Skip to content

Pwned Machines

Full attack chains on retired Hack The Box machines — enumeration to root, every step documented.

Disclaimer

Writeups are only published for retired machines in accordance with Hack The Box's rules. No active machine solutions are shared here.

// filter targets
🖥️ Windows 🔥 Medium
HTB Querier Walkthrough
Step-by-step Hack The Box Querier walkthrough. Exploit hardcoded Excel macro credentials, capture MSSQL NTLMv2 hashes, and escalate via Cached GPP files.
🖥️ Linux 🔥 Easy
HTB Sau Walkthrough
Sau is an Easy Difficulty Linux machine that features a Request Baskets instance that is vulnerable to Server-Side Request Forgery (SSRF) via [CVE-2023-27163](https://nvd.nist.gov/vuln/detail/CVE-2...
🖥️ Linux 🔥 Easy
HTB Cap Walkthrough
A comprehensive penetration testing walkthrough for Hack The Box: Cap. Covers service enumeration, exploiting Insecure Direct Object Reference (IDOR) to leak sensitive PCAP data, and escalating privileges via abused Linux Capabilities and CVE-2021-4034 (PwnKit).
🖥️ Linux 🔥 Easy
HTB Soccer Walkthrough
A highly detailed, professional walkthrough for the Hack The Box machine Soccer. Explores Tiny File Manager exploitation, WebSocket Blind SQL Injection, and privilege escalation via doas and dstat plugins.
🖥️ Linux 🔥 Hard
HTB Nimbus Walkthrough
Step-by-step Hack The Box Nimbus walkthrough. Exploit SSRF filter bypass, extract AWS IAM credentials, and abuse SQS queue for remote code execution.
🖥️ Windows 🔥 Medium
HTB Checkpoint Walkthrough — BadSuccessor (CVE-2025-53779) Active Directory Exploit
Step-by-step Hack The Box Checkpoint walkthrough. Exploit the BadSuccessor dMSA vulnerability (CVE-2025-53779) on Windows Server 2025 for full domain compromise via AD object restoration, malicious VS Code extension, and Volatility memory forensics.
🖥️ Windows 🔥 Easy
HTB EscapeTwo Walkthrough — ADCS ESC1 & ESC4 Exploitation
Step-by-step HTB EscapeTwo walkthrough. Abuse MSSQL database privileges, exploit ADCS certificate template vulnerabilities (ESC1 & ESC4) with Certipy, and compromise the Domain Controller.
🖥️ Windows 🔥 Medium
HTB Escape Walkthrough — MSSQL & ADCS ESC1 Exploitation
Step-by-step HTB Escape walkthrough. Extract MSSQL credentials from a public PDF, capture NetNTLM hashes, exploit log files, and abuse ADCS ESC1 for full domain administrator takeover.