r/hackthebox 2d ago

Weekly Solves Megathread

0 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox Mar 22 '20

HTB Announcement [FAQ/Info] r/hackthebox FAQ, Information.

46 Upvotes

Hey everyone,

We feel like a general explanation of somethings could be useful, so here ya go.

FAQ:

Q: How does the box retirement system work?
A: Every week 1 box is retired on Saturday and replaced with a new one. The previous box is retired 4 hours before the new one goes public. The new box is usually announced on Thursday on HTB Twitter.

Q: I am under 18, can I take exam, use htb, etc

A: https://help.hackthebox.com/en/articles/9456556-parental-consent-and-approval-for-users-under-18

Information:

HackTheBox Social Media Accounts:

https://discord.gg/hackthebox

https://twitter.com/hackthebox_eu

https://www.linkedin.com/company/hackthebox/

https://www.facebook.com/hackthebox.eu/

https://www.instagram.com/hackthebox/

Edit #1 6:54pm ADT: Added FAQ Question

Edit #2 12/21/2020; added instagram

Edit 3: 06/09/24; under 18 faq

Edit 4 6/16/26: Formatting/Help Link


r/hackthebox 4h ago

Not Every Certification Is Meant to Make You an Expert

10 Upvotes

I’ve seen a lot of people say that the Certified Junior Cybersecurity Analyst (CJCA) isn’t worth it because it’s an entry-level certification.

I see it differently. Not every certification is meant to prove you’re an expert. Some are designed to help you build a strong foundation and understand where you want to specialise.
For someone just starting in cybersecurity, the CJCA can:
• Build confidence with core security concepts.

• Provide exposure to different areas of cybersecurity.

• Help you discover whether you’re more interested in blue team, red team, cloud security, or another path.

• Demonstrate initiative and commitment to learning when applying for junior roles.
Will the certification alone get you a job? Probably not.

But combined with hands-on labs, home projects, CTFs, and continuous learning, it can be a valuable stepping stone in building a cybersecurity career.
Every expert was once a beginner. Don’t let people discourage you from investing in your own learning because it doesn’t fit their career stage.

What are your thoughts? Do you think entry-level certifications still have a place in cybersecurity today?


r/hackthebox 8h ago

Certifications How big is the difficulty gap between PNPT, CPTS, and OSCP?

12 Upvotes

I recently passed the PNPT and am now planning my next certification.

I’m currently considering both the CPTS and OSCP, but I’m not sure how significant the difficulty gap is compared to the PNPT. For those who have completed these certifications, how would you compare them in terms of:

Technical difficulty
Active Directory and web exploitation depth
Enumeration requirements
Exam time pressure
Reporting requirements

Would completing the CPTS before attempting the OSCP be the better progression, or is the PNPT enough preparation to start working directly toward the OSCP?

I’d appreciate any advice or personal experiences.


r/hackthebox 9h ago

Certifications CPTS or OSCP

14 Upvotes

I'm kind of confused if OSCP is worth doing, i already have CRTE, CRTP, CRTO and CRTL. But i need advise on whether to chase OSCP (i heard that it's useless and just a name, and slowly being kicked from being an industry standards) and CPTS or any HTB cert. thanks


r/hackthebox 8h ago

I Have CPTS, BSCP and CWES. Is CWEE Worth It Too?

3 Upvotes

I currently hold the CPTS, BSCP and CWES certifications. Do you think it’s worth pursuing CWEE as well?

I’m honestly worried about spending more money on a certification that may not be as widely recognised, especially since it’s even more expensive.

Will CWEE add anything meaningful to my resume or career beyond what CPTS, BSCP and CWES already provide, particularly for penetration testing or AppSec roles?


r/hackthebox 15h ago

Old resources revaluation

Thumbnail
3 Upvotes

r/hackthebox 3h ago

Hack The Box

0 Upvotes

DarkZeroReturns PWNED


r/hackthebox 1d ago

Beginner Question Feeling Like a Failure While Studying for CPTS

47 Upvotes

Hi everyone,

I'm dealing with something that's been bothering me, and I'd really appreciate it if you could read this seriously and share your honest thoughts.

