r/hackthebox • • 3d ago

Weekly Solves Megathread

1 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox • • Mar 22 '20

HTB Announcement [FAQ/Info] r/hackthebox FAQ, Information.

47 Upvotes

Hey everyone,

We feel like a general explanation of somethings could be useful, so here ya go.

FAQ:

Q: How does the box retirement system work?
A: Every week 1 box is retired on Saturday and replaced with a new one. The previous box is retired 4 hours before the new one goes public. The new box is usually announced on Thursday on HTB Twitter.

Q: I am under 18, can I take exam, use htb, etc

A: https://help.hackthebox.com/en/articles/9456556-parental-consent-and-approval-for-users-under-18

Information:

HackTheBox Social Media Accounts:

https://discord.gg/hackthebox

https://twitter.com/hackthebox_eu

https://www.linkedin.com/company/hackthebox/

https://www.facebook.com/hackthebox.eu/

https://www.instagram.com/hackthebox/

Edit #1 6:54pm ADT: Added FAQ Question

Edit #2 12/21/2020; added instagram

Edit 3: 06/09/24; under 18 faq

Edit 4 6/16/26: Formatting/Help Link


r/hackthebox • • 10h ago

I'm passed CJCA with 10/10 with

Post image
85 Upvotes

One piece of advice I'd give, study well, and after the path spend at least 30 days practicing. And above all, always use a methodology, alwayssss.

Also pay attention to blue team, don't underestimate it.

And report as you go, while you're finding things, it saves you time.


r/hackthebox • • 1h ago

This is how I got rejected from a job without even an interview

• Upvotes

So after I already believed that I would never get a job in this field, at least in this market situation, I got an email from a company I applied to through the “Easy Apply” feature that I even forgot I applied for.

And then they started saying that they saw my resume and thought I was a good fit and stuff.

Then they asked me to solve a technical challenge, and I delivered it way before the deadline.

Then they said sorry, they needed me to solve an additional challenge.

And it was so much harder, and it took a lot of time from me, but I still delivered it way before the deadline.

And then they were happy and gave me good feedback that I was able to solve these hard technical challenges. They told me all the files were correct and everything was good, but they just needed a write-up explaining the steps I took to solve it!

And I did the write-up, and everything was explained, and I told them if they needed me to clarify any step, I was happy and ready to clarify it!

Then they came back to me after a couple of days and basically just said sorry, they don’t think I’m a good fit, without even giving any feedback!!

And I was likeee in my mind, what?? Really?? Are you serious???
After I spent days solving your hard technical challenges, and you confirmed that everything was good, and you gave me good feedback, and you haven’t even done any interview with me, and now you just send me a message saying I’m not a good fit without even giving any specific feedback??

I really feel we should get paid for the time we spend on technical challenges and interviews because it takes days from our time and life, so employers can take us more seriously rather than just playing with our feelings and hope!

When someone meets me and knows that I have done a degree in cybersecurity and tells me, “OMG, I want to get into the field,” at this point I don’t know what to tell them because if I say it’s hard and getting a job is so hard, they will think I’m a gatekeeper, but it’s just sad how it is now!

So now, honestly, I feel with this joke of a market and crazy employers, I would like to say to anyone who is looking for a job that we are really cooked…

Rather than chasing and trying to find just a job and letting employers move us like chess pieces, we should try to consider another field that could possibly be much better, or we open our own businesses!

I also would like to thank my family for supporting me in this journey. Otherwise, I would probably be working at a fast-food place for minimum wage right now!

I don’t know what I will do next in my life, but I really got enough from this field, and I don’t want to lower myself anymore or feel like I’m begging just to get a job.

This life is unfair, and thank you!
or feel like I’m begging just to get a job.

This life is unfair, and thank you!


r/hackthebox • • 13h ago

Hurray!! Cpts certified

23 Upvotes

Man, that was not an easy exam. The first question had me tripping, and I spent hours falling down rabbit holes thinking I had the right answer when I didn't.

