HackTheBox machine writeups documenting exploitation techniques, privilege escalation vectors, and security research.
HackTheBox
❯ Artificial — TensorFlow RCE via malicious model upload, Backrest/restic abuse for root file exfil [ml]
❯ Code — Python sandbox escape via subprocess subclass chain, path traversal in backy.sh [web]
❯ Outbound — RoundCube RCE (Metasploit), DES session decryption, CVE-2025-27591 symlink privesc [web]
❯ Planning — Grafana CVE-2024-9264 command injection, env credential leak, crontab UI RCE [web]
❯ Support — SMB UserInfo.exe reverse engineering, LDAP credential extraction, RBCD attack for SYSTEM [active-directory]
❯ OutDated — Follina/MS-MSDT phishing via SMTP, BloodHound AD path, SharpWSUS WSUS abuse for root [windows]
❯ MetaTwo — BookingPress SQLi (CVE-2022-0739), WordPress XXE (CVE-2021-29447), Passpie PGP cracking [web]
❯ Shoppy — NoSQL injection login bypass and user dump, Mattermost credential leak, Docker group escape [web]
❯ photobomb — Credentials in JS source, Ruby Sinatra command injection, PATH hijacking via sudo SETENV [web]
❯ Precious — pdfkit v0.8.6 command injection, .bundle credential leak, YAML deserialization as root [web]
❯ TenTen — WordPress Job Manager IDOR (CVE-2015-6668), steganographic SSH key, trivial sudo privesc [web]
❯ Squashed — NFS UID spoofing for webroot write, PHP shell, X11 session screenshot reveals root password [linux]
❯ Steamcloud — Kubernetes kubeletctl exec in nginx pod, service account token abuse, malicious pod mounts host FS [cloud]
❯ Sense — pfSense txt file disclosure reveals creds, Metasploit graph injection RCE as root [web]
❯ Ambassador — Grafana CVE-2021-43798 file read, SQLite/MySQL credential chain, Consul token in git history for root [linux]
❯ Blocky — Minecraft plugin .jar decompile reveals hardcoded SQL creds, password reuse to SSH, unrestricted sudo [linux]
❯ Love — SSRF via staging subdomain scans localhost:5000 for creds, PHP meterpreter upload, AlwaysInstallElevated to SYSTEM [windows]
❯ Legacy — Windows XP SMBv1, MS17-010 EternalBlue via Metasploit lands direct SYSTEM shell [windows]
❯ RouterSpace — Android APK reverse proxied through Genymotion+Burp, API command injection writes SSH key, CVE-2021-3156 sudo privesc [linux]
> End of output.