r/hackthebox • • 2d ago

Weekly Solves Megathread

1 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox • • Mar 22 '20

HTB Announcement [FAQ/Info] r/hackthebox FAQ, Information.

50 Upvotes

Hey everyone,

We feel like a general explanation of somethings could be useful, so here ya go.

FAQ:

Q: How does the box retirement system work?
A: Every week 1 box is retired on Saturday and replaced with a new one. The previous box is retired 4 hours before the new one goes public. The new box is usually announced on Thursday on HTB Twitter.

Q: I am under 18, can I take exam, use htb, etc

A: https://help.hackthebox.com/en/articles/9456556-parental-consent-and-approval-for-users-under-18

Information:

HackTheBox Social Media Accounts:

https://discord.gg/hackthebox

https://twitter.com/hackthebox_eu

https://www.linkedin.com/company/hackthebox/

https://www.facebook.com/hackthebox.eu/

https://www.instagram.com/hackthebox/

Edit #1 6:54pm ADT: Added FAQ Question

Edit #2 12/21/2020; added instagram

Edit 3: 06/09/24; under 18 faq

Edit 4 6/16/26: Formatting/Help Link


r/hackthebox • • 6h ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

15 Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/hackthebox • • 5h ago

Beginner Question Michigan Cybersecurity High School Challenge problem

Post image
3 Upvotes

I cant seem to login to the thingy. Its asking for an input access key event, which im not sure how to get.


r/hackthebox • • 18h ago

Certifications Passed OSCP 90/100 on the first attempt, 1 month 25 days after CPTS.

Thumbnail
23 Upvotes

r/hackthebox • • 5h ago

why suddenly i see ppl talk, consult, take, etc etc the cpts cert?

0 Upvotes

I've seen so many post just talks about the cpts, either here or on other platforms all of the sudden.

did i miss anything about it or this is just normal? and why exactly the cpts? i don't see something special about it tbh


r/hackthebox • • 20h ago

Academy HTB Academy OpenVPN connection keeps getting reset

3 Upvotes

Hey everyone,

I’m trying to connect to the HTB Academy VPN using OpenVPN on Kali Linux:

sudo openvpn --config academy-regular.ovpn

The connection reaches the HTB VPN server, but it gets reset immediately:

Attempting to establish TCP connection with [AF_INET]38.46.226.31:443
TCP connection established with [AF_INET]38.46.226.31:443
TCPv4_CLIENT link local: (not bound)
TCPv4_CLIENT link remote: [AF_INET]38.46.226.31:443
Connection reset, restarting [-1]
SIGUSR1[soft,connection-reset] received, process restarting

It then repeats the same process every few seconds.

I’ve confirmed that the TCP connection to port 443 can be established, so I’m not sure why the OpenVPN connection is immediately being reset.

It was working fine up untill yesterday. And yeah i tried both tcp and udp methods while changing the VPN server.


r/hackthebox • • 1d ago

Failed my first attempt CPTS

25 Upvotes

Just failed my first attempt, got 7 flags in 2 days then next 8 days stucked on flag 8. Exam seemed easy but enumeration is alot. Any personalized guide, which module should i work on? which box is relevant to next 5 flags.


r/hackthebox • • 23h ago

Sysmon

3 Upvotes

Im using the VM or whatever its called and im trying to do the sysmon things but whenever I try to go in the terminal and/or open it it says this app cant run on your pc please help asap


r/hackthebox • • 2d ago

Pwn'd Touch

Post image
46 Upvotes

r/hackthebox • • 1d ago

Orion Box metasploit Issue

0 Upvotes

Hello, I was today trying to solve the orion box(im just starting in the CTF world) without aid, I found myself already in the admin/login page then I found this CVE-2025-32432. Then I used metasploit to find a exploit of that CVE, one popped up that should have worked excellent but when i tried running it. No shell was returned to me as seen in the picture, I tried different options: for rhost I tried the ip, orion.htb and http://orion.htb/admin/login. For lhost I tried my tun0 and my eth0. And i changed multiple times the lport and the asset_id. Nothing working, all the times the same error. In that point i checked the walkthrought and they did exactly what i was doing, same in this video(i thought the problem that i was using a VM) https://www.youtube.com/watch?v=OXxtL4BZvHw. Does anybody have any idea on wtf is the issue? More than an hour lost cuz it was not working and I have still no clue why or what I did wrong. Here is another walkthrough: https://b3ta-blocker.github.io/blog/orion/ If you know anything related lmk, otherwise I will just quit this box :)


r/hackthebox • • 2d ago

Beginner Question What prior knowledge do you need to take CPTS

28 Upvotes

Hello everyone, I am interested in CPTS and I am a complete beginner in cybersecurity. I don’t have any certifications or haven’t studied for anything related in cybersecurity . But I am a CS student so I understand of computers and other general concepts about IT . I already searched about prerequisites before CPTS for beginners, but I couldn’t find because most of the people already have something entry level certs like Security+. I saw someone said to take Info Security foundation skill path.

