
Media VulnLab
Media VulnLab Media is an medium rated VulnLab machine on HackTheBox. It features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a ...

Media VulnLab Media is an medium rated VulnLab machine on HackTheBox. It features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a ...

Postman HackTheBox Postman is an easy difficulty Linux machine, which features a Redis server running without authentication. This service can be leveraged to write an SSH public key to the user’s...

Fluffy HackTheBox Fluffy is an easy-difficulty Windows machine designed around an assumed breach scenario, where credentials for a low-privileged user are provided. By exploiting CVE-2025-24071, t...

Trick HackTheBox Trick is an Easy Linux machine that features a DNS server and multiple vHost’s that all require various steps to gain a foothold. It requires basic knowledge of DNS in order to ge...

Bedside HackTheBox Bedside is a medium rated hackthebox machine which is based on … For more blogs please check out https://a45hw1n.github.io/ This box is currently live on HTB, dont look at w...

Intelligence HackTheBox Intelligence is a medium difficulty Windows machine that showcases a number of common attacks in an Active Directory environment. After retrieving internal PDF documents st...

Certificate HackTheBox Certificate is a hard Windows Active Directory machine that starts with an E-learning platform. The web application is vulnerable to Null-Byte Injection and stacked zip expl...

Haze HackTheBox Haze is a hard difficulty Windows machine focused on web exploitation, domain abuse, and Windows privilege escalation. Initial access is gained by exploiting a Splunk Arbitrary Fil...

Scepter HackTheBox Scepter is a hard difficulty Windows machine that starts with an unauthenticated NFS share, allowing the attacker to download a sensitive PFX certificate file. The attacker then...

RustyKey HackTheBox RustyKey is a hard difficulty Windows Machine which showcases a Timeroasting Attack, Active Directory ACL abuse following Windows Group Policy Enumeration to abuse the 7-Zip Sh...