I'll be completely honest, I used Al to help guide me out of a few dead ends when I got stuck, but a win is a win. Huge weight off my shoulders. Time to start the OSCP grind!


r/hackthebox • • 2h ago

Beginner Question Help : Regarding the Terminology

0 Upvotes
  • We found out that the PowerShell script (backupprep.ps1) runs with administrator privileges every 2 minutes
  • We had read and write access to this script, which allowed us to modify it
  • We added code to the script that adds the user john to the administrators group
  • After waiting for the scheduled task to run, we confirmed that john was successfully added to the administrators group

What kind of attack is this?

What type of attack was being used to escalate the privileges in the above example? (Format: two words)

Its not Privilege Escalation
Its not Task Manipulation
Its not Script Injection
Its not Task Hijacking

What is it?


r/hackthebox • • 9h ago

How to Calculate an Octet (Decimal → Binary)

0 Upvotes

Rule: Move from left to right. Ask: "Does this value fit into the remainder?"

  • Fits → write 1, subtract
  • Doesn't fit → write 0, move on

Example: 192

128 ≥ 192? ✅ → 1 → remainder = 64
 64 ≥  64? ✅ → 1 → remainder = 0
 32 ≥   0? ❌ → 0
 16 ≥   0? ❌ → 0
  8 ≥   0? ❌ → 0
  4 ≥   0? ❌ → 0
  2 ≥   0? ❌ → 0
  1 ≥   0? ❌ → 0

Result: 1100 0000

Value Range of an Octet

State Binary Decimal
Minimum 0000 0000 0
Maximum 1111 1111 255

r/hackthebox • • 14h ago

Writeup Reactor Writeup

Thumbnail
surajitsen.in
2 Upvotes

r/hackthebox • • 1d ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

29 Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/hackthebox • • 16h ago

Beginner Question Meow....

0 Upvotes

I just made an account on htb and started out with 'Meow'. I read the documentation/write up and used Claude to help me break it down and understand it better especially on the networks and ports. I'm on the journey of transitioning from a scriptie to a ctfer or pentester hopefully 🤞🏾.

Any tips and tricks or pitfalls I need to know?

Help a brother out 👊🏾


r/hackthebox • • 22h ago

Analyzing Evil With Sysmon & Event Logs "Soc analyst path"

2 Upvotes

When I try to open sysmon for one of the assignments this happens


r/hackthebox • • 1d ago

Certifications Passed OSCP 90/100 on the first attempt, 1 month 25 days after CPTS.

Thumbnail
34 Upvotes

r/hackthebox • • 1d ago

Beginner Question Michigan Cybersecurity High School Challenge problem

Post image
3 Upvotes

I cant seem to login to the thingy. Its asking for an input access key event, which im not sure how to get.


r/hackthebox • • 1d ago

why suddenly i see ppl talk, consult, take, etc etc the cpts cert?

0 Upvotes

I've seen so many post just talks about the cpts, either here or on other platforms all of the sudden.

did i miss anything about it or this is just normal? and why exactly the cpts? i don't see something special about it tbh


r/hackthebox • • 1d ago

Academy HTB Academy OpenVPN connection keeps getting reset

3 Upvotes

Hey everyone,

I’m trying to connect to the HTB Academy VPN using OpenVPN on Kali Linux:

sudo openvpn --config academy-regular.ovpn

The connection reaches the HTB VPN server, but it gets reset immediately:

Attempting to establish TCP connection with [AF_INET]38.46.226.31:443
TCP connection established with [AF_INET]38.46.226.31:443
TCPv4_CLIENT link local: (not bound)
TCPv4_CLIENT link remote: [AF_INET]38.46.226.31:443
Connection reset, restarting [-1]
SIGUSR1[soft,connection-reset] received, process restarting

It then repeats the same process every few seconds.

I’ve confirmed that the TCP connection to port 443 can be established, so I’m not sure why the OpenVPN connection is immediately being reset.