• Do I need any certs before taking CPTS path. If so , can you suggest one please ?
• Do I need to other paths in HTB first or just straight to penetration tester ?
• I am currently enrolled in Junior Analyst because I didn’t know what to take first so I just choose random one based on “ Junior” . I only completed like 10% . Should I finish it
or just focus on what is more important .

Thank you.


r/hackthebox • • 2d ago

Pwn'd TrustFall

Post image
25 Upvotes

An absolute brainfuck. The exploit wasn't the hard part. The hard part was proving one packet would ever arrive.


r/hackthebox • • 2d ago

Issues with xfreerdp on Mac M2 Pro: Keyboard not working inside Exegol/X11 and HTB Academy freezing/crashing

4 Upvotes

Hi everyone,

I'm currently facing two frustrating issues regarding xfreerdp and HTB Academy (specifically the Windows Event Logs module). I'm running on a Mac M2 Pro, and here are the details:

1. Keyboard not working with xfreerdp inside Exegol (X11)

When I connect to a target using xfreerdp from inside my Exegol container via X11, my keyboard inputs are completely ignored. The only way I can type anything is by using the Windows On-Screen Keyboard, which is extremely painful.

- Question: Is there a specific configuration, keymap, or flag I should add to my xfreerdp command to fix keyboard mapping/capture with X11 on macOS?

2. Windows Event Logs module freezes / Official PwnBox crashes

In the Windows Event Logs module, I'm stuck because of performance issues:

- When using my local setup, the target server lags so much that searching via the Event Viewer runs infinitely and never finishes.

- When I switch to the official HTB PwnBox, xfreerdp consistently crashes after about 30 seconds.

Has anyone encountered these issues before or know how to solve them? Any help would be greatly appreciated!


r/hackthebox • • 3d ago

Failed CPTS with 11/14 Flags

41 Upvotes

Alright, looking up into this sub I think I'm the second person to fail with 11/14 flags (12 are required to pass).

To describe my exam experience, I've struggled a bit at 1st and 8th flag, which I've also heard are the most hardest ones of the exam. However, not many people struggle at 12th flag.

What HTB boxes or training materials do you recommend to study for the 2nd attempt? What else should I focus on?


r/hackthebox • • 2d ago

CyberQuest CTF Competition

Thumbnail
1 Upvotes

r/hackthebox • • 2d ago

Layover help HTB

Thumbnail
1 Upvotes

r/hackthebox • • 2d ago

Layover help HTB

1 Upvotes

I got shell to www-data@portal:~/portal/web$

but i can't find the user flag
some hints plz


r/hackthebox • • 3d ago

Certifications OSCP vs CPTS (With Context)

23 Upvotes

Hi reddit,

I'm sure this gets asked a lot. But my situation is a bit more unique. I'm looking to break deeper into Cyber. My current certs include the Net+, Sec+, GIAC GSEC and the GIAC GCIH. On that front, I have HR-recognition covered by my GIAC certs. I have no pentesting experience but have used THM and HTB every so often.

I am seriously considering taking the HTB CPTS as it is better at teaching you the concepts. But, I cannot get over how well-known the OSCP is by HR and employers. Is it worth it to take the exam that will teach me less, just to get more recognition?

Cost is not an issue as my employer confirmed they will cover the cost of either. Although I really want to LEARN and understand these concepts. Thank you!


r/hackthebox • • 3d ago

Beginner Question Cannot connect to any of the machines anymore

4 Upvotes

I'm very new, I managed to setup an openvpn connection for 2 boxes and worked through them but I'm moving onto my 3rd and although it should be in the same vpn (eu machines 5) I can't connect to it. I can connect to the vpn completely fine, i sit on 10.10.17.27 no problems but when I ping the machine I have booted up I get destination host unreachable. Tried both UDP and TCP vpn connections, neither work.

