~ / writeups

hack the box_

Full attack-chain writeups for retired Hack The Box machines — from initial recon to root.

7 machines owned Linux User + Root

Retired machines, full chains from recon to root. → view my HTB profile

Cohort
Easy · SSRF → Marimo WebSocket RCE → PackageKit TOCTOU
→
Enigma
Easy · NFS → Roundcube → OpenSTAManager RCE → OliveTin injection
→
Management
Easy · OpenAM deserialization RCE → GLPI decryption → rdiff-backup
→
Nexus
Easy · Git-history leak → TinyMCE upload RCE → git-tree path traversal
→
Orion
Easy · Craft CMS object-injection RCE → telnetd auth bypass
→
Paperwork
Easy · LPD command injection → JetDirect traversal → SCM_RIGHTS leak
→
TwoMillion
Easy · API mass-assignment → command injection → OverlayFS kernel exploit
→