/hackthebox-writeups

Writeups for HacktheBox 'boot2root' machines

GNU General Public License v3.0GPL-3.0

hackthebox-writeups

Writeups for HacktheBox machines (boot2root) and challenges written in Spanish or English.

https://www.hackthebox.eu/

Important notes about password protection

Machines writeups until 2020 March are protected with the corresponding root flag. But since this date, HTB flags are dynamic and different for every user, so is not possible for us to maintain this kind of system. So from now we will accept only password protected challenges, endgames, fortresses and retired machines (that machine write-ups don't need password). For endgames or fortresses, the password should be all the flags concatenated.

hpys_htb_writeups logo

Disclaimer

It is totally forbidden to unprotect (remove the password) and distribute the pdf files of active machines, if we detect any misuse will be reported immediately to the HTB admins.
Anyway, all the authors of the writeups of active machines in this repository are not responsible for the misuse that can be given to the corresponding documents. Please think that this is done to share techniques not for spoilers.

Submissions

If you want to incorporate your own writeup, notes, scripts or other material to solve the boot2root machines and challenges you can do it through a 'pull request' or by sending us an email to: hackplayers_at_Ymail.com.

In this way, you will be added to our top contributors list (see below) and you will also receive an invitation link to an exclusive Telegram group where several hints (not spoilers) are discussed for the HacktheBox machines.

Please consider protecting the text of your writeup (e.g. not allowing to be copied) so that it can not be easily shared on platforms such as Pastebin. Of course, if someone leaks a writeup of an active machine it is not the responsibility of the author. If we detect someone who does it, they will immediately report to the HTB Staff so they can take the appropriate measures.

Note: the minimum requirement to enter the "special" Telegram group is also to have a hacker level or higher (no script kiddies).

Star contributors (+5 writeups)

