Altered

Overview This note documents what an attacker can see and abuse from an interactive mysql> prompt, using the Altered box as a training ground. It moves from enumeration, through file read/write, to remote code execution via user-defined functions (UDF). Context for Altered: the application database account holds the FILE privilege (which is why INTO OUTFILE succeeds), and the mysql process runs as its own dedicated user rather than root. That makes it an ideal environment for practising UDF and general_log tricks. ...

AlteredLinuxMedium
September 6, 2026 · 7 min

Enterprise

Overview Machine author: TheHermit. Host: Ubuntu, with Docker containers (Debian 8 Jessie). Theme: Star Trek: The Next Generation. Chain: recon, SQL injection in a custom WordPress plugin, credentials in a draft post, Joomla admin, PHP shell upload via eXtplorer, a www-data shell on the host (outside Docker), a SUID stack buffer overflow in /bin/lcars, root. The key trap: there are two different www-data shells. One is in a Docker container (WordPress/Joomla), the other is on the real host (via Apache on 443). Root only comes from the second one. ...

EnterpriseLinuxHard
September 6, 2026 · 9 min

Forge

Overview Machine author: NoobHacker9999. IP: 10.10.10.x. Technique categories: SSRF, SSRF filter bypass, redirect-based SSRF, data exfiltration, Python pdb privesc. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 enumeration (nmap, gobuster dir + vhost) v "Upload from URL" on forge.htb -> SSRF v localhost blacklist -> bypass via a 301 redirect from your own server v access to admin.forge.htb (localhost only) -> exfil /announcements (FTP creds user:heightofsecurity123!, /upload supports ftp://) v SSRF + ftp:// scheme -> read /home/user/.ssh/id_rsa v SSH as user -> user.txt v sudo python3 /opt/remote-manage.py -> force an exception -> pdb.post_mortem -> root shell v root.txt Three concepts to take away: ...

ForgeLinuxMedium
September 6, 2026 · 7 min

GoodGames

Overview Machine author: TheCyberGeek. IP: 10.10.10.x. Recon: only port 80 is open (Werkzeug/Python 3.9.2, a Flask application). SQL injection in the login form: authentication bypass plus a dump of the main database. The admin’s MD5 hash cracks to superadministrator. Subdomain internal-administration.goodgames.htb: a Flask panel, password reuse. SSTI in the profile field: RCE, a reverse shell, root inside a Docker container. Docker escape via a shared bind-mount plus the SUID bit: root on the host. Reconnaissance 1 2 ports=$(nmap -p- --min-rate=1000 -T4 10.10.10.x | grep ^[0-9] | cut -d '/' -f 1 | tr '\n' ',' | sed s/,$//) nmap -p$ports -sV -sC -Pn 10.10.10.x Port 80: Werkzeug/2.0.2 Python/3.9.2, title GoodGames | Community and Store. The footer reveals the domain goodgames.htb. ...

GoodGamesLinuxEasy
September 6, 2026 · 5 min

Media

Overview Windows Server 2022 (build 10.0.20348). Stack: Apache XAMPP + PHP 8.1. Stage Technique Result Recon nmap: 22 (SSH), 80 (HTTP), 3389 (RDP) Windows, a video upload form Foothold .wax/.asx playlist leaks Net-NTLMv2 via Responder hash for MEDIA\enox Crack hashcat -m 5600 + rockyou enox:1234virus@ Access SSH (WinRM/5985 is closed) shell as enox Lateral NTFS junction from Uploads\<md5> to C:\xampp\htdocs write a webshell as Apache Shell webshell + reverse shell nt authority\local service PrivEsc FullPowers (recover SeImpersonate) then GodPotato nt authority\system Two official paths to SYSTEM: ...

MediaWindowsMedium
September 6, 2026 · 10 min

Node

Overview Machine author: rastating. Focus: privilege escalation (misconfiguration / service abuse, and a ret2libc BOF). 1 2 3 4 5 6 7 8 9 10 recon +- leaky API /api/users/ -> crack hashes -> login as web admin v download myplace.backup (base64 -> zip) +- crack the zip password (john) -> application source -> Mongo creds v SSH as mark (password reuse) +- privesc #1 (mark -> tom): a Mongo-driven scheduler runs exec() as tom v privesc #2 (tom -> root): SUID /usr/local/bin/backup -> ret2libc BOF (plus unintended methods) Skills: API enumeration, credential reuse, service abuse through a database, SUID binary analysis (ltrace/Ghidra), ret2libc, NX + ASLR bypass, blacklist filter bypass. ...

