My HackTheBox CTF Methodology - From fresh box to root!

Not a question per se, but I think it would be cool if we put together guides on different “in roads”,

ie after you get admin access to the web app what are the common things to look for (eg, file upload and filter evasion, lfi, rfi, template editing etc.)

or the different things you can do if you have access to smb shares or anon ftp… there’s a lot more to do than the usual CTF “collect the files and follow the clues” type stuff.

(afterall, this is where it gets interesting imho :smiley:)


Yes that’s a great idea!

Start a document?

1 Like