HackTheBox - Blue
Blue is a classic beginner-friendly Windows machine that lives up to its name. Recon quickly surfaces a well-known SMB weakness, and a public exploit does the rest — landing a shell with no privilege escalation step required.
Blue is a classic beginner-friendly Windows machine that lives up to its name. Recon quickly surfaces a well-known SMB weakness, and a public exploit does the rest — landing a shell with no privilege escalation step required.
Lame is one of HTB’s oldest retired machines and a staple for beginners. The attack surface is small but telling — a quick scan surfaces a notoriously vulnerable service version that leads straight to a root shell in a single step, with no privilege escalation required.
This box involves exploiting a known deserialization vulnerability in a self-hosted ML platform, then chaining it with a misconfigured sudo permission to escalate privileges via a malicious PyTorch model file.
This module is designed to help you understand and learn the basic concepts of different password attacks.
A Linux machine where a publicly exposed JAR file reveals a vulnerable internal SOAP service, and a chain of misconfigurations — from exposed credentials to a world-writable binary — leads all the way to root.
Version 1.0