HackTheBox Index Page
Challenges
Web
Machines
Linux
Connected
The write-up will be published after the machine is officially retired.
DevHub
The write-up will be published after the machine is officially retired.
Reactor
The write-up will be published after the machine is officially retired.
DevArea
The write-up will be published after the machine is officially retired.
Kobold
The write-up will be published after the machine is officially retired.
VariaType
The write-up will be published after the machine is officially retired.
CCTV
The write-up will be published after the machine is officially retired.
Interpreter
Initial access through exploiting Mirth Connect vulnerability and root access through exploiting SSTI vulnerability.
WingData
The write-up will be published after the machine is officially retired.
Facts
Path traversal vulnerability and services running with sudo privilege will lead to the complete exploitation.
Conversor
Pwn the machine through malicious XSLT file upload, password hash cracking and linux utility exploitation.
BoardLight
Linux machine exploiting Dolibarr functionalities and privilege escalation.
Windows
MonitorsFour
Initial access through detailed enumeration and exploitation of Cacti service. Root access through docker containers.
Bastion
Initial access through accessing backup data and privilege escalation through mRemoteNG configuration files.
Netmon
Windows machine focused on finding and exploiting PRTG Network Monitor related vulnerabilities.
SecNotes
Windows Machine exploiting web vulnerabilities and Linux inside Windows 😉.
Arctic
Exploiting the vulnerabilities in Adobe ColdFusion and Exploiting privileges using Potato.
Active Directory
Timelapse
Machine pwned through detailed recon, hash cracking and finding clear-text passwords. Understanding of WinRM and LAPS will be helpful in the journey.
Return
Machine pwned by exploiting Web application and AD group privileges.
Blackfield
AD machine exploited through enumeration, permission exploitation, hash dump through LSASS and NTDS.dit files.
Active
AD machine exploited through detailed file crawling and kerberoasting attack.