HackTheBox Starting Point Writeups

HackTheBox Starting Point Writeups

February 6, 2025
1 min read (50 min read total)
17 subposts
index

This is a detailed write-up of all my HackTheBox Starting Point machines. I will update this post as I complete more machines.

Available Writeups (17)

HackTheBox Starting Point: Meow Walkthrough

This is my personal notes for HTB Meow Machine. Since this is just a starting point, I will provide a quick and short walkthrough for my notes.

Weak Credentials Misconfiguration
January 7, 2025
3 min read
Read more

HackTheBox Starting Point: Fawn Walkthrough

This is my personal notes for HTB Fawn Machine

FTP Misconfiguration
January 8, 2025
2 min read
Read more

HackTheBox Starting Point: Dancing Walkthrough

This is my personal notes for HTB Dancing Machine

SMB Misconfiguration +1
January 9, 2025
3 min read
Read more

HackTheBox Starting Point: Explosion Walkthrough

This is my personal notes for HTB Explosion Machine

RDP Misconfiguration +1
February 4, 2025
2 min read
Read more

HackTheBox Starting Point: Redeemer Walkthrough

This is my personal notes for HTB Redeemer Machine

Redis Misconfiguration +1
February 4, 2025
1 min read
Read more

HackTheBox Starting Point: Appointment Walkthrough

In this blog post, we will walk through the process of enumerating and exploiting a misconfigured web application running on an Apache server.

SQL Injection Reconnaissance +1
February 6, 2025
2 min read
Read more

HackTheBox Starting Point: Mongod Walkthrough

Database Misconfiguration +2
February 6, 2025
2 min read
Read more

HackTheBox Starting Point: Preignition Walkthrough

Web Exploitation Reconnaissance
February 6, 2025
2 min read
Read more

HackTheBox Starting Point: Synced Walkthrough

Rsync Reconnaissance +1
February 6, 2025
2 min read
Read more

HackTheBox Starting Point: Crocodile Walkthrough

Web Exploitation Anonymous Access +1
February 8, 2025
3 min read
Read more

HackTheBox Starting Point: Responder Walkthrough

WinRM SMB +2
February 8, 2025
4 min read
Read more

HackTheBox Starting Point: Sequel Walkthrough

MySQL Database +1
February 8, 2025
2 min read
Read more

HackTheBox Starting Point: Three Walkthrough

Reverse Shell AWS S3 +1
February 10, 2025
4 min read
Read more

HackTheBox Starting Point: Bike Walkthrough

Walkthrough for the HackTheBox Starting Point machine "Bike", focusing on exploiting a NodeJS web application vulnerable to Server Side Template Injection (SSTI) to achieve Remote Code Execution (RCE).

NodeJS Remote Code Execution +1
February 11, 2025
4 min read
Read more

HackTheBox Starting Point: Ignition Walkthrough

Magento Weak Credentials +1
February 11, 2025
3 min read
Read more

HackTheBox Starting Point: Funnel Walkthrough

In this walkthrough, we will explore the HackTheBox Starting Point machine named "Funnel".

FTP SSH Tunneling +1
February 18, 2025
8 min read
Read more

HackTheBox Starting Point: Pennyworth Walkthrough

In this walkthrough, we will explore the HackTheBox Starting Point machine named "Pennyworth".

Jenkins RCE +1
February 23, 2025
1 min read
Read more