ArticleHTB Academy - Get started
HTB Academy Get started: Build a practical, deep understanding of the Nmap flags you actually use during HTB/CTF and real engagements, then connect t…
Nmap scanning, service discovery, enumeration workflows, and practical command references.
ArticleHTB Academy Get started: Build a practical, deep understanding of the Nmap flags you actually use during HTB/CTF and real engagements, then connect t…
ArticleHTB Academy Firewall and IDS/IPS Evasion Medium Lab: After we conducted the first test and submitted our results to our client, the administrators ma…
ArticleHTB Academy Firewall and IDS/IPS Evasion Hard Lab: Re run web enumeration to identify the exact version of the service your client cares about (DNS o…
ArticleHTB Academy Firewall and IDS/IPS Evasion Easy Lab: Identify the operating system running on the target that sits behind IDS/IPS controls, and submit…
ArticleHTB Academy nmap scanning basics: Nmap Enumeration & Vulnerability Assessment The objective was divided into two tasks: 1. Find all TCP ports on your…
ArticleHTB Academy nmap network performance: Nmap Scanning Performance Optimization • HTB Academy • nmap
ArticleHTB Academy NSE Scripts: Use Nmap Scripting Engine (NSE) to enumerate a target, discover interesting HTTP paths, and recover the flag. I played with…
ArticleHTB Academy Service Enumeration: Enumerate all ports/services on the host and extract the flag exposed by one of the services. • HTB Academy • htb ac…
ArticleHTB Academy Host Discovery nmap: Fast, reliable host discovery during recon. These are my go‑to nmap one‑liners for ranges, lists, ad‑hoc targets, an…
ArticlePandora [Hack the box] [Blog] : started of with a nmap scan for • Security • nmap, private key
ArticlePaper [Hack the box] [BLOG]: regular scan • Security • nmap, security
ArticleHack The Box Help: Gain an initial foothold on 10.10.10.121 by exploiting an unauthenticated file upload in HelpDeskZ 1.0.2, obtain a reverse shell,…
ArticleHack The Box Explore user flag: Capture at least one user flag per day. This entry documents a box where initial scans missed the path to user, follo…
ArticleHack The Box Wall User and Root flag: Gain initial access to the host, then escalate privileges to root. • HackTheBox • brute force, nmap
ArticleHack The Box Luke User and Root flag: Gain initial foothold and escalate to read user and root flags, documenting the JWT weaknesses and the API/port…
ArticleHack The Box Bank user flag: Gain user access on bank.htb by abusing the support.php file upload to achieve remote code execution and retrieve the us…
ArticleHack The Box Sneaky: Enumerate a web server exposing only port 80. Pivot to SSH over IPv6 using a leaked RSA private key discovered via the /dev port…
ArticleHack The Box blue: Exploit MS17‑010 (EternalBlue) on the target and obtain shells for user and SYSTEM. • HackTheBox • metasploit, msf
ArticleHack The Box Joker: Gain initial access and escalate to root on 10.10.10.21, documenting each step with commands, reasoning, and evidence. • Security…
ArticleHack The Box Tentan: Gain user and root on the target at 10.10.10.10 by enumerating a WordPress site, abusing a vulnerable plugin to discover an uplo…
ArticleHack The Box Brainfuck: Gain initial access and retrieve the user flag on brainfuck.htb using web/app layer enumeration and misconfigurations. (Root…
ArticleHack The Box cronOS Complete: Break into Cronos (10.10.10.13), obtain user and then root flags. • HackTheBox • nmap, recon
ArticleHack The Box Lame user and root: Obtain user and root flags on 10.10.10.7 (HTB Beep) by abusing Elastix/vTigerCRM misconfigurations and a Local File…