Hack The Box — Mailroom
A practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.
Read write-uproot@kali:~$ ls ./writeups
Reproducible attack paths, clear technical reasoning and lessons learned from authorized Hack The Box labs.
Knowledge base
Every entry follows the same reviewable structure: recon, foothold, escalation and takeaways.
6 write-ups
A practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.
Read write-upCaption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access.
Read write-upValidation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials.
Read write-upA practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation.
Read write-upA hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise.
Read write-upHack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation.
Read write-upTry a broader search or clear one of the filters.
Publication standard
Only commands and findings reproduced during the solve are documented.
Flags, personal secrets, VPN data and unrelated tokens are removed. Retired lab credentials appear only when they are essential to reproduce the attack path.
Public entries are limited to content permitted by Hack The Box publication rules.