Section Contents

  • 📄 HTB: Bashed

    A beginner box demonstrating the danger of public web shells and misconfigured sudo permissions.

  • 📄 HTB: Beep

    Exploiting Elastix VoIP software. A box with 6 different entry points including LFI, Shellshock, and weak passwords.

  • 📄 HTB: Cap

    Analyzing packet captures (PCAP) to find plain text creds and abusing Linux Capabilities (setcap) for root.

  • 📄 HTB: Lame

    A comprehensive walkthrough of the first Machine on HackTheBox. Exploiting Samba (CVE-2007-2447) and Distcc (CVE-2004-2687).

  • 📄 HTB: Nibbles

    Exploiting 'Nibbleblog' via an image upload plugin CVE and modifying a monitor script for root.

  • 📄 HTB: Shocker

    Classic Shellshock (CVE-2014-6271) exploitation against a CGI script.