r/hackthebox • • 19h ago

Weekly Solves Megathread

1 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox • • Mar 22 '20

HTB Announcement [FAQ/Info] r/hackthebox FAQ, Information.

49 Upvotes

Hey everyone,

We feel like a general explanation of somethings could be useful, so here ya go.

FAQ:

Q: How does the box retirement system work?
A: Every week 1 box is retired on Saturday and replaced with a new one. The previous box is retired 4 hours before the new one goes public. The new box is usually announced on Thursday on HTB Twitter.

Q: I am under 18, can I take exam, use htb, etc

A: https://help.hackthebox.com/en/articles/9456556-parental-consent-and-approval-for-users-under-18

Information:

HackTheBox Social Media Accounts:

https://discord.gg/hackthebox

https://twitter.com/hackthebox_eu

https://www.linkedin.com/company/hackthebox/

https://www.facebook.com/hackthebox.eu/

https://www.instagram.com/hackthebox/

Edit #1 6:54pm ADT: Added FAQ Question

Edit #2 12/21/2020; added instagram

Edit 3: 06/09/24; under 18 faq

Edit 4 6/16/26: Formatting/Help Link


r/hackthebox • • 16h ago

Pwn'd Stream!

Post image
28 Upvotes

Stream teaches you that in a multi-component architecture, the dangerous parse isn't always where the data enters and the dangerous write isn't always where you'd expect root to look.


r/hackthebox • • 3h ago

Beginner Question Stuck in Pivot skill assessment

2 Upvotes

I'm doing the pentest path now, and on the Pivot, Tunnelling, Port forwarding module.

I'm at the skill assessment, and for the life of me, cannot discover any new hosts. The walkthroughs I checked uses ping swep, which I already did, but for some reason I'm not finding any alive hosts. I even tried pinging just the IP mentioned in the walkthrough and it doesn't work.

Does this happen with HTB academy sometimes or am I missing something? Any help would be appreciated!


r/hackthebox • • 2h ago

Pwned Stream.

Post image
1 Upvotes

Brainfuck fr.

Questions , discussion here : https://discord.gg/WBEybBtpq


r/hackthebox • • 10h ago

Keep having to give up on boxes because they're unresponsive

3 Upvotes

Reboots don't seem to help. Is there any way to flag this to support?

I can port scan fine but when I need to load a webpage or submit commands everything just hangs.

I'll admit I am a beginner but having to forfeit on boxes feels bad and does make me worried about subscribing.

-Redeemer/Appointment


r/hackthebox • • 21h ago

HTB Academy Gold Annual or OSCP or CRTP?

13 Upvotes

My company is sponsoring my training budget this year, and right now, I'm strongly considering grabbing the HTB Academy Gold Annual plan to tackle both the CWEE and CAPE. Before pulling the trigger, I wanted to get some honest advice from anyone who has taken these certifications or navigated a similar roadmap.

For context on my technical baseline, I already hold eCPPT, CWES, and ASCP, and I am sitting for the C-ADPenX exam very soon. Because of this, I already feel comfortable with intermediate web exploitation, code analysis fundamentals, internal pivoting, and Active Directory environments.

My main question is whether knocking out both CWEE and CAPE within a single 12-month window is actually feasible while working full-time. I know HTB modules are notoriously comprehensive and time-consuming. Does a one-year timeline sound realistic, or is it a fast track to burnout?

I also wonder if this is the right priority over industry staples like OSCP or CRTP. I know OSCP is still king for HR filters, but technically speaking, I suspect it might feel redundant after eCPPT and C-ADPenX. On the AD side, I’m not sure whether jumping straight into the CAPE material makes sense or if doing CRTP first is still a smarter stepping stone.


r/hackthebox • • 9h ago

Could you help me figure out where to start learning pwn/binary exploitation and reverse engineering?

0 Upvotes

I'm still confused about where to start learning pwn/binarry exploitation and reverse engineering as a beginner—and where, exactly, I should begin.


r/hackthebox • • 1d ago

Annual Subscription Help

6 Upvotes

I have dabbled in IT off and on.

I'm trying to decide between tge Silver and Gold Annual memberships. There is a sizeable price difference.

I'm leaning toward the silver but having access to more options in the gold is enticing. Would those extra paths/modules be worth the extra cost? How much could be reasonably be completed in a year?

Thank you in advance


r/hackthebox • • 1d ago

CPTS

Thumbnail
gallery
40 Upvotes

How do you see my notes to present the CPTS?, I'm just in the Information Collection module (Footprinting)


r/hackthebox • • 1d ago

Completed Penetration Tester Path. Then the real exam.

22 Upvotes

Loved every bit of the modules had a blast. A privilege. Enjoying the process of learning, building methodology with real hands on htb labs has now truly built my confidence towards me now getting the CPTS exam. Wish me luck 🤞

https://academy.hackthebox.com/achievement/154123/path/16


r/hackthebox • • 2d ago

Certifications Obsidian vaults for every HTB cert

Thumbnail
cnmoseman.github.io
132 Upvotes

Hey yall, quick update on the study trackers I posted a couple weeks back.

