ðŸŽŊ HTB CPTS Write-ups

Walkthroughs for the Hack The Box machines on the CPTS track. Each write-up runs the full chain from enumeration to the root flag, and ends with a condensed attack chain, a commands cheat sheet, and a diagnostic map.

Machines

  • 🐑 Fluffy — NTLM capture (CVE-2025-24071) → ACL abuse → shadow credentials → ADCS ESC16
  • ðŸĪĩ Jeeves — Jenkins RCE → KeePass loot → Pass-the-Hash → Alternate Data Streams
  • 🎭 Trick — DNS zone transfer → SQLi FILE read → SSH → Fail2Ban hijack
  • ðŸ“Ū Postman — unauthenticated Redis → SSH key recovery → su pivot → OverlayFS LPE
  • 👁ïļ POV — IIS file read → ASP.NET ViewState RCE → WinRM pivot → SeDebugPrivilege
  • ðŸŠĶ TombWatcher — AD object-control chain → deleted-object recovery → ADCS ESC15
  • 🎎 Media — Responder NetNTLMv2 capture → PHP webshell → SeTcbPrivilege PoC
  • ðŸĶ— VulnCicada — NFS leak → Kerberos relay (ADCS ESC8) → DCSync
  • 📚 StreamIO — MSSQL SQLi → PHP include RCE → Firefox creds → LAPS
  • ðŸĨ· Voleur — Kerberos-only AD → Office crack → WriteSPN Kerberoast → AD object restore → DPAPI → WSL pivot → NTDS dump
  • 👑 Administrator — ACL abuse chain → password resets → FTP Password Safe crack → GenericWrite Kerberoast → DCSync
  • 📜 Authority — anonymous SMB → Ansible Vault crack → PWM LDAP capture → ADCS ESC1 → Pass-the-Cert → RBCD/S4U → DCSync
  • 🍚 Craft — Gogs source review → leaked API creds → Python eval() RCE → container → internal MySQL → cred reuse → SSH key → Vault SSH OTP → root
  • 🔁 Redelegate — anonymous FTP KeePass → season/year crack → MSSQL RID enum → targeted spray → Helpdesk ForceChangePassword → SeEnableDelegationPrivilege + GenericAll over FS01$ → constrained delegation S4U → DCSync
  • ðŸķ Snoopy — DNS AXFR → download-endpoint LFI → BIND RNDC key → dynamic DNS mail hijack → Mattermost reset interception → SSH honeypot cred capture → sudo git apply symlink write → ClamAV DMG XXE as root
  • ðŸ‘ŧ Ghost — LDAP wildcard auth bypass → Gitea source review → Ghost path traversal → SSH ControlMaster → Golden SAML → linked MSSQL → child-to-parent trust abuse

16 items under this folder.