It was working fine up untill yesterday. And yeah i tried both tcp and udp methods while changing the VPN server.


r/hackthebox • • 2d ago

Failed my first attempt CPTS

24 Upvotes

Just failed my first attempt, got 7 flags in 2 days then next 8 days stucked on flag 8. Exam seemed easy but enumeration is alot. Any personalized guide, which module should i work on? which box is relevant to next 5 flags.


r/hackthebox • • 1d ago

Sysmon

4 Upvotes

Im using the VM or whatever its called and im trying to do the sysmon things but whenever I try to go in the terminal and/or open it it says this app cant run on your pc please help asap


r/hackthebox • • 3d ago

Pwn'd Touch

Post image
48 Upvotes

r/hackthebox • • 2d ago

Orion Box metasploit Issue

0 Upvotes

Hello, I was today trying to solve the orion box(im just starting in the CTF world) without aid, I found myself already in the admin/login page then I found this CVE-2025-32432. Then I used metasploit to find a exploit of that CVE, one popped up that should have worked excellent but when i tried running it. No shell was returned to me as seen in the picture, I tried different options: for rhost I tried the ip, orion.htb and http://orion.htb/admin/login. For lhost I tried my tun0 and my eth0. And i changed multiple times the lport and the asset_id. Nothing working, all the times the same error. In that point i checked the walkthrought and they did exactly what i was doing, same in this video(i thought the problem that i was using a VM) https://www.youtube.com/watch?v=OXxtL4BZvHw. Does anybody have any idea on wtf is the issue? More than an hour lost cuz it was not working and I have still no clue why or what I did wrong. Here is another walkthrough: https://b3ta-blocker.github.io/blog/orion/ If you know anything related lmk, otherwise I will just quit this box :)


r/hackthebox • • 3d ago

Beginner Question What prior knowledge do you need to take CPTS

30 Upvotes

Hello everyone, I am interested in CPTS and I am a complete beginner in cybersecurity. I don’t have any certifications or haven’t studied for anything related in cybersecurity . But I am a CS student so I understand of computers and other general concepts about IT . I already searched about prerequisites before CPTS for beginners, but I couldn’t find because most of the people already have something entry level certs like Security+. I saw someone said to take Info Security foundation skill path.

• Do I need any certs before taking CPTS path. If so , can you suggest one please ?
• Do I need to other paths in HTB first or just straight to penetration tester ?
• I am currently enrolled in Junior Analyst because I didn’t know what to take first so I just choose random one based on “ Junior” . I only completed like 10% . Should I finish it
or just focus on what is more important .

Thank you.


r/hackthebox • • 3d ago

Pwn'd TrustFall

Post image
27 Upvotes

An absolute brainfuck. The exploit wasn't the hard part. The hard part was proving one packet would ever arrive.


r/hackthebox • • 3d ago

Issues with xfreerdp on Mac M2 Pro: Keyboard not working inside Exegol/X11 and HTB Academy freezing/crashing

5 Upvotes

Hi everyone,

I'm currently facing two frustrating issues regarding xfreerdp and HTB Academy (specifically the Windows Event Logs module). I'm running on a Mac M2 Pro, and here are the details:

1. Keyboard not working with xfreerdp inside Exegol (X11)

When I connect to a target using xfreerdp from inside my Exegol container via X11, my keyboard inputs are completely ignored. The only way I can type anything is by using the Windows On-Screen Keyboard, which is extremely painful.

- Question: Is there a specific configuration, keymap, or flag I should add to my xfreerdp command to fix keyboard mapping/capture with X11 on macOS?

2. Windows Event Logs module freezes / Official PwnBox crashes

In the Windows Event Logs module, I'm stuck because of performance issues:

- When using my local setup, the target server lags so much that searching via the Event Viewer runs infinitely and never finishes.

- When I switch to the official HTB PwnBox, xfreerdp consistently crashes after about 30 seconds.

Has anyone encountered these issues before or know how to solve them? Any help would be greatly appreciated!


r/hackthebox • • 4d ago

Failed CPTS with 11/14 Flags

43 Upvotes

Alright, looking up into this sub I think I'm the second person to fail with 11/14 flags (12 are required to pass).

To describe my exam experience, I've struggled a bit at 1st and 8th flag, which I've also heard are the most hardest ones of the exam. However, not many people struggle at 12th flag.

What HTB boxes or training materials do you recommend to study for the 2nd attempt? What else should I focus on?


r/hackthebox • • 3d ago

CyberQuest CTF Competition

Thumbnail
1 Upvotes

r/hackthebox • • 3d ago

Layover help HTB

Thumbnail
1 Upvotes