ðŊ HTB CPTS Write-ups
Walkthroughs for the Hack The Box machines on the CPTS track. Each write-up runs the full chain from enumeration to the root flag, and ends with a condensed attack chain, a commands cheat sheet, and a diagnostic map.
Machines
- ð Fluffy â NTLM capture (CVE-2025-24071) â ACL abuse â shadow credentials â ADCS ESC16
- ðĪĩ Jeeves â Jenkins RCE â KeePass loot â Pass-the-Hash â Alternate Data Streams
- ð Trick â DNS zone transfer â SQLi
FILEread â SSH â Fail2Ban hijack - ðŪ Postman â unauthenticated Redis â SSH key recovery â
supivot â OverlayFS LPE - ðïļ POV â IIS file read â ASP.NET ViewState RCE â WinRM pivot â SeDebugPrivilege
- ðŠĶ TombWatcher â AD object-control chain â deleted-object recovery â ADCS ESC15
- ðŽ Media â Responder NetNTLMv2 capture â PHP webshell â SeTcbPrivilege PoC
- ðĶ VulnCicada â NFS leak â Kerberos relay (ADCS ESC8) â DCSync
- ðš StreamIO â MSSQL SQLi â PHP include RCE â Firefox creds â LAPS
- ðĨ· Voleur â Kerberos-only AD â Office crack â WriteSPN Kerberoast â AD object restore â DPAPI â WSL pivot â NTDS dump
- ð Administrator â ACL abuse chain â password resets â FTP Password Safe crack â GenericWrite Kerberoast â DCSync
- ð Authority â anonymous SMB â Ansible Vault crack â PWM LDAP capture â ADCS ESC1 â Pass-the-Cert â RBCD/S4U â DCSync
- ðš Craft â Gogs source review â leaked API creds â Python
eval()RCE â container â internal MySQL â cred reuse â SSH key â Vault SSH OTP â root - ð Redelegate â anonymous FTP KeePass â season/year crack â MSSQL RID enum â targeted spray â Helpdesk ForceChangePassword â SeEnableDelegationPrivilege + GenericAll over FS01$ â constrained delegation S4U â DCSync
- ðķ Snoopy â DNS AXFR â download-endpoint LFI â BIND RNDC key â dynamic DNS mail hijack â Mattermost reset interception â SSH honeypot cred capture â sudo
git applysymlink write â ClamAV DMG XXE as root - ðŧ Ghost â LDAP wildcard auth bypass â Gitea source review â Ghost path traversal â SSH ControlMaster â Golden SAML â linked MSSQL â child-to-parent trust abuse