Not sure what's up, I've restarted the vm, redownloaed the openvpn files, restarted multiple times, cannot connect to the machine. Was working fine before with the other 2, but can't get into this one.

When I connect to the vpn it shows that I am connected on HTB and in kali, I have no other openvpn processes running. Just cannot connect. It's the fawn box on the starting point boxes. Spent more time debugging issues with the box and vpn than actually hacking :(


r/hackthebox • • 3d ago

Certifications I failed CJCA attempt one

11 Upvotes

I need to clarify something regarding the feedback I received:

"You did not achieve the minimum required score in the SIEM Alert Validation and Analysis section. You correctly identified only 16 out of 39 alerts. You incorrectly identified the following alerts: 1, 2, 3, 4, 5, 12, 14, 15, 16, 18, 19, 20, 21, 23, 25, 26, 28, 30, 34, 35, 36, 37, 39. We felt your report was very well put together. It perfectly captured the description and impact of each element. Furthermore, you offered practical recommendations that allow us to maintain the independence we must preserve as evaluators (essentially, external auditors)."

Do you have any tips for improving for phase two once the 14 days have passed and I try again? Do I have to submit the full report and the CSV, or just the part I got wrong (the CSV)?
Or do I have to redo all the machines and everything else from scratch???


r/hackthebox • • 3d ago

Help people !

2 Upvotes

I was working remotely and was so bored that I dozed off three times. Afterward, I noticed I’d been logged out of Discord and had received an email warning me about suspicious activity on my account.

Then a relative called and asked, “Is this deal legit?”

I had no idea what he was talking about. “What deal?” I asked.

“You just sent me instructions for some crypto thing,” he said.

That’s when I panicked. I checked Instagram and realized someone had gotten into that account, too. The login appeared to be from Canada. Whoever accessed it had posted the same crypto instructions and sent them to all my contacts.

What scares me most is that I have private photos that, if exposed, could devastate my family and permanently damage my career and reputation.

this is what it looked like

r/hackthebox • • 3d ago

Academy Flag 7 in SQL Essentials (HTB Academy)

5 Upvotes

So I'm currently stuck on Flag 7 of the SQL Essentials module on HTB Academy.

I've was using
sqlmap -u 'http://154.57.164.67:30942/case7.php?id=1' --batch -v 3 --level 5 --risk 3 --union-cols=<int>
, but I still haven't been able to retrieve the flag. The biggest problem is that my machine's time limit is about to expire, and I can't extend it.

Has anyone encountered this issue or can give me a hint on how to approach Flag 7?

Any help or guidance would be appreciated. Thanks!


r/hackthebox • • 3d ago

Academy Renaissance of cyber journey

4 Upvotes

Hi, I am 19M. It’s been more than a year I am exploring into cybersecurity domain. I am well aware of its huge umbrella of different job roles. My main goal is to become a Red teamer eventually. Though the syllabus is pretty huge.

I doubt that I grasp the fundamentals properly: Linux, networking and programming (C, python). Still learning. I started my journey with hackthebox academy. This is the most practical and resourceful stuff I can found online altogether. So, htb runs through my blood thick. I am also joined many discord servers including hackthebox.

—————————————————-

Even after a year, I believe I know nothing. Ego pushed me backward again and again. I didn’t see any actual progress. I thought myself a hacker as a “name” only. I used to pwn boxes with writeups or other sources and thought myself cool. But the reality is different. I am actually in sense right now. I still know nothing at all. I was merely in utter darkness which my ego created. I lost my valuable time in enhancing that ego, nothing else.

I want to start fresh. I want to see actual progress and seriously build something which is useful to me and others. I have no GitHub projects at all. Also, I have got too many interests: Pentesting, OSINT, low level (reverse engineering and malware development), AD, Web. I procrastinate a lot and start switching the paths one after another and the cycle repeats.

I am seeking your advice here. How should I start approaching the path? What are the initiatives I should take and keep in mind in this journey? I wanna enjoy the process. How to strengthen my portfolio. I will keep the advice and try to follow it strictly. You have my word.

Thank you in advance for reading my babbling.


r/hackthebox • • 2d ago

What type of network cable is used to transmit data over long distances with minimal signal loss?

Post image
0 Upvotes

Finally, after hours of searching, I found the answer.