Hacking Labs

HackTheBox machine writeups documenting exploitation techniques, privilege escalation vectors, and security research.


HackTheBox

❯ Artificial — TensorFlow RCE via malicious model upload, Backrest/restic abuse for root file exfil [ml]

❯ Code — Python sandbox escape via subprocess subclass chain, path traversal in backy.sh [web]

❯ Outbound — RoundCube RCE (Metasploit), DES session decryption, CVE-2025-27591 symlink privesc [web]

❯ Planning — Grafana CVE-2024-9264 command injection, env credential leak, crontab UI RCE [web]

❯ Support — SMB UserInfo.exe reverse engineering, LDAP credential extraction, RBCD attack for SYSTEM [active-directory]

❯ OutDated — Follina/MS-MSDT phishing via SMTP, BloodHound AD path, SharpWSUS WSUS abuse for root [windows]

❯ MetaTwo — BookingPress SQLi (CVE-2022-0739), WordPress XXE (CVE-2021-29447), Passpie PGP cracking [web]

❯ Shoppy — NoSQL injection login bypass and user dump, Mattermost credential leak, Docker group escape [web]

❯ photobomb — Credentials in JS source, Ruby Sinatra command injection, PATH hijacking via sudo SETENV [web]

❯ Precious — pdfkit v0.8.6 command injection, .bundle credential leak, YAML deserialization as root [web]

❯ TenTen — WordPress Job Manager IDOR (CVE-2015-6668), steganographic SSH key, trivial sudo privesc [web]

❯ Squashed — NFS UID spoofing for webroot write, PHP shell, X11 session screenshot reveals root password [linux]

❯ Steamcloud — Kubernetes kubeletctl exec in nginx pod, service account token abuse, malicious pod mounts host FS [cloud]

❯ Sense — pfSense txt file disclosure reveals creds, Metasploit graph injection RCE as root [web]

❯ Ambassador — Grafana CVE-2021-43798 file read, SQLite/MySQL credential chain, Consul token in git history for root [linux]

❯ Blocky — Minecraft plugin .jar decompile reveals hardcoded SQL creds, password reuse to SSH, unrestricted sudo [linux]

❯ Love — SSRF via staging subdomain scans localhost:5000 for creds, PHP meterpreter upload, AlwaysInstallElevated to SYSTEM [windows]

❯ Legacy — Windows XP SMBv1, MS17-010 EternalBlue via Metasploit lands direct SYSTEM shell [windows]

❯ RouterSpace — Android APK reverse proxied through Genymotion+Burp, API command injection writes SSH key, CVE-2021-3156 sudo privesc [linux]


> End of output.