root@kali:~$ ls ./writeups

Hack The Box Write-ups

Reproducible attack paths and evidence-led investigations from authorized Hack The Box Machines, Challenges and Sherlocks.

16 published Retired content only RSS feed

Knowledge base

Field notes from the labs

Browse full machine attack paths, focused technical challenges and defensive Sherlock investigations.

16 write-ups

Hack The Box

Hack The Box Challenge — SocratesPanel

SocratesPanel chains fat-GET cache poisoning, reflected XSS, an admin-only SSRF and Redis inline-command injection to recover a cached secret.

Type
challenge
Difficulty
Hard
Category
Web
web-cache-poisoningfat-getreflected-xssrace-conditionssrf
Read write-up
Hack The Box

Hack The Box Challenge — PhantomFeed

PhantomFeed chains a ReDoS-amplified registration race, Nuxt open redirect and OAuth token theft with ReportLab RCE to recover the flag.

Type
challenge
Difficulty
Hard
Category
Web
web-securityrace-conditionregular-expression-dosoauth2open-redirect
Read write-up
Hack The Box

Hack The Box Challenge — Alien Complaint Form

Alien Complaint Form combines stored HTML injection with an unsafe same-origin JSONP callback to bypass CSP and expose a bot-only cookie.

Type
challenge
Difficulty
Medium
Category
Web
web-securitystored-xsscsp-bypassjsonphtml-injection
Read write-up
Hack The Box

Hack The Box Challenge — HTB Proxy

HTB Proxy chains a DNS-based SSRF filter bypass, HTTP request smuggling and shell command injection to expose a randomized flag file.

Type
challenge
Difficulty
Medium
Category
Web
web-securityssrfhttp-request-smugglingcommand-injectionparser-differential
Read write-up
Hack The Box

Hack The Box Challenge — Nexus Void

Nexus Void chains scoped SQLite injection with unsafe Json.NET type handling to instantiate a command-running setter and achieve root code execution.

Type
challenge
Difficulty
Medium
Category
Web
web-securitysql-injectionunsafe-deserializationdotnetjson-net
Read write-up
Hack The Box

Hack The Box Challenge — Volnaya Forums

Volnaya Forums chains nginx CRLF response splitting, path-scoped session fixation and self-XSS to execute code in an authenticated admin browser.

Type
challenge
Difficulty
Easy
Category
Web
web-securitycrlf-injectionsession-fixationstored-xsscookie-path
Read write-up
Hack The Box

Hack The Box Challenge — E.Tree

E.Tree turns unsafe XPath construction into a boolean oracle, allowing two XML secret fragments to be recovered character by character.

Type
challenge
Difficulty
Easy
Category
Web
web-securityxpath-injectionblind-injectionxmlresponse-oracle
Read write-up
Hack The Box

Hack The Box Challenge — Phonebook

Phonebook exposes an LDAP wildcard injection that bypasses authentication and creates a response oracle for recovering a password one character at a time.

Type
challenge
Difficulty
Easy
Category
Web
web-securityldap-injectionauthentication-bypassblind-injectionresponse-oracle
Read write-up
Hack The Box

Hack The Box — CrossFitTwo

CrossFitTwo chains WebSocket SQL injection, DNS rebinding, CSWSH, Node.js module hijacking and YubiKey OTP forgery to achieve full OpenBSD root access.

Type
machine
Difficulty
Insane
OS
Other
openbsdwebsocket-sqliarbitrary-file-readunbounddns-rebinding
Read write-up
Hack The Box

Hack The Box — Mailroom

A practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.

Type
machine
Difficulty
Hard
OS
Linux
stored-xssssrfnosql-injectionmongodbsource-code-review
Read write-up
Hack The Box

Hack The Box — Caption

Caption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access.

Type
machine
Difficulty
Hard
OS
Linux
web-cache-poisoningweb-cache-deceptionxssrequest-smugglingh2c
Read write-up
Hack The Box

Hack The Box — Validation

Validation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials.

Type
machine
Difficulty
Easy
OS
Linux
web-securitysql-injectionmysqlinformation-schemafile-privilege
Read write-up
Hack The Box

Hack The Box — Soccer

A practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation.

Type
machine
Difficulty
Easy
OS
Linux
web-enumerationdefault-credentialsfile-uploadremote-code-executionwebsocket
Read write-up
Hack The Box

Hack The Box — Ghost

A hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise.

Type
machine
Difficulty
Insane
OS
Windows
active-directoryldap-injectionpath-traversalcommand-injectionkerberos
Read write-up
Hack The Box

Hack The Box — NodeBlog

Hack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation.

Type
machine
Difficulty
Easy
OS
Linux
nodejsexpressnosql-injectionmongodbxxe
Read write-up

Publication standard

Built for learning, not spoilers

Verified steps

Only commands, analysis and findings reproduced during the solve are documented.

Sanitized evidence

Flags, personal secrets, VPN data and unrelated tokens are removed before publication.

Publishable content

Public entries are limited to content permitted by Hack The Box publication rules.