Home
A Hacker's Dream
Cancel

Lame

HTB Lame Overview: Lame is a easy rated machine on Hackthebox that exploits the Distcc service vulnerable to CVE-2004-2687 which allows us to execute arbitrary code to gain foothold to the machine...

Keeper

Overview: Keeper is an Easy rated HTB machine that uses default credentials to gain access into a dashboard that leaks user credentials that can be used to gain foothold on the machine. It then exp...

Jerry

HTB: Jerry Overview: Jerry is an Easy rated Windows machine on Hackthebox that exploits the upload of java applications (.war files) to gain foothold. Scanning and Enumeration So we start by ...

Grandpa

Overview: Grandpa is an Easy rated HTB machine that exploits a vulnerable IIS version to gain compromised access. HTB: Grandpa Scanning and Reconnaissance so we start by scanning for open ports...

Blue

HTB: Blue Overview: Blue is an Easy rated windows machine on Hackthebox that exploits the popular SMB vulnerability (EternalBlue: MS17-010) to gain compromised access as System on the machine. Sca...

Bashed

HTB: Bashed Overview: Bashed is an easy rated HTB machine that exploits a web facing php-bash console to gain compromised access and then exploits a cronjob running to gain a reverse shell as the ...

Authority

HTB: Authority Overview: Authority is a medium rated Windows machine that highlights the dangers of misconfigurations, password reuse, storing credentials on shares, and demonstrates how default s...

Access

Overview: Access is an Easy rated HTB machine that highlights how accessible FTP/file shares can often lead to getting a foothold or lateral movement. It also exploits saved credentials to gain pri...

Devel

tags: juicypotato, seimpersonateprivilege, ftp — HTB: Devel Overview: Devel is a HTB machine rated as easy on Hackthebox. This machine exploits a file upload in the open FTP server which can be...

Active

HTB: Active Overview: Active is an easy rated machine on HacktheBox. This machine exploits a GPP attack to obtain credentials which we then use to perform a kerberoast attack. After performing thi...