Hack The Box Challenge — SocratesPanel
SocratesPanel chains fat-GET cache poisoning, reflected XSS, an admin-only SSRF and Redis inline-command injection to recover a cached secret.
Read write-uproot@kali:~$ ls ./writeups
Reproducible attack paths and evidence-led investigations from authorized Hack The Box Machines, Challenges and Sherlocks.
Knowledge base
Browse full machine attack paths, focused technical challenges and defensive Sherlock investigations.
16 write-ups
SocratesPanel chains fat-GET cache poisoning, reflected XSS, an admin-only SSRF and Redis inline-command injection to recover a cached secret.
Read write-upPhantomFeed chains a ReDoS-amplified registration race, Nuxt open redirect and OAuth token theft with ReportLab RCE to recover the flag.
Read write-upAlien Complaint Form combines stored HTML injection with an unsafe same-origin JSONP callback to bypass CSP and expose a bot-only cookie.
Read write-upHTB Proxy chains a DNS-based SSRF filter bypass, HTTP request smuggling and shell command injection to expose a randomized flag file.
Read write-upNexus Void chains scoped SQLite injection with unsafe Json.NET type handling to instantiate a command-running setter and achieve root code execution.
Read write-upVolnaya Forums chains nginx CRLF response splitting, path-scoped session fixation and self-XSS to execute code in an authenticated admin browser.
Read write-upE.Tree turns unsafe XPath construction into a boolean oracle, allowing two XML secret fragments to be recovered character by character.
Read write-upPhonebook exposes an LDAP wildcard injection that bypasses authentication and creates a response oracle for recovering a password one character at a time.
Read write-upPerspective chains SSI file disclosure, forged ASP.NET authentication, RC4 keystream reuse, ViewState deserialization and an AES padding oracle.
Read write-upCrossFitTwo chains WebSocket SQL injection, DNS rebinding, CSWSH, Node.js module hijacking and YubiKey OTP forgery to achieve full OpenBSD root access.
Read write-upA practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.
Read write-upCaption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access.
Read write-upValidation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials.
Read write-upA practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation.
Read write-upA hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise.
Read write-upHack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation.
Read write-upTry a broader search or clear one of the filters.
Publication standard
Only commands, analysis and findings reproduced during the solve are documented.
Flags, personal secrets, VPN data and unrelated tokens are removed before publication.
Public entries are limited to content permitted by Hack The Box publication rules.