Jan 10, 2024, 07:52 PM
Hello everyone! I'm delighted to share my journey into the field of ethical hacking and begin my HackTheBox experience. I've always been interested in cybersecurity and decided to take the plunge.
|
My Journey Getting Started on HackTheBox
by TheVHSBoy - Wednesday January 10, 2024 at 07:52 PM
|
|
Jan 10, 2024, 07:52 PM
Hello everyone! I'm delighted to share my journey into the field of ethical hacking and begin my HackTheBox experience. I've always been interested in cybersecurity and decided to take the plunge.
Jan 10, 2024, 08:05 PM
(Jan 10, 2024, 07:56 PM)ElBakhaw Wrote: Very good my friend !! i can's say it is hard i am enjoying learning on it, if i can say a bad thing is that i am moving forward too slowly, so i think at some point i would need to learn more out of this platform. (Jan 10, 2024, 08:08 PM)nopz0x90 Wrote: Good, keep learning. I'm really getting into HackTheBox, and your advice to treat it as a creative thinking exercise make a lot of sense, and I will surely take your advice carefully and look into IppSec's and 0xdf's writeups cuz it appeared to me after some research to be a treasure for learning, and i hope you give me some advises or personal experiences or specific tasks on HackTheBox that you found especially interesting or challenging. (Jan 10, 2024, 07:52 PM)TheVHSBoy Wrote: Hello everyone! I'm delighted to share my journey into the field of ethical hacking and begin my HackTheBox experience. I've always been interested in cybersecurity and decided to take the plunge.Let's take a closer look at the addictive challenges that HackTheBox has to offer, with a particular focus on 'Aragog' and 'Apocalyst'. These challenges serve as good benchmarks to improve your penetration testing skills. Aragog: Unraveling the Complex Web Level: Medium Aragog's mission is to find both user.txt and root.txt in the labyrinth of vulnerabilities. The journey begins with a careful scan using Nmap to reveal open ports 21, 22, and 80. In particular, anonymous FTP logins open the way for exploration. FTP exploration revealed an interesting test.txt file that introduces his XML-based Subnet_Mask hint. It makes clever use of XML External Entity (XXE) injection to traverse /etc/passwd and protect SSH-RSA keys. Finally, user.txt is captured and the permissions of root.txt are extended. Apocalyst: Navigating the Apocalypse Level: Intermediate Apocalyst presents a moderate challenge with the ultimate goal of discovering user.txt and root.txt. Port enumeration with Nmap shows open ports 22 and 80. Your web journey begins and leads you to the Apocalypse Preparation Blog. Investigating WordPress vulnerabilities using wpscan and directory enumeration leads to the Rightiousness directory. Steganalysis plays an important role as it reveals hidden list.txt files from images. Wpscan also exposes credentials, paving the way for Metasploit exploits. This journey includes privilege escalation, decryption of base64 encoded secrets, and culminates in the victory of user.txt and root.txt. It's an apocalypse-themed adventure full of twists and turns. you can read more about those challenges from here: apocalyst aragog
Jan 11, 2024, 02:26 PM
Stuck On Privesc Every Fking Time
I am getting nowhere with getting root access by myself. I am able to get pwn the user easily but never the root user. I always need hints and most of the time, even walkthroughs. Can You Guys Suggest some resources or something to improve my skills? Thanks
Jan 11, 2024, 03:31 PM
(Jan 11, 2024, 02:26 PM)r0001 Wrote: Stuck On Privesc Every Fking Time I am too in the learning phase. I would recommend you to try guided mode and then try it without looking at hints.
Jan 12, 2024, 10:42 PM
I'm also going to begin learning soon. I have been interested about it for sometime but I haven't yet started. I wish you best of luck in your journey.
Jan 13, 2024, 09:33 PM
Learning takes time, my friend.
Feb 21, 2024, 08:20 PM
Oh, congratulations and good journey.
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] CPTS 12 FLAGS | 73 | 2,332 |
4 hours ago Last Post: louikizzz |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 89 | 8,100 |
5 hours ago Last Post: Xploitd |
||
|
|
[FREE] HackTheBox All Cheatsheets | 10 | 626 |
8 hours ago Last Post: chufoni |
|
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 28 | 2,851 |
8 hours ago Last Post: chufoni |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 375 | 93,674 |
8 hours ago Last Post: Johe |
||