DevArea — Medium Linux machine walkthrough cover

DevArea — HackTheBox Season 10 Walkthrough

DevArea chains a SOAP service SSRF through Hoverfly middleware RCE to foothold, then escalates via Flask session forgery, command injection, and a symlink/log-write trick to root. A deeply layered box with real-world misconfigurations at every turn.

March 28, 2026 · 9 min · Logan Dawson
Kobold — Easy Linux machine walkthrough cover

Kobold — HackTheBox Season 10 Walkthrough

Kobold chains an unauthenticated MCP server command injection with a sneaky newgrp trick that quietly grants Docker group membership — all without a single password prompt.

March 21, 2026 · 7 min · Logan Dawson
Principal — Medium Linux machine walkthrough cover

Principal — HackTheBox Walkthrough

Principal chains a fresh CVE in pac4j-jwt — where encryption was mistaken for authentication — with SSH CA key abuse to go from zero to root on a Java Spring Boot platform.

March 12, 2026 · 7 min · Logan Dawson
CCTV — Easy Linux machine walkthrough cover

CCTV — HackTheBox Season 10 Walkthrough

CCTV is a deceptively layered Easy box where default credentials are just the beginning — JWT forgery, daemon-based command injection, and a clever motionEye auth quirk all stand between you and root.

March 5, 2026 · 8 min · Logan Dawson
Pirate — Hard Windows machine walkthrough cover

Pirate — HackTheBox Season 10 Walkthrough

Pirate is a brutal Hard-rated Windows Domain Controller that chains together gMSA password extraction, ADFS internals abuse, NTLM relay over a Hyper-V double-pivot, and SPN hijacking to reach Domain Admin — a genuine enterprise attack simulation.

February 27, 2026 · 14 min · Logan Dawson