No ctry nick avatar team machines challenges total writeups
1 Fiti L1k0rD3B3ll0t4 Bashed, Arctic, Tenten, Celestial, Mirai, Nibbles, Sunday, Valentine, Dev0ops, Aragog, Canape, Mischief, Jerry, Olympus, Bounty, Access, Carrier, Curling, Dab, Ypuffy, Waldo, Secnotes, Irked, Frolic, Chaos, Fortune, Friendzone, Lightweight, Querier, Help Conceal, CTF, Netmon, Sizzle, Arkham, OneTwoSeven, LaCasaDePapel, Helpline, Ghoul, Bastion, Swagshop, Ellingson, Writeup, Chainsaw, Haystack, Jarvis, Player, Smasher2, Unattended, Kryptos Impossible password, Widescreen, Unified, Milkshake, It's raining blood, Hackerman, Forest, Cartographer, 0ld is g0ld, HDC, Beatles, Brainy's Cipher, Classic Yet Complicated, Da Vinci, Deceitful Batman, Digital Cube, Keys, Lernaean, Pusheen Loves Graphs, Sick Teacher, Weak RSA, Fuzzy, I Know Mag1k, Grammar 74
2 SirBroccoli Watch4Hack SwagShop, Jarvis, OneTwoSeven, Haystack, Heist, Bitlab, Wall, Bankrobber, Postman, Mango, AI, Control, Obscurity, Registry, Resolute, Sniper, JSON, OpenAdmin, Monteverde, Nest, Sauna, Book Emdee five for life, Craft, FreeLancer, Bombs landed, Eat the cake, Headache, Find the secret flag, Debugme, Impossible password, DSYM, Snake, Find the easy pass, Obscure, Crooked crockford, ExploitedStream, Ropme, Old Bridge, Little Tommy, Ropmev2, Baby RE, headache2, Breach, Easy Phish, Infiltration, We Have a Leak, Cryptohorrific, Da Vinci, Digital Cube, Forest, Pusheen Loves Graphs, Senseless Behaviour, Templed, M0rsarchive, Interdimensional Internet, ezpz, Under Construction, 58
3 noraj Rawsec Academy, Admirer, Blackfield, Blunder, Book, Buff, Cache, Cascade, Control, Doctor, Dyplesher, Fatty, ForwardSlash, Jewel, Laboratory, Magic, Mango, Monteverde, Nest, Obscurity, Omni, Oouch, OpenAdmin, Passage, Remote, Resolute, ServMon, SneakyMailer, Tabby, Traceback, Traverxec, Worker 32
4 crysal SKPH4X Bastion, Writeup, SwagShop Find the easy pass, snake, Da Vinci, Beatles, BitsNBytes, Forest, hackerman, Hidden in Colors, Milkshake, Monstrosity, Raining Blood, Retro, Widescreen, Digital Cube, Pusheen Loves Graphs, 0ld is g0ld, Eternal loop, Blackhole, misDIRection, fs0ciety, Longbottoms Locker, Inferno, Grammar, I know Mag1k, M0rsarchive, Money Flowz, cat 30
5 volken SinHack Poison, Jerry, Curling, Help, Irked, Popcorn 0ld is g0ld, Blackhole, fs0ciety, Art, Inferno, misDIRection, Eternal Loop, Longbottom's Locker, Hackerman, Raining Blood, Unified, Brainy's cipher, Da Vinci, Deceiful Batman, Forest, HDC, Marshal in the Middle, Weak RSA, Keys, Retro 26
6 FlatMarsSociet Solitaire wolf Bastion, Networked, Writeup, Traverxec, Sauna, OpenAdmin, Nest Easy Phish, Infiltration, 0ld is g0ld, Art, Blackhole, Croocked Crockford, Eternal_Loop, Inferno, Longbottom's Locker, M0sarchive, fs0ciety, misDIRection, Emdee five for life, Fuzzy, Cartographer, iknowmag1k, Lernaean, Freelancer 25