NodeLinuxMedium
September 6, 2026 · 9 min

PermX

Overview Chamilo LMS 1.11.24, Ubuntu 22.04. Release: 2024-07-06. Retire: 2024-11-02. IP: 10.10.10.x. Chain: unauthenticated file upload to RCE (CVE-2023-4220), a reused Chamilo database password for the mtz system account, then a symlink-following sudo ACL script for root. Reconnaissance Port scan 1 2 nmap -p- --min-rate 10000 10.10.10.x nmap -p 22,80 -sCV 10.10.10.x Open ports: 22/tcp: OpenSSH 8.9p1 (Ubuntu 22.04 jammy) 80/tcp: Apache 2.4.52, redirects to http://permx.htb Subdomain fuzzing The server routes HTTP requests by the Host header, so fuzz subdomains: ...

PermXLinuxEasy
September 6, 2026 · 7 min

Pollution

Overview Machine author: Tr1s0n. IP: 10.10.10.x. Chain: forum token, escalation to admin, XXE (file / source read), Redis (session replacement), access to developers., LFI + PHP filter chain (RCE as www-data), PHP-FPM / FastCGI (pivot to victor), prototype pollution in a Node.js API (RCE as root). Reconnaissance 1 nmap -sV -sC -p- 10.10.10.x Open: 22 (SSH), 80 (HTTP). Redis (6379) is local only / password protected. 1 10.10.10.x collect.htb developers.collect.htb The vhost developers.collect.htb is protected by Basic Auth. ...

PollutionLinuxHard
September 6, 2026 · 5 min

Postman

Overview Machine author: TheCyberGeek. OS: Ubuntu 18.04.3 LTS (Bionic). 1 2 3 Redis 6379 (no auth) --SAVE authorized_keys to .ssh/--> shell as redis --crack /opt/id_rsa.bak (ssh2john + john) -> computer2008--> su Matt (password reuse) --Webmin 10000, CVE-2019-12840 command injection in `u`--> root Foothold: Redis listens without authentication; abuse SAVE to write an SSH public key to /var/lib/redis/.ssh/authorized_keys, shell as redis. Lateral movement: the encrypted private key /opt/id_rsa.bak is cracked by john (password computer2008); Matt reuses that as his system password; su Matt. Privilege escalation: log into Webmin with Matt’s credentials; CVE-2019-12840 (command injection in the Package Updates module, parameter u); Webmin runs as root, so RCE as root. Reconnaissance 1 2 nmap -p- --min-rate 10000 -oA scans/nmap-alltcp 10.10.10.x nmap -p 22,80,6379,10000 -sC -sV -oA scans/nmap-tcpscripts 10.10.10.x Port Service Version Notes 22 SSH OpenSSH 7.6p1 Ubuntu standard 80 HTTP Apache 2.4.29 (Ubuntu) “under construction” page 6379 Redis Redis 4.0.9 no authentication 10000 HTTP MiniServ 1.910 (Webmin httpd) HTTPS, admin panel Port 6379 (Redis) is the obvious foothold: open to the world, no password. Port 10000 (Webmin 1.910): a specific old version, worth keeping for privesc. Webmin runs as root, so any RCE there is root. Port 80 is a dead end. Gobuster: /images /upload /css /js /fonts, nothing useful. Initial Access Redis, shell as redis Redis 4.0-5.0 with a default, open configuration allows arbitrary disk writes with the privileges of the redis process: ...

PostmanLinuxEasy
September 6, 2026 · 9 min

RedCross

Overview Machine author: ompamo. Debian. A maze box with multiple paths at every stage. Key concepts: cookie reuse between subdomains, NSS + PostgreSQL as the backend for system accounts, command injection in a setuid wrapper, and a x64 ROP buffer overflow. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +- XSS (contact form) --------------+ admin.redcross.htb +- SQLi -> crack charles -----------+-> reuse PHPSESSID +- guest account -> cookie ---------+ | v +- Haraka SMTP RCE ---------------+ shell as penelope + +-> user.txt +- cmd injection (iptctl) -> www-data -> PostgreSQL creds -> add a user gid=1000 | v +- gid=27 (sudo) -> sudo su ------+ (unintended) root +- unixnssroot -> uid=0 -> su ----+ (intended) +- BOF in iptctl (setuid) -> ROP -+ (BOF path) | v root.txt Reconnaissance 1 2 3 22/tcp ssh OpenSSH 7.4p1 Debian 10+deb9u3 (Debian 9 Stretch) 80/tcp http Apache 2.4.25 443/tcp ssl/http Apache 2.4.25 Script scans (-sC) hang, so there is a WAF. Run only -sV. HTTP GET / redirects (301) to https://intra.redcross.htb. Add it to /etc/hosts. Domain and directory enumeration: ...

RedCrossLinuxMedium
September 6, 2026 · 8 min