HackTheBox: Editorial

Enumeration 1 export target=10.129.50.62 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target -oN nmap_editorial Add it to the /etc/hosts 1 echo '10.129.50.62 editorial.htb' | sudo tee -a /etc/hosts Web Application (80) There is a book upload page I’ve tried to upload a php file VHost fuzzing, no luck There is a cover URL we can provide, try SSRF: ...

August 17, 2026 · 3 min · 445 words · burkocyigit

HackTheBox: Builder

Enumeration 1 export target=10.129.230.220 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,8080 -T5 $target Web Application (8080) Jenkins 2.441 There is a user, jennifer On Jenkins 2.441 there is a arbitrary file read vulnerability, CVE-2024-23897, and there is a public exploit for it: https://github.com/godylockz/CVE-2024-23897 We can get the var/jenkins_home/users/users.xml There is a user directory jennifer_12108429903186576833, let’s read its config file ...

August 14, 2026 · 1 min · 199 words · burkocyigit

HackTheBox: Dog

Enumeration 1 export target=10.129.231.223 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add dog.htb to hosts Nmap says there is are git repo found. Let’s download it. 1 wget -r -np -R "index.html*" http://$target Looking around, I find the mysql password of root 1 BackDropJ2024DS2024 Found another user in the repo: 1 tiffany Web Application (80) Blog, powered by Backdrop CMS ...

August 12, 2026 · 2 min · 255 words · burkocyigit

HackTheBox: Knife

Enumeration 1 export target=10.129.48.60 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Initial Foothold PHP version is 8.1.0-dev It has a RCE exploit (www.exploit-db.com/exploits/49933) Persistence 1 ssh-keygen -t ed25519 -f persist -N '' 1 2 3 4 5 6 7 $ mkdir ~/.ssh $ chmod 700 ~/.ssh $ echo "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINxWXXtr3AsLHPThSrbfRuFUTfqCcghxiINCr9pz5rEg burak@kali" > ~/.ssh/authorized_keys $ chmod 600 ~/.ssh/authorized_keys ...

August 12, 2026 · 1 min · 134 words · burkocyigit

HackTheBox: Precious

Enumeration 1 export target=10.129.48.66 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add it to the etc/hosts Web Application Smells like SSRF or LFI, test it out. Setup a server: 1 python3 -m http.server 8000 Initial Foothold Server uses Ruby and pdfkit to convert to PDFs. pdfkit 0.8.6 has a command injection vulnerability and has a public exploit (https://github.com/UNICORDev/exploit-CVE-2022-25765) ...

August 12, 2026 · 3 min · 454 words · burkocyigit

HackTheBox: Codify

Enumeration 1 export target=10.129.47.211 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80,3000 -T5 $target -oN nmap_codify Add codify.htb to hosts: 1 echo "10.129.47.211 codify.htb" | sudo tee -a /etc/hosts Web Application (80) We can execute code, there are some limitations though: We learn that it uses vm2: Link redirects to github and the version is 3.9.16. Let’s search for a vulnerability if any exists. ...

August 11, 2026 · 3 min · 595 words · burkocyigit

HackTheBox: CozyHosting

Enumeration 1 export target=10.129.229.88 Port Scanning 1 rustscan -a $target --ulimit 10000 -g 1 nmap -Pn -sC -sV -n -p22,80 -T5 $target Add cozyhosting.htb to hosts 1 echo "10.129.229.88 cozyhosting.htb" | sudo tee -a /etc/hosts Web Application (80) Portfolio page There is a login page as well: Vhost fuzz 1 ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u http://cozyhosting.htb/ -H 'Host: FUZZ.cozyhosting.htb' --ac Nothing shows up. Directory Search 1 dirsearch -u http://cozyhosting.htb/ A lot of output, but the actuator is interesting: ...

August 11, 2026 · 2 min · 276 words · burkocyigit

HackTheBox: Busqueda

Enumeration 1 export target=10.129.47.156 Port Scanning Add the domain to hosts: 1 sudo nano /etc/hosts Web Application (port 80) We see some kind of search engine: We see a version info on the footer: Searchor 2.4.0. Let’s search it if it is vulnerable. After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC. https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection Download the PoC: 1 git clone https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection.git ...

August 10, 2026 · 2 min · 299 words · burkocyigit