7 kaosam CameLUG Obscurity, Postman, Openadmin, Sauna, Resolute, Book, Forest, Registry, Nest, Control, Sniper, Traceback, Traverxec, Mango, Servmon, Cascade, Magic, Remote, Blunder, Buff, Doctor, APT, Laboratory 23
8 icebreakcrypt Solitaire wolf Massacre, Brainy's Cipher, Widescreen, Blackhole, Pusheen Loves Graphs, Milkshake, Raining blood, The Future Bender, Decode me, Baby RE, Illumination, Walzer, Window's Infinity Edge 19
9 drx51 solitaire wolf Celestial, Dev0ops, Nibbles, Shocker, Valentine, Bashed, Chatterbox, Jerry, Canape, Sense, Silo, Active, Waldo, Mischief, Stratosphere, Poison, Olympus, Tartarsauce 18
10 d0n601 mystiko Luke, SwagShop, Writeup, Jarvis, Haystack, Craft, Traverxec, Traceback, Ophiuchi, Armageddon snake , Emdee five for life, Fuzzy, Easy Phish, Illumination 15
11 wilsonnkwan CyberFrenzy Ethereal, Arkham (coauthor mmb), OneTwoSeven, Bastion, SwagShop, Lacasadepapel, Ellingson, Luke, Kryptos, Smasher2, Ghoul, Unattended, Craft 13
12 1v4n solitaire wolf Olympus, Jerry, Curling, Netmon Da Vinci, Hackerman, Forest, fs0ciety, Weak RSA, Unified, SickTeacher, Milkshake, Easy Phis 13
13 IceL0rd BirdsArentReal Arkham, Fordwardslash, Tenten, Valentine, Blackfield, Fuse, Cache, Apocalyst, Cronos, Bank, Poison, Blunder 13
14 Qarnix Hacky Craft, Sniper, Traverxec, Worker, Doctor Easy Phish, Infiltration, We Have a Leak, Breach, Bank Heist, USB-Ripper, ID Exposed, Money Flowz 13
15 KaoRz L1k0rD3B3ll0t4 Olympus, Secnotes, Ypuffy, Smasher Find the easy pass, Impossible Password, ropme, Old Bridge, ropmev2, Dream diary 1, Dream diary 2 11
16 Magichk Watch4Hack Luke, Writeup Please, don't share, Bank Heist, MarketDump, Emdee five for life, Fuzzy, August, Easy Phish, DSYM 10
17 pimmytrousers BitsPlz Bounty, Celestial, Jerry, Poison, Sunday, Valentine, Canape, Stratosphere, Dev0ops 9
18 mcruz solitaire wolf Valentine, Jerry, Legacy, Poison, Sunday, Silo, Active, Hawk, Querier 9
19 frosters solitaire wolf Aragog, Silo, Bounty, Rabbit, Dev0ps, Valentine, Secnotes, Oz 8
20 mgp25 MemoryLeaks Blue Shadow, Deadly Arthropod, MarketDump, Marshall In The Middle, Obscure, Reminiscent, Took The Byte, USB Ripper 8
21 7Rocky CocoTeam Lost Modulus, Lost Modulus Again, LunaCrypt, mysterybox, RLotto, racecar, Restaurant, baby CachedView 8
22 artikrh Sushi Hawk, Stratosphere, Reddish, Waldo, Dab, Secnotes, Access 7
23 Sekisback solitaire wolf Carrier, Teacher, Ypuffy, Redcross, Lightweight, Conceal, Fortune 7
24 un1k0n MemoryLeaks Keys, Decode me, lernaean, cartographer, grammar, Emdee five for life, ezpz 7
25 amber solitaire wolf Vault, Giddy, Frolic, Chaos Infinite Descent, Call, blacksquare 7
26 Hilbert Solitaire wolf Mango, Blocky, Postman, Networked, Traverxec, Obscurity BabyEncryption 7
27 VbScrub Solitaire wolf Bastion, Resolute, Monteverde, Forest, JSON, Sniper 6
28 Str0ng3erG3ek Vyt3k1ng5 Control, Monteverde, Registry, Sniper, Traverxec, Sauna 6
29 OscarAkaElvis FightClub Olympus The Art of Reversing, I know Mag1k, Retro, Nostalgia 6

