HackTheBox - Forge

Bypass SSRF filters using domain redirection and abusing Python PDB

HackTheBox - Intelligence

Intelligence brings some cool enumeration and exploitation techniques to own Active Directory. It …

HackTheBox - Dynstr

Dynstr imitates a company that offers a Dynamic DNS service. The provided API for this service is …

HackTheBox - Pit

As a medium difficulty box, Pit from Hack The Box has an interesting enumeration flow. It starts by …

HackTheBox - Schooled

Moodle exploitation using CVEs

HackTheBox - Gobox

SSTI in Golang, abuse S3 bucket, and NGINX backdoor

HackTheBox - Ophiuchi

Deserialization attack on YAML and reversing web assembly

HackTheBox - Tenet

Friendly PHP insecure deserialization attack and race condition

HackTheBox - Ready

Turns SSRF to remote code execution and escape from a Docker container

HackTheBox - Time

Exploiting an insecure deserialization on Jackson library and how to mitigate it

HackTheBox - Passage

USBCreator LPE on Linux

HackTheBox - Worker

Learn how Azure Pipelines can be abused

HackTheBox - SneakyMailer

Example of a phishing attack and PyPI package exploitation

HackTheBox - Tabby

Abusing Tomcat manager-script roles and escalate to root with LXC container

HackTheBox - Bucket

Pentesting against simulated AWS S3 Bucket

HackTheBox - Cascade

Plundering dead Active Directory accounts

HackTheBox - Magic

SQLi for login bypass and embed webshell to an image file