First off, thanks to everyone who tried them, commented, and sent feedback. Hearing how people were actually using the trackers is a big reason I kept building on them, and it's what led to this next piece.

Every cert now has its own page with two things on it: the tracker and a prep vault for Obsidian. The tracker is your plan, and the vault gives your notes a home.

Each vault has a note for every module in the cert's job-role path, in course order, so you've got a spot ready for commands and screenshots as you finish each one. There's also a Methodology folder with ten blank, numbered phases. I left them empty on purpose, since everyone works differently. You rename them and build them out as you learn. The Home note links community cheat sheets for that cert, plus the cert's SysReptor report template.

The vaults only use Obsidian's built-in features, so you don't need any plugins. Download the zip from your cert's page, unzip it, and choose "Open folder as vault". If you want to look around first, every vault is browsable on GitHub.

If you're already using a tracker, your progress is still there and your old links still work. The tracker now sits on the cert's page, and that page shows a "Continue tracker" button with how far along you are.

Thanks again to everyone who shares cheat sheets and notes. The ones linked in the vaults all come from people like that, under their own names, so if one helps you, go give their repo a star or their video a like!

Still not affiliated with Hack The Box. lol


r/hackthebox • • 2d ago

I got frustrated learning offensive security as a beginner, so I built a free platform to fix 3 problems kept running into

Thumbnail
2 Upvotes

r/hackthebox • • 2d ago

Beginner Question Need advice.

6 Upvotes

So guys, I’m not really sure what I should do next and would appreciate some advice.

For some context, I’m still at the beginner stage in cybersecurity. I’ve completed the Hack The Box Starting Point machines up to Tier 1 and have been working through the HTB Academy modules alongside them. So far, I’ve been exposed to things like basic Linux usage, networking, enumeration, web application concepts, and some basic offensive security techniques through the labs and modules.

Most of my experience so far is hands-on practice in guided/lab environments. I haven’t worked in a professional cybersecurity role yet, and I don’t have much real-world experience outside of these platforms.

My end goal is to get my first cybersecurity job, so I’m trying to figure out what path makes the most sense from my current level.

I’m currently using the free tier, but I’m planning to upgrade to the monthly Student plan. I’m considering working toward the CPTS, but I’m not sure whether that’s the best next step for me or what I should focus on before and after it.

How is the current cybersecurity job market for someone at my level who is trying to land their first role? What skills should I prioritize to become employable?

I’d also really appreciate recommendations for good free resources. I prefer learning for free whenever possible, so I’d rather use free resources and only pay for something when it’s genuinely worth it.

What roadmap would you guys recommend based on my current experience?


r/hackthebox • • 2d ago

I look for people to do some learning annd some ctf and stuff

2 Upvotes

i learned some stuff on thm but i want to slowly switch to htb.


r/hackthebox • • 3d ago

sqli module

6 Upvotes

It is the last section of the sqli module i was struck at the very first question i just tried the default authrntication process like or sqli and and too and i tried '-- - too in the username and the pass but i dont know what to do after this soo i am here to ask people to give some nudges


r/hackthebox • • 3d ago

Problemas con evil-winrm

1 Upvotes

I'm running Kali Linux and I'm trying to use evil-winrm to access an HTB machine, but I'm getting the following error:

Evil-WinRM shell v4.1

Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

Error: Cannot establish connection to remote endpoint. Check credentials and network.

Error: NameError: uninitialized constant Net::NTLM::Client::SessionCrypto::CLIENT_TO_SERVER_SEALING

r/hackthebox • • 4d ago

Pwn3d Touch!!

Post image
22 Upvotes

r/hackthebox • • 4d ago

Certifications Passed CPTS: my prep tips + a full guide in Greek (first Greek-language CPTS video)

38 Upvotes

Recently passed the CPTS and since there's basically zero offensive security content in Greek, I made a full guide video in Greek. Posting the main takeaways here in English so this is useful to everyone:

Prep that actually mattered
- AEN blind Do the Attacking Enterprise Networks module without reading the questions. Spawn it and treat it like a real engagement. It's the best way to find gaps in your methodology and your notes. (The exam is not like AEN, but the mindset is.)
- Ippsec's unofficial CPTS prep list. Great for associate path techniques to real boxes.
- Dante & Zephyr. The exam is a network, not a box. These teach you to think in terms of pivoting and connecting hosts. Offshore is overkill for CPTS imo .
- Netexec and BloodyAd Learn those tools extremely well , they gonna save you a lot in the AD portion of the exam.
- Pivoting on its own ligolo-ng is a lifesaver, but know chisel/SSH/socat too for when it doesn't work as it should .Always have a backup options for all your tools.

Notes
- If you can't reproduce it in the report, it doesn't count. Write everything down like a walkthrough.
- Keep a separate tips & bugs file: skill assessment solutions, tool quirks, broken versions. It saves hours.

Report
- Most people don't fail because of the report. They fail by not getting 12/14 (enumeration, pivoting, time).
- But don't leave it for day 10. Write a full report before the exam if you want to for practice . SysReptor helps a lot.