Occasional contributors (2-5 writeups)

Ctry nick avatar team machines challenges
manulqwerty L1k0rD3B3ll0t4 Stratosphere, Canape, Nibbles, Bounty, Jarvis,
humurabbi Solitaire wolf Safe,Heist, Unattended, Networked, Craft
mansoor Solitaire wolf Ellingson, Safe, Frolic, OneTwoSeven, Ghoul
Leonishan solitaire wolf Helpline, Unattended Blue Shadow, Reminiscent, Took the byte
wilde Solitaire wolf Active, Waldo, Hawk, Zipper
fibbot solitaire wolf Celestial, Poison, Canape, Sunday
spenkk Sentry Bart, Dev0ops, Dropzone snake
ozunu OzunuClan Giddy, Irked, Teacher, Access
n4xh4ck5 solitaire wolf Jerry, PopCorn, Haircut, Curling
3v4Si0N L1k0rD3B3ll0t4 Canape, TartarSauce, Bounty
Pitenager solitaire wolf Blue, Mirai, Nibbles Cartographer, Lernaean
x4nt0n AlphaPwner Sunday, Olympus, Access Marshal In The Middle
FrankyTech L1k0rD3B3ll0t4 Active, Dev0ops, Olympus
TheLegend solitaire wolf Active, Dev0ops I know Mag1k, Snake
kabutor solitaire wolf Aragog, Access, LaCasaDePapel_alt
Vis0r L1k0rD3B3ll0t4 Blocky, Chatterbox Matrioshka
31337 Writeup, Haystack, Ellingson
giru solitaire wolf Irked, Bounty
morph3 solitaire wolf Help, Friendzone
Paint solitaire wolf Carrier, Ethereal
Ghostpp7 L1k0rD3B3ll0t4 Valentine, TartarSauce
o00o solitarire wolf Reel, Nightmare
felli0t solitaire wolf DevOops, Chatterbox
CyberVaca L1k0rD3B3ll0t4 Chatterbox, Reddish
b1gb1t r00th4ck Sunday, Active
roskyfrosky solitaire wolf Jerry, Celestial
Sephiroth Bin4ryCh4os Fortune, Vault
BinaryShadow Watch4Hack Safe Call, Crack this!, Decode me
tabacci Solitaire wolf HackBack, RE Obscure, Nostalgia, LostKey
thereallulz solitaire wolf Retro, Monstrosity, Senseless Behaviour
luthorien ARGSS Not Art, Grammar, Hidden in Colors
Pepelu Solitaire wolf Player, Craft
w4tchw0lf L1k0rD3B3ll0t4 BitsNBytes, Monstrosity
SadFud solitaire wolf Impossible Password, Find the easy pass
epi Hackmethod Ypuffy, SwagShop
v3he solitaire wolf Old Bridge, ropmev2
3l33t solitaire wolf Safe, Jarvis, Player, Craft
thecapo Solitaire wolf Forest, Heist
wezzlaren Hacky Mango, Postman
egotisticalSW Solitaire wolf Heist, Traverxec, Obscurity
DarkNight2019 T0pt33m Forest, Registry
retrocraft Solitaire wolf Obscurity, Traverxec
BananaPr1nc3 Solitaire wolf Traverxec DSYM
offk0rs MemoryLeaks Safe, Ellingson, Jarvis
Jacker31 NightTrain Heist, OpenAdmin, Arkham, Book
Mrx-Exploit TCLRED Traverxec Ezpz
ypl Solitaire wolf Ropme, ropmev2
xiaobye Solitaire Wolf OpenAdmin, Mango, Obscurity
ghsi10 solitaire wolf You know 0xDiablos, Console, bad_grades
h4ckd0tm3 SickaLoot Unprintable, QuickR
Segf4ul7 Solitaire Wolf You know 0xDiablos, ropme, ropmev2, Little Tommy
hyperreality Solitaire wolf Optimus Prime, RsaCtfTool
DaWoschbar SickaLoot Sauna, Traceback
ebaitello Solitaire wolf Cat, Missing in Action
Ap0k4L1p5 ALTr34lity Admirer Cryptohorrific
blankdash VoidUnity obscurity Reminiscent, MarketDump
snovvcrash Solitaire Wolf Hades, RPG, Ascension
d4rkc0nd0r AlphaPwners TwoForOne, Emo, Bare Metal
islamukheef Solitaire Wolf Baby RE, HackyBird
sp00fexpl01t Solitaire Wolf Sharp Phonebook, LoveTok, petpet rcbee
hacefresko Solitaire Wolf Weather App, baby ninja jinja, Breaking Grad
apehex Solitaire Wolf Query, Exatlon, quick maffs, signup, Protein Cookies
ejedev Solitaire Wolf Toxic, APKey, SeeTheSharpFlag, PersistenceIsFutile

Fleeting contributors (1 writeup)

