Appointment — Very Easy Linux machine walkthrough cover

Appointment — HackTheBox Starting Point Walkthrough

Appointment is a deceptively simple box that teaches one of the most fundamental web vulnerabilities: SQL injection authentication bypass. One payload, one flag — but the lesson lasts a career.

February 1, 2026 · 5 min · Logan Dawson
Crocodile — Very Easy Linux machine walkthrough cover

Crocodile — HackTheBox Starting Point Walkthrough

Crocodile proves that the simplest misconfigurations can be devastating — an open FTP server hands you the keys to the web app if you know where to look.

February 1, 2026 · 4 min · Logan Dawson
Responder — Very Easy Windows machine walkthrough cover

Responder — HackTheBox Starting Point Walkthrough

A deceptively instructive box that chains LFI with NTLM hash theft — Responder shows how a single vulnerable parameter on a Windows web server can hand you administrator credentials.

February 1, 2026 · 5 min · Logan Dawson
Sequel — Very Easy Linux machine walkthrough cover

Sequel — HackTheBox Starting Point Walkthrough

Sequel is a dead-simple but instructive HackTheBox machine that highlights one of the most dangerous real-world misconfigurations: a MySQL/MariaDB instance exposed to the network with no root password.

February 1, 2026 · 4 min · Logan Dawson
Three — Starting Point Linux machine walkthrough cover

Three — HackTheBox Starting Point Walkthrough

A misconfigured S3-compatible bucket with an open write policy turns a static band website into a remote code execution opportunity. Here’s how subdomain enumeration and a single AWS CLI command led to a shell.

February 1, 2026 · 5 min · Logan Dawson
Oopsie — HackTheBox Linux machine walkthrough cover

Oopsie — HackTheBox Starting Point Walkthrough

Oopsie chains credential reuse, a cookie-based IDOR, and a file upload to land a shell — then a SUID binary with an unsafe PATH gets us root. A masterclass in chained misconfigurations.

January 31, 2026 · 7 min · Logan Dawson
Unified — Very Easy Linux machine walkthrough cover

Unified — HackTheBox Starting Point Walkthrough

Unified is a Very Easy Linux box that weaponizes the infamous Log4Shell vulnerability against an unpatched UniFi Network controller, then chains unauthenticated MongoDB access to go from nobody to root.

January 31, 2026 · 5 min · Logan Dawson
Vaccine — Very Easy Linux machine walkthrough cover

Vaccine — HackTheBox Starting Point Walkthrough

Vaccine chains together anonymous FTP access, zip cracking, hardcoded credentials, and a PostgreSQL SQL injection into a full compromise — then escapes to root through a classic vi sudo misconfiguration.

January 31, 2026 · 5 min · Logan Dawson
Archetype — HackTheBox Windows machine walkthrough cover

Archetype — HackTheBox Starting Point Walkthrough

Archetype shows how a single misconfigured SMB share cascades into full domain compromise — SSIS config files, xp_cmdshell, and PowerShell history all play a role.

January 30, 2026 · 6 min · Logan Dawson
Dancing — HackTheBox Windows machine walkthrough cover

Dancing — HackTheBox Starting Point Walkthrough

Dancing is a beginner-friendly Windows box that teaches the fundamentals of SMB enumeration. A misconfigured file share with anonymous access is all you need to grab the flag.

January 30, 2026 · 4 min · Logan Dawson