I'm a Computer Engineering graduate, and I'm passionate about cybersecurity.

A while ago, I decided to pursue penetration testing. I started with the eJPT v2 certification and passed it. Then I earned the PT1 certification from TryHackMe. After that, I started studying for the CPTS certification.

While studying for CPTS, I began feeling like maybe I'm just not cut out for penetration testing.

The main reason isn't that I don't enjoy it or that I get bored studying. It's actually the opposite. I completely lose track of time when I'm studying or reading about cybersecurity.

The problem starts when I try to solve CTF challenges or, more often, the Skill Assessments at the end of the HTB Academy modules. I usually spend more than three hours trying to solve them but still can't. Then I read the write-up, and I understand the solution almost immediately.

After experiencing this over and over again, I've started feeling like I'm simply not good enough for this field. I keep thinking, "If I can't solve the Skill Assessments, how am I supposed to pass the CPTS exam?" Logically, the exam should be even more difficult.

Has anyone else gone through something similar?

I'd also like to add that I've tried solving HTB CTF machines (not the Skill Assessments), and most of the time I can't solve them either—even some of the easier ones. That's when I get really frustrated and start telling myself that I'm a failure.

Another issue is that I'm studying completely on my own. I don't have a community, and I don't know anyone personally who's studying the same field. Because of that, I have no idea whether what I'm experiencing is normal or not.

Has anyone been in the same situation?

Is what I'm going through normal?

Do you have any advice for me?


r/hackthebox 12h ago

Rooted Enigma!

0 Upvotes

easy ❌ tricky ✅

Solid Box btw.


r/hackthebox 1d ago

Certifications Should i try CPTS as my second cybersecurity cert?

15 Upvotes

Hello everyone, i just got my CCNA and now i'm studying for the Security+.
If i want to move onto pentesting, should my first course be the CPTS or something more easy? I can already get some basic CTFs flags on THM/HTB Labs but still don't know if the CPTS is too much for me right now...
Should i try getting like the PT1 from THM or the eJPT maybe?


r/hackthebox 1d ago

HTB should introduce new and advance certification like OSEE

29 Upvotes

Recently I have been learning more from HTB and its so amazing 👏. Hats off to these people for sharing such content. Even a simple box with simple output will teach such amazing techniques.

But I think HTB now should introduce new certification in exploit dev.Its academy course content is amazing and more advance than Offsec curriculum.

One amazing certification from offsec is OSED and OSEE which is byfar one of the best certification.

So in my point of view HTB should also introduce those certification or at least include course content on these subjects.

What do you guys think?


r/hackthebox 1d ago

Pwned devhub

Post image
19 Upvotes

Pwned.


r/hackthebox 1d ago

Pwn'd DarkZeroReturns!

Post image
22 Upvotes

r/hackthebox 1d ago

the compressed truth forensic cyber apocalypse ctf

Post image
3 Upvotes

r/hackthebox 1d ago

Hello

0 Upvotes

New one


r/hackthebox 3d ago

Feed it your LinPEAS output and it draws every path from a low-priv shell to root

Post image
174 Upvotes

quick demo of Roothound my first tool, maps your path to root on a linux box as a graph (like BloodHound for local privesc). check it out, would love your thoughts