Ctry nick avatar team machines challenges
absolutezero Sentry Fighter
xephrox solitaire wolf Mischief
worldunruled hackmethod Active
rtheory FlavorTown Reddish
thereverend solitaire wolf Active
Zaiuss L1k0rD3B3ll0t4 Celestial
attl4s juankeres Falafel
kauffman solitaire wolf Poison
revil solitaire wolf Sunday
k4nj1d solitaire wolf nibbles
giovii criuz Mischief
3zculprit solitaire wolf Olympus
FuxSocy PhobosGroup Dev0ops
abselithat Pratum Chatterbox
Killerloops prosegur Tear or dear
Renero criuz Digital Cube
Gibdeon PKTeam Old Bridge
therearwindow solitaire wolf Beatles
malwrecon solitaire wolf Ypuffy
labyrinth badwolf Ebola Virus
zdravich TMHC Carrier Mission Impossible
Wh04m1 YoRHa Ropme
coldBug NeatMalwAreParty Curling
dionero solitaire wolf Jerry
TheShahzada solitaire wolf Mischief
SadClown solitaire wolf Redcross
julianjm solitaire wolf Old Bridge
snowman418 solitaire wolf Reel
jondow Bailando Help
lolfireball solitaire wolf Lightweight
solsanctum solitaire wolf Carrier
fbbc solitaire wolf Conceal
4lexag EphorSec Cryptohorrific_es, Cryptohorrific_en
superhedgy Solitaire wolf Netmon
blazz3 PwnD34L3rS Sizzle
Marduk PwnD34L3rS Helpline
lduros solitaire wolf SwagShop
explmuzz N00b543V3R Bastion
AlhA solitaire wolf Emdee Five for Live
liamm PORTKNOCKWHOSTHERE Jarvis
cavla Solitaire wolf Crooked Crockford
entropy Solitaire wolf Crooked Crockford
MrP4p3r Solitaire wolf Fuzzy
emmanuel Solitaire wolf Craft
Cript0crc Solitaire wolf Eemedefive for live
bWlrZQo USCh4ck3r5 Craft
naveen1729 Solitaire wolf Player
AmbrotD Solitaire wolf USB Ripper
danielcues Ripp3rs Mission Impossible
arcc Solitaire wolf json bitlab
CRYPT0HEX Solitaire wolf Writeup
couchpotato Solitaire wolf Heist
sneakypanda Mystiko Zetta
nitrow Solitaire wolf Image Processing 101
Cyb3rb0b Solitaire wolf Json
N7E iamroot Mango
Parteek Singh D3v1L5 Sniper
c1cada CommandlineKings Obscurity
Mrigendra Soni Solitaire Wolf Postman
mikeywayne Solitaire Wolf traverxec
Milo p0t4t03s ezpz
N1Z4M 7eam4dholokam OpenAdmin
corshine Solitaire Wolf OpenAdmin
SevenLayerJedi Solitaire Wolf Nest
IamKsNoob Solitaire Wolf Postman
Bayrem Cartographer
Bayrem Solitaire Wolf Cartographer
3gbCyber KAU OpenAdmin
FlapJack NashvilleCTF OpenAdmin
wazKoo ScripTease Traceback
Shkk Solitaire wolf Monteverde
elklepo notSoBad Fatty
Chr0x6eOs SickaLoot QuickR
dayld Solitaire wolf breaking grad
7riple7hrea7 p0tat0z Interdimensional Internet
caracal HideAndSec Mr. Burns
aminegr Solitaire Wolf Emdee five for life
run3 hack2tan Mission Pinpossible
Isopach Solitaire Wolf Baby RE
YoavD Solitaire Wolf HackyBird

Special note

Hack the Box is a superb platform to learn pentesting, there are many challenges and machines of different levels and with each one you manage to pass you learn a new thing. But talking among ourselves we realized that many times there are several ways to get rooting a machine, get a flag ... That's why we created this repository, as a site to share different unofficial writeups to see different techniques and acquire even more knowledge. That is our goal and our passion, to share to learn together.

Some people have been distrustful because in this repository there are writeups of active machines, even knowing that absolutely each one of them is protected with the corresponding password (root flag or challenge). But We did not want to give up this because we think the most interesting thing for a HTB player is to check other users' walkthroughs right after they get it, that is, not wait for weeks or months afterwards. For this reason, we have asked the HTB admins and they have given us a pleasant surprise: in the future, they are going to add the ability for users to submit writeups directly to HTB which can automatically be unlocked after owning a machine. And also, they merge in all of the writeups from this github page. Simply great!

Therefore it is a real pride that they have decided to include the functionality of this repo directly on their platform. When this is done, this Github will be migrated and will be inactive but with a pleasantly fulfilled mission. Until then, Keep pushing!

Hackplayers community, HTB Hispano & Born2root groups.