained delegation abuse for SYSTEM.
Other platforms