CCTV — Easy Linux machine walkthrough cover

CCTV — HackTheBox Season 10 Walkthrough

CCTV is a deceptively layered Easy box where default credentials are just the beginning — JWT forgery, daemon-based command injection, and a clever motionEye auth quirk all stand between you and root.

March 5, 2026 · 8 min · Logan Dawson
Eighteen — HackTheBox Windows machine walkthrough cover

Eighteen — HackTheBox Retired Walkthrough

Eighteen is a Windows Server 2025 Domain Controller box that chains MSSQL impersonation, Werkzeug hash cracking, and the newly-disclosed BadSuccessor vulnerability (CVE-2025-53779) to achieve full domain compromise — a rare chance to exploit a live DC in a lab environment.

February 27, 2026 · 9 min · Logan Dawson
Interpreter — Medium Linux machine walkthrough cover

Interpreter — HackTheBox Season 10 Walkthrough

Interpreter chains a pre-auth deserialization RCE against a healthcare integration platform with a devious Python f-string injection to reach root — a box that rewards thorough enumeration and creative payload crafting.

February 27, 2026 · 8 min · Logan Dawson
Pirate — Hard Windows machine walkthrough cover

Pirate — HackTheBox Season 10 Walkthrough

Pirate is a brutal Hard-rated Windows Domain Controller that chains together gMSA password extraction, ADFS internals abuse, NTLM relay over a Hyper-V double-pivot, and SPN hijacking to reach Domain Admin — a genuine enterprise attack simulation.

February 27, 2026 · 14 min · Logan Dawson
Pterodactyl — Medium Linux machine walkthrough cover

Pterodactyl — HackTheBox Season 10 Walkthrough

A Minecraft panel hiding two CVEs and a SUSE-specific PAM trick — Pterodactyl chains a Laravel LFI into code execution, then escalates via a race-condition SUID mount flaw in udisks2.

February 26, 2026 · 8 min · Logan Dawson
WingData — Easy Linux machine walkthrough cover

WingData — HackTheBox Season 10 Walkthrough

WingData chains two fresh CVEs — an unauthenticated RCE in Wing FTP Server and a Python tarfile filter bypass via PATH_MAX overflow — into a clean root. Don’t let the ‘Easy’ rating fool you.

February 26, 2026 · 7 min · Logan Dawson
Monitorsfour — Medium Windows machine walkthrough cover

Monitorsfour — HackTheBox Retired Walkthrough

MonitorsFour chains a fresh Cacti RCE vulnerability with an exposed Docker API to go from web login to full Windows host compromise — a great lesson in container escape methodology.

February 6, 2026 · 6 min · Logan Dawson
Facts — Season 10 Release Arena Linux machine walkthrough cover

Facts — HackTheBox Season 10 Walkthrough

Facts chains a Rails mass-assignment CVE in CamaleonCMS to admin access, leaks MinIO credentials hiding a backdoored SSH key, and escapes to root through Puppet’s facter tool — a satisfying end-to-end story about trusting your CMS too much.

February 2, 2026 · 6 min · Logan Dawson
Unified — Very Easy Linux machine walkthrough cover

Unified — HackTheBox Starting Point Walkthrough

Unified is a Very Easy Linux box that weaponizes the infamous Log4Shell vulnerability against an unpatched UniFi Network controller, then chains unauthenticated MongoDB access to go from nobody to root.

January 31, 2026 · 5 min · Logan Dawson