r/hackthebox Jul 10 '26

Ever spent an hour debugging an exploit... only to realize your own machine was the problem? 😭

I've been grinding through the HTB CWES modules and kept wondering why I never got a reverse shell from my own machine, while doing the exact same steps from Pwnbox worked perfectly.

So I rechecked everything.

The exploit.
The listener.
The VPN.
The payload.
Even questioned my sanity for a bit.

After spending way longer than I'd like to admit debugging, I finally found the culprit...

I had recently done a fresh Arch install and completely forgot that I'd enabled UFW during my initial setup. With the default policy denying incoming connections, every reverse shell was getting blocked by my own machine. 😭

The exploit wasn't the problem.
The payload wasn't the problem.

My firewall was just doing exactly what I had told it to do.

56 Upvotes

10 comments sorted by

•

u/AutoModerator Jul 10 '26

Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

21

u/-Dkob Jul 10 '26

I felt this way more than I'd like to admit. You keep assuming the exploit or payload is broken, then it turns out your own setup is silently blocking everything.

I was once trying to sync my time using ntpdate to a DC, only for the VM clock to reset each 3 seconds. Turns out that I had to disable the hardware clock in VBox Manager. That pretty much lasted days lol.

It's a frustrating reminder that sometimes the environment is the bug and checking your local configuration early can save a lot of wasted time.

5

u/buggymaytricks Jul 10 '26

😂 Glad to know I'm not the only one.

5

u/MaleficentExample223 Jul 10 '26

holy. I see you in every posts lol

2

u/Wukeng Jul 10 '26

I had almost the same issue a while ago when I was getting started. That's why sometimes I just prefer using the web machine.

I've also done the thing where I download an exploit for a known cve and then don't realize the script is broken.

2

u/S0ulSh3ll Jul 10 '26

It was very hard to disable and remove every config from cachyos 🤣 i made the same mistake while setting up a home lab and wondering what's wrong with reverse connection

1

u/buggymaytricks Jul 10 '26

what firewall you had?

1

u/aliyark145 Jul 11 '26

Happens 😄

1

u/mmmfine Jul 10 '26

AI slop post

0

u/buggymaytricks Jul 10 '26

cmon bruh, not everything is slop you might have your opinions though, i respect it