HackTheBox : Pterodactyl Writeup
Summary Pterodactyl is a Linux box built around an unauthenticated RCE in the Pterodactyl game-server management panel. A static "MonitorLand" landing page on port 80 gives no functionality of its own

Search for a command to run...
Articles tagged with #htb-writeup
Summary Pterodactyl is a Linux box built around an unauthenticated RCE in the Pterodactyl game-server management panel. A static "MonitorLand" landing page on port 80 gives no functionality of its own

Summary Garfield is a Windows Active Directory box centered on an attack path that's invisible to standard BloodHound collection: SYSVOL file-level write access that isn't reflected in AD object ACLs.

Summary Watcher is a Linux box built around a self-hosted Zabbix monitoring stack. The front door isn't a permissions misconfig at all - it's a real Zabbix CVE (CVE-2024-22120), a time-based blind SQL

Summary Phoenix is a WordPress box with a long, winding path to root. The short version: an unauthenticated SQL injection in a forum plugin leaks the whole WordPress database, which gives admin creden

Summary Escape is a Windows box that exposes only RDP (3389). The RDP session drops you into a locked-down kiosk account (KioskUser0) meant for a "Conference Display" app. The box is solved entirely t

Summary Manage is a Linux box built around an exposed Java RMI / JMX service running alongside an Apache Tomcat 10.1.19 web server. The JMX endpoint had no authentication configured, which allowed a r
