Hack The Box
Hack The Box
Writeups for retired Hack The Box machines. Each post covers the full attack path: initial recon, foothold, privilege escalation, and any post-exploitation worth noting. Machines are retired at time of writing. Difficulty and key techniques are listed on each card.
Easy — Linux. IKE/IPSec PSK cracking, sudo 1.9.17 hostname bypass (CVE-2025-32462).
Easy — Windows. NFS enumeration, Umbraco RCE, TeamViewer CVE-2019-18988.
Medium — Linux. .git disclosure, PDO SQLi null-byte bypass, runkit RCE, RULE_PATH privesc.
Easy — Linux. os.path.join file write, cron execution, MD5 crack, needrestart CVE-2024-48990.
Last updated on