root@kali:~$ ls ./writeups/machines

HTB Machine Write-ups

Complete, evidence-backed attack paths for retired Hack The Box machines.

8 published Retired content only RSS feed

Knowledge base

Retired machine archive

From initial enumeration to foothold, privilege escalation and final technical takeaways.

8 write-ups

Hack The Box

Hack The Box — CrossFitTwo

CrossFitTwo chains WebSocket SQL injection, DNS rebinding, CSWSH, Node.js module hijacking and YubiKey OTP forgery to achieve full OpenBSD root access.

Type
machine
Difficulty
Insane
OS
Other
openbsdwebsocket-sqliarbitrary-file-readunbounddns-rebinding
Read write-up
Hack The Box

Hack The Box — Mailroom

A practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.

Type
machine
Difficulty
Hard
OS
Linux
stored-xssssrfnosql-injectionmongodbsource-code-review
Read write-up
Hack The Box

Hack The Box — Caption

Caption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access.

Type
machine
Difficulty
Hard
OS
Linux
web-cache-poisoningweb-cache-deceptionxssrequest-smugglingh2c
Read write-up
Hack The Box

Hack The Box — Validation

Validation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials.

Type
machine
Difficulty
Easy
OS
Linux
web-securitysql-injectionmysqlinformation-schemafile-privilege
Read write-up
Hack The Box

Hack The Box — Soccer

A practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation.

Type
machine
Difficulty
Easy
OS
Linux
web-enumerationdefault-credentialsfile-uploadremote-code-executionwebsocket
Read write-up
Hack The Box

Hack The Box — Ghost

A hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise.

Type
machine
Difficulty
Insane
OS
Windows
active-directoryldap-injectionpath-traversalcommand-injectionkerberos
Read write-up
Hack The Box

Hack The Box — NodeBlog

Hack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation.

Type
machine
Difficulty
Easy
OS
Linux
nodejsexpressnosql-injectionmongodbxxe
Read write-up