DevArea — Medium Linux machine walkthrough cover

DevArea — HackTheBox Season 10 Walkthrough

DevArea chains a SOAP service SSRF through Hoverfly middleware RCE to foothold, then escalates via Flask session forgery, command injection, and a symlink/log-write trick to root. A deeply layered box with real-world misconfigurations at every turn.

March 28, 2026 · 9 min · Logan Dawson
WingData — Easy Linux machine walkthrough cover

WingData — HackTheBox Season 10 Walkthrough

WingData chains two fresh CVEs — an unauthenticated RCE in Wing FTP Server and a Python tarfile filter bypass via PATH_MAX overflow — into a clean root. Don’t let the ‘Easy’ rating fool you.

February 26, 2026 · 7 min · Logan Dawson
Crocodile — Very Easy Linux machine walkthrough cover

Crocodile — HackTheBox Starting Point Walkthrough

Crocodile proves that the simplest misconfigurations can be devastating — an open FTP server hands you the keys to the web app if you know where to look.

February 1, 2026 · 4 min · Logan Dawson
Vaccine — Very Easy Linux machine walkthrough cover

Vaccine — HackTheBox Starting Point Walkthrough

Vaccine chains together anonymous FTP access, zip cracking, hardcoded credentials, and a PostgreSQL SQL injection into a full compromise — then escapes to root through a classic vi sudo misconfiguration.

January 31, 2026 · 5 min · Logan Dawson
Fawn — HackTheBox Unix machine walkthrough cover

Fawn — HackTheBox Starting Point Walkthrough

Fawn is a beginner HackTheBox machine that demonstrates one of the most common real-world misconfigurations: anonymous FTP access left enabled with sensitive files sitting in the root directory.

January 30, 2026 · 4 min · Logan Dawson