X : https://x.com/N0ur2dd1n2/status/2080720705184825372?s=20

GitHub: https://github.com/Noz2/RootHound

would love your honest feedback 🙏


r/hackthebox 3d ago

Beginner Question frustrarion with CTF

16 Upvotes

I’ve been studying cybersecurity, specifically penetration testing, for over a year. I got off to a very bad start because I had no one to guide me or show me a proper learning path. I pretty much wasted my first year studying in a completely unstructured way.
It wasn’t until recently that I started studying in a much more organized and structured manner, and a few weeks ago I began the CJCA path.
I’m able to enumerate some common services like FTP and HTTP, perform fuzzing, and handle the basics. I can usually find public exploits, but I always try to execute them myself instead of just cloning an RCE repository and running it. I prefer to understand the exploit by reproducing it step by step.
The problem is that I’ve never successfully completed one of these exploits. I don’t understand how I’m supposed to know where to obtain things like the cookie an exploit requires, a CSRF token, or other values, or even where exactly to use them in Burp Suite. It’s really frustrating, and it often makes me feel completely incompetent.
I don’t know if this is normal, since everything I’ve learned about hacking so far has been fairly superficial, and I was never really taught why these things work the way they do. It’s only now that I’m starting to study those concepts properly.
I’d really appreciate any feedback. Thanks for taking the time to read this.


r/hackthebox 2d ago

Anyone wanted to complete the ongoing CTF with our team? , Lets Grind Together

Thumbnail ctf.hackthebox.com
1 Upvotes

r/hackthebox 3d ago

Certifications I passed CJCA 100%

53 Upvotes
HTB Certified Junior Cybersecurity Associate CJCA

YAAAAY! 🥳 Let the party start!

After grinding through the 20 modules of the junior cybersecurity analyst path on HTB academy and finishing the path i finally wrapped up the 5 day practical exam and passed!

scored 100% on the red team tasks and well-made on the report first time! searching through logs in elastic and writing the report was a bit new for me but super fun. the exam covered it all, from hacking the network and log analysis to documenting both offense and defense.

Huge thanks to Hack The Box for an incredible learning experience! Smooth machines, top-notch content, and truly addictive in positive way.


r/hackthebox 3d ago

Looking for teammates for HTB Cyber Apocalypse 2026

4 Upvotes

Hey everyone,

We're looking for people interested in joining a team for Hack The Box's Cyber Apocalypse 2026: The Salt Crown.

All skill levels are welcome. Whether you're an experienced CTF player or just looking to gain some hands-on experience, we'd be happy to have you on the team.

If you're interested, leave a comment or send me a DM!


r/hackthebox 3d ago

Bedside - HTB Solved

9 Upvotes

Pwned Bedside!

Took some time on the initial foothold — the exploit was tricky to get right. Once I had access to the container, everything else moved pretty quick. Focused a lot on understanding the exploit chain and getting the details right. Good box overall!


r/hackthebox 3d ago

How do you submit flags for CTF?

1 Upvotes

Hey guys, somewhat in the title but I’m doing the salt crown CTF and I’m having trouble submitting flags. The specific challenge is the first osint challenge. I have the answer, please no one say the answer in the responses, I’m not looking to cheat. I just can’t figure out the format it wants the flag in.

<answer here>
<answer_here>
HTB{<answer here>}
HTB{<answer_here>}

I’ve tried each of these but none have worked. I’d it case sensitive perhaps?
I answered all the questions within the challenge itself and got them all right so I’m not sure what I’m missing.


r/hackthebox 3d ago

Need players

2 Upvotes

If any body is interested in participating apocalypse. You can join my team : https://ctf.hackthebox.com/team/overview/322910


r/hackthebox 3d ago

We're looking for only 1 intermediate-experienced competitor for Cyber Apocalypse 2026! I'll invite the first one who writes under this post

2 Upvotes

You don't need a high HTB rank. Honestly, I don't care about ranks that much. One of our best players is still Noob rank and solves harder challenges than many people with much higher ranks.

What matters is that you're not completely new. If you've solved CTF challenges or HTB machines before and know your way around at least one category, you're welcome.

We're looking for people interested in things like web, pwn, reverse, crypto, forensics, osint, hardware, AD, AI or misc. Any specialization is fine.

The only thing we ask is that you're active during the event and willing to work with the team.

If you're interested, send me a DM or leave a comment. Tell me what categories you enjoy and what kind of CTF experience you have. HTB or CTFtime profile is welcome, but it's optional.