โŒ

Normal view

There are new articles available, click to refresh the page.
Before yesterdayThreatninja.net

Hack The Box: Kobold Machine Walkthrough โ€“ Easy Difficulty

By: darknite
1 August 2026 at 10:58

Completed the Hack The Box "Kobold" machine, an easy-difficulty Linux challenge focused on web exploitation and container-based privilege escalation.

The assessment involved identifying and exploiting an unauthenticated Remote Code Execution vulnerability (CVE-2026-23744) in MCPJam Inspector to gain initial access as the ben user. During the privilege escalation phase, I explored Docker security weaknesses by leveraging excessive group permissions to escape the container environment and obtain root access. Additionally, I analyzed an alternative attack path involving CVE-2025-64714 in PrivateBin, which allowed sensitive configuration data exposure and access to the Arcane container management interface. This machine provided practical experience in vulnerability exploitation, container security assessment, and identifying risks associated with exposed internal services.

#HackTheBox #HTB #CyberSecurity #PenetrationTesting #OffensiveSecurity #RedTeam #Linux #Docker #VulnerabilityManagement #CVE #EthicalHacking #CybersecurityLearning โ€ฆ

Learn MoreHack The Box: Kobold Machine Walkthrough โ€“ Easy Difficulty

The post Hack The Box: Kobold Machine Walkthrough โ€“ Easy Difficulty appeared first on Threatninja.net.

Hack The Box: Fries Machine Walkthrough โ€“ Hard Difficulty

By: darknite
25 July 2026 at 10:58

Just wrapped up another Hack The Box machine: Fries (Hard).

TThis machine provided a realistic attack path that started with source code review in Gitea, where leaked credentials in a Git commit led to authenticated PostgreSQL RCE through pgAdmin. From there, I pivoted through the internal Docker network using Ligolo-ng, abused an exposed NFS share and debugfs to gain host access, then exploited PWM configuration weaknesses to capture LDAP credentials. The final stage involved Active Directory enumeration and AD CS (ESC6/ESC7) abuse to obtain an administrator certificate and compromise the domain. A great lab for practising web exploitation, Docker security, Linux privilege escalation, internal pivoting, and Active Directory attacks.

#HackTheBox #HTB #CyberSecurity #PenetrationTesting #RedTeam #ActiveDirectory #ADCS #Docker #Ligolo #PostgreSQL #Gitea #EthicalHacking #Writeup #CTF โ€ฆ

Learn MoreHack The Box: Fries Machine Walkthrough โ€“ Hard Difficulty

The post Hack The Box: Fries Machine Walkthrough โ€“ Hard Difficulty appeared first on Threatninja.net.

โŒ
โŒ