VariaType Walkthrough
The portal subdomain hosts a PHP Validation Dashboard. A .git directory was exposed at the root, allowing full source code recovery including deleted content from commit history.
HackTheBox walkthroughs for retired machines.
No matches.
The portal subdomain hosts a PHP Validation Dashboard. A .git directory was exposed at the root, allowing full source code recovery including deleted content from commit history.
print("[+]Done! Payload will be executed once somebody logs in.").
The exploits points the payload to the author's one on the file exploit.py, on line:.
On port 8000 the webserver running is serving the user.txt flag, maybe is another user who brought up the server to hack it????
There is a login page on admin.php.
The target appears to have executed the payload.
Why this worked: The developer left credentials hardcoded in client-side JavaScript, validated entirely in the browser. No server-side auth — the JS just checks if input matches an
Development share — write access confirmed:.
RPC null session — user enumeration:.
crackmapexec smb 10.10.11.69 -u 'j.fleischman' -p 'J0elTHEM4n1990!' --shares.
Facts - an easy HackTheBox walkthrough with full steps and screenshots.
nxc mssql DC01.eighteen.htb -u kevin -p 'iNa2we6haRj2gaw!' --local-auth --rid-brute.
Step 3 — Start listener and trigger:.
Step 3 — Retrieve verification link from ticket:.
FTP transmits credentials in cleartext, exposing valid system credentials.
First attempt — upload .aspx webshell directly (naive approach):.
Blocky - an easy HackTheBox walkthrough with full steps and screenshots.
Beep - an easy HackTheBox walkthrough with full steps and screenshots.
mRemoteNG stores saved credentials in %APPDATA%\mRemoteNG\confCons.xml.
Site title: "Arrexel's Development Site" — hints at phpbash tool.
Attempt 1 — Malicious snap package with install hook:.
crackmapexec smb 10.129.5.161 -u '' -p '' --shares.
Impact: Full remote code execution (RCE).
Start BurpSuite and intercept traffic from browser via FoxyProxy.
The request-baskets project has been associated with a Server-Side Request Forgery (SSRF) vulnerability, specifically identified as CVE-2023-27163.
Host is up, received reset ttl 63 (0.035s latency).
lsattr lists the file attributes on a second extended file system. See chattr below for a description of each attribute.
If you want to decompile an Android APK application to see what files are inside run the following command:.
Exiftool is highly useful for extracting metadata from documents extracted during enumeration. Leaking metadata can lead to compromise if it gets into the wrong hands, as it can ca
Short description to include any strange things to be dealt with.
This hard-difficulty Windows machine from Hack the Box was both challenging and fun. As the name suggests, it focuses on a few user-made code projects that use the C Sharp programm
This medium difficulty Linux machine by MrR3boot on Hack the Box was very interesting and quite relevant in today's cloud-centric world. Many websites these days are hosted and run
This easy-difficulty Linux machine had an interesting take on a common use of a docker container. Installing a GitLab instance and storing sensitive code in it are likely uses that
This machine was almost dissapointingly easy for a medium box. It definitely should have been classified 'Easy'. A simple test at the beginning revealed a verbose error message. So
A medium-difficulty Windows box that was fairly straightforward. Privilege escalation required going through two different users and taking advantage of Windows domain group permis
Hold on to your seats, because this Insane Windows machine is a wild ride. TODO:Finish this writeup, there are more notes and stuff in the notes app if anything is missing...
Short description to include any strange things to be dealt with...when there is a proper description here the website build will stop breaking. Hopefully this is enough text to fi
This Windows insane-difficulty machine was quite challenging, but mostly due to its use of some unconventional settings. Breaking in involved many of the normal enumeration and pri
This easy difficulty BSD system...Short description to include any strange things to be dealt with.
This machine was not as difficult in some respects as other Hard-difficulty machines, but the way that the machine was realistically hardened made it more challenging. The use of s
This Insane-difficulty machine from Hack The Box took far longer to root than I would have liked, mostly due to getting hung up on the the final exploit. I took a break from it, af
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with - Hard Linux.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
This Insane-difficulty machine from Hack The Box took me a lot longer to progress to the initial foothold than most boxes take to root! This machine had some very interesting avenu
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with - Linux hard difficulty.
Short description to include any strange things to be dealt with.
This medium-difficulty Windows machine gave me a chance to exploit a vulnerable service that we hear of often in training as being an overlooked problem for many Enterprises: print
Dyplesher was an insane difficulty Linux machine that tested both web enumeration skills, and code review and writing skills. Multiple Git repositories containing source code, the
This easy difficulty Linux machine featured a content management system that was new to me, and a simple to use but interesting way to bypass a common configuration used by system
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
An easy difficulty Linux machine that has an interesting take on database manipulation to obtain a local file inclusion vulnerability. It also has an interesting new (to me) way to
TODO: Finish this writeup~! Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Short description to include any strange things to be dealt with.
Traceback is an easy difficulty Linux machine that gives a good introduction to web shells and tracing the steps of how an attacker compromised a server (then defaced it!).
This was an easy Windows machine....but don't get stuck chasing the rabbits!
A fairly easy Windows machine that requires a little 'outside the box' thinking in order to get the initial foothold. After that, simple enumeration will give everything else that
An Insane difficulty Linux machine that tested my web skills quite a bit and also had me doing as much research on new protocols and services as three or four easy or medium boxes
This had difficulty Linux machine taught me a lot about the internal workings of a federated access control system, specifically an implementation of Oauth2. Persistence and the ab
This was a fairly easy Windows box that required a bit of back-and-forth between locations and also a little bit of .NET-fu to proceed. Luckily there are tools and websites out the
The Backslash Gang left a message behind:.
This medium difficulty Windows machine was a good refresher on themes and techniques I had seen in other machines (such as Nest), but also introduced new things and gave enough of
A medium Linux box that was fairly straightforward, but still challenging enough to teach some interesting use cases for 'standard' attacks.
Type to search · / or Ctrl+K to open · ↑↓ to move · Enter to open · Esc to close