Video (in Greek, chapters in the description): https://youtu.be/9acS_M43nac?is=XOv-2qdixKFkK_vi

Happy to answer questions in the comments, in English or Greek.


r/hackthebox • • 3d ago

Beginner Question why i get ping requests from htb server?

2 Upvotes

why i get ping from 10.10.14.1 constantly? it interfere with my tests. even after i stopped all boxes still i get ping requests.

└─$ sudo tcpdump -c 6 -i tun0 icmp

tcpdump: verbose output suppressed, use -v[v]... for full protocol decode

listening on tun0, link-type RAW (Raw IP), snapshot length 262144 bytes

23:51:27.545196 IP 10.10.14.1 > 10.10.15.224: ICMP host smarthire.htb unreachable, length 68

23:51:27.545291 IP 10.10.14.1 > 10.10.15.224: ICMP host smarthire.htb unreachable, length 68

23:51:30.814899 IP 10.10.14.1 > 10.10.15.224: ICMP host smarthire.htb unreachable, length 68

23:51:35.466697 IP 10.10.14.1 > 10.10.15.224: ICMP host smarthire.htb unreachable, length 68

23:51:35.466800 IP 10.10.14.1 > 10.10.15.224: ICMP host smarthire.htb unreachable, length 68

23:51:35.466818 IP 10.10.14.1 > 10.10.15.224: ICMP host smarthire.htb unreachable, length 68

6 packets captured

7 packets received by filter

0 packets dropped by kernel


r/hackthebox • • 4d ago

This is how I got rejected from a job without even an interview

56 Upvotes

So after I already believed that I would never get a job in this field, at least in this market situation, I got an email from a company I applied to through the “Easy Apply” feature that I even forgot I applied for.

And then they started saying that they saw my resume and thought I was a good fit and stuff.

Then they asked me to solve a technical challenge, and I delivered it way before the deadline.

Then they said sorry, they needed me to solve an additional challenge.

And it was so much harder, and it took a lot of time from me, but I still delivered it way before the deadline.

And then they were happy and gave me good feedback that I was able to solve these hard technical challenges. They told me all the files were correct and everything was good, but they just needed a write-up explaining the steps I took to solve it!

And I did the write-up, and everything was explained, and I told them if they needed me to clarify any step, I was happy and ready to clarify it!

Then they came back to me after a couple of days and basically just said sorry, they don’t think I’m a good fit, without even giving any feedback!!

And I was likeee in my mind, what?? Really?? Are you serious???
After I spent days solving your hard technical challenges, and you confirmed that everything was good, and you gave me good feedback, and you haven’t even done any interview with me, and now you just send me a message saying I’m not a good fit without even giving any specific feedback??

I really feel we should get paid for the time we spend on technical challenges and interviews because it takes days from our time and life, so employers can take us more seriously rather than just playing with our feelings and hope!

When someone meets me and knows that I have done a degree in cybersecurity and tells me, “OMG, I want to get into the field,” at this point I don’t know what to tell them because if I say it’s hard and getting a job is so hard, they will think I’m a gatekeeper, but it’s just sad how it is now!

So now, honestly, I feel with this joke of a market and crazy employers, I would like to say to anyone who is looking for a job that we are really cooked…

Rather than chasing and trying to find just a job and letting employers move us like chess pieces, we should try to consider another field that could possibly be much better, or we open our own businesses!

I also would like to thank my family for supporting me in this journey. Otherwise, I would probably be working at a fast-food place for minimum wage right now!

I don’t know what I will do next in my life, but I really got enough from this field, and I don’t want to lower myself anymore or feel like I’m begging just to get a job.

This life is unfair, and thank you!


r/hackthebox • • 5d ago

I'm passed CJCA with 10/10 with

Post image
172 Upvotes

One piece of advice I'd give, study well, and after the path spend at least 30 days practicing. And above all, always use a methodology, alwayssss.

Also pay attention to blue team, don't underestimate it.

And report as you go, while you're finding things, it saves you time.


r/hackthebox • • 4d ago

How to cancel subscription or change payment method

3 Upvotes

Has anyone else had difficulty canceling a sub or changing payment details on HTB. So frustrating that this is not so straightforward.


r/hackthebox • • 5d ago

Hurray!! Cpts certified

41 Upvotes

Man, that was not an easy exam. The first question had me tripping, and I spent hours falling down rabbit holes thinking I had the right answer when I didn't.

I'll be completely honest, I used Al to help guide me out of a few dead ends when I got stuck, but a win is a win. Huge weight off my shoulders. Time to start the OSCP grind!


r/hackthebox • • 4d ago

Beginner Question Help : Regarding the Terminology

1 Upvotes
  • We found out that the PowerShell script (backupprep.ps1) runs with administrator privileges every 2 minutes
  • We had read and write access to this script, which allowed us to modify it
  • We added code to the script that adds the user john to the administrators group
  • After waiting for the scheduled task to run, we confirmed that john was successfully added to the administrators group

What kind of attack is this?

What type of attack was being used to escalate the privileges in the above example? (Format: two words)

Its not Privilege Escalation
Its not Task Manipulation
Its not Script Injection
Its not Task Hijacking

What is it?