HackTheBox Writeup - SmartHire
Target IP: 10.129.245.215 Difficulty: Medium OS: Linux 1. Reconnaissance Nmap Scan PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.15 (Ubuntu Linux; protocol 2.0) ...
Target IP: 10.129.245.215 Difficulty: Medium OS: Linux 1. Reconnaissance Nmap Scan PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.15 (Ubuntu Linux; protocol 2.0) ...
Name: DevHub OS: Linux Difficulty: Medium Target IP: 10.129.4.145 1. Enumeration Nmap Scan The scan revealed three open ports: 22/tcp: SSH 80/tcp: HTTP (Redirects to http://devhub.htb) 6...
Target IP: 10.129.4.208 Difficulty: Medium OS: Linux 1. Reconnaissance Nmap Scan PORT STATE SERVICE 21/tcp open ftp (Anonymous login allowed) 22/tcp open ssh 80/tcp open http 8080/tc...
Silentium is a Medium-rated Linux machine on HackTheBox that involves exploiting an AI-driven platform (Flowise AI) and a self-hosted Git service (Gogs). Enumeration Initial Nmap scan revealed th...
Name: Abducted OS: Linux Difficulty: Medium Target IP: 10.129.244.177 1. Enumeration Nmap Scan Initial scanning revealed two primary services: 22/tcp: OpenSSH 9.6p1 445/tcp: Samba 4.6.2 ...
WingData is an Easy-difficulty Linux machine that demonstrates the exploitation of a service-level RCE and a recently discovered path traversal vulnerability in a Python-based administrative script...
TwoMillion is an Easy-difficulty Linux machine released to celebrate HackTheBox reaching 2 million users. It features a nostalgic recreation of the old HTB platform, involving an invite code bypass...
Facts is a Medium-rated Linux machine on HackTheBox that involves exploiting a Mass Assignment vulnerability in Camaleon CMS, discovering S3 credentials in the admin panel, and leveraging a sudo mi...
Kobold is an Easy-rated Linux machine on HackTheBox that focuses on subdomain enumeration, exploiting an unauthenticated RCE in an API-driven application, and leveraging Docker misconfigurations fo...
The CCTV machine on HackTheBox is a medium-difficulty Linux box that focuses on exploiting a video surveillance stack. The attack path involves exploiting a SQL injection in ZoneMinder to gather in...