Appointment — Very Easy Linux machine walkthrough cover

Appointment — HackTheBox Starting Point Walkthrough

Appointment is a deceptively simple box that teaches one of the most fundamental web vulnerabilities: SQL injection authentication bypass. One payload, one flag — but the lesson lasts a career.

February 1, 2026 · 5 min · Logan Dawson
Crocodile — Very Easy Linux machine walkthrough cover

Crocodile — HackTheBox Starting Point Walkthrough

Crocodile proves that the simplest misconfigurations can be devastating — an open FTP server hands you the keys to the web app if you know where to look.

February 1, 2026 · 4 min · Logan Dawson
Responder — Very Easy Windows machine walkthrough cover

Responder — HackTheBox Starting Point Walkthrough

A deceptively instructive box that chains LFI with NTLM hash theft — Responder shows how a single vulnerable parameter on a Windows web server can hand you administrator credentials.

February 1, 2026 · 5 min · Logan Dawson
Sequel — Very Easy Linux machine walkthrough cover

Sequel — HackTheBox Starting Point Walkthrough

Sequel is a dead-simple but instructive HackTheBox machine that highlights one of the most dangerous real-world misconfigurations: a MySQL/MariaDB instance exposed to the network with no root password.

February 1, 2026 · 4 min · Logan Dawson
Unified — Very Easy Linux machine walkthrough cover

Unified — HackTheBox Starting Point Walkthrough

Unified is a Very Easy Linux box that weaponizes the infamous Log4Shell vulnerability against an unpatched UniFi Network controller, then chains unauthenticated MongoDB access to go from nobody to root.

January 31, 2026 · 5 min · Logan Dawson
Vaccine — Very Easy Linux machine walkthrough cover

Vaccine — HackTheBox Starting Point Walkthrough

Vaccine chains together anonymous FTP access, zip cracking, hardcoded credentials, and a PostgreSQL SQL injection into a full compromise — then escapes to root through a classic vi sudo misconfiguration.

January 31, 2026 · 5 min · Logan Dawson