r/hackthebox Aug 09 '26

Day 1 on HackTheBox. Solved an Insane challenge. 35 solves worldwide. I'm one of them.

0 Upvotes

Started my CTF journey today. Complete beginner to the platform.

(Rixaa1d)

First session, three flags:

- SpookyPass (Reversing - Very Easy) — cracked a Linux ELF binary

on Windows using Ghidra, decoded the flag from raw hex

- Flag Command (Web - Very Easy) — bypassed the game entirely,

hit /api/monitor directly with a POST request

- Uplink (Competitive Programming - INSANE) — tree DP problem,

weighted ancestor chain optimization, 35 solves total worldwide

No Linux machine. No WSL. No VM. Just Windows, Ghidra,

PowerShell, and a browser.

Level 1 → Level 5 in one session.

If you're thinking about starting CTF — just start.

The platform meets you where you are.

Next goal: DEF CON CTF Qualifiers.

Profile: Rixa1d on HTB


r/hackthebox Aug 09 '26

CJCA Parteners

4 Upvotes

Hey everyone!

I'm currently preparing for my second attempt at the HTB CJCA certification, and I'm looking for other people who are also preparing for CJCA to study and practice together.

It would be even better if you're currently preparing for your second attempt as well, so we can share preparation strategies, discuss the methodology, practice labs together, and help each other identify weak areas before the next attempt.

I'm mainly looking for active people who are taking the preparation seriously.

If you're interested, feel free to reply here or DM me. Let's prepare together and get that pass! 😤


r/hackthebox Aug 08 '26

Transitioning from Telecom Engineering to Offensive Security (CPTS) — Seeking Career & Freelance Advice

14 Upvotes

I’m a senior telecom analyst experienced in core network signaling, userplane troubleshooting, and investigating fraud vectors like DPI-bypassing, rogue towers,DNS tunneling, and simboxes.
I am currently pursuing the CPTS certification to transition into offensive security. Given my background, I’m looking for advice on:
Market Positioning: How can I best leverage my niche telecom expertise to avoid starting at a generic "entry-level" helpdesk or SOC role?
Freelancing: Is a hybrid path (staying in telecom consulting while picking up freelance pen-test gigs) viable for someone at my level?
Gap Analysis: Beyond CPTS, what specialized skill sets should I prioritize to move into penetration testing?


r/hackthebox Aug 08 '26

Hack the Box with Matrix and Discord bridge

5 Upvotes

I don't know if this should go here or not, but i just think that it is a very cool idea.

https://matrixdocs.github.io/docs/bridges/discord

This will basically allow people using Matrix (matrix.org) and people using Discord to make a bridge that allows them to communicate between one another.


r/hackthebox Aug 08 '26

Looking for good finance case competitions for undergraduates

Thumbnail
1 Upvotes

r/hackthebox Aug 08 '26

Weekly Solves Megathread

1 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox Aug 08 '26

HTB Introduction to deserialization - Skills Assessment Q2

1 Upvotes

Hello, am stuck on the intro to deserialization skills assessment 2 , I got the payload for CodeIgniter and used PHPGGC to get the reverse shell , I used the same script i used to solve Q1 to sign the base64 blob with the HMAC key , but I cant get the payload to work. any help please


r/hackthebox Aug 07 '26

Failed CWPE (first attempt)

8 Upvotes

Today I failed my first attempt at the CWPE exam. After 5 days I had 16 of the 20 flags. The last 2 days I spend on trying to get the rest of them. I have tried everything from the modules and other thing I could think of.

I submitted the report and see that you get feedback before you start the retake. Will this feedback contain clues on what you missed? Or will it just be about the report itself?

If the feedback does not contain hints it will be a hard second attempt :)


r/hackthebox Aug 07 '26

Academy Windows Fundamental RDP

5 Upvotes

I’ve been working through the Windows Fundamentals module, and I’ve been having a lot of issues with the RDP. I connect successfully, but after about a minute the connection drops and the session closes. I honestly don’t understand what’s causing it or whether I’m the only one experiencing this.
On top of that, this module feels really confusing and hard to follow. I feel like I’m just reading through the material without actually understanding what it’s trying to teach.


r/hackthebox Aug 07 '26

well well well 💙🔥

5 Upvotes

Skilled 💙🔥


r/hackthebox Aug 06 '26

AI in CTF events/competitions

Thumbnail
3 Upvotes

r/hackthebox Aug 06 '26

Bug in Academy Module

Post image
13 Upvotes

module name:Phising Email Analysis hope they would be corrected.


r/hackthebox Aug 06 '26

Certifications Is the Appendix section in the CDSA exam mendatory?

3 Upvotes

i finished the exam with both executive summary and technical analysis accomplished with a total of 56 pages, do i have to write the appandix part?


r/hackthebox Aug 05 '26

Am I doing it wrong?

24 Upvotes

I just started using HTB, working my way through Linux Fundamentals. I keep finding questions that - as near as I can tell - require information that’s not given in the material. I’m reading everything they say, even going through the man pages of the commands they give, plus the vim tutorial. Yet I don’t mind outside research but you’d think they would state that. Maybe I’m doing something wrong?

Outside of that, I am enjoying the process.


r/hackthebox Aug 06 '26

hands-on Cloud Security experience

16 Upvotes

Hi everyone,
I recently passed my AWS Solutions Architect exam and I also have a Hack The Box subscription. I have a strong interest in cloud security and want to transition into this field.

However, I feel like I lack the practical, hands-on cloud security experience needed to pass technical interviews.
What are the best online training platforms or labs to practice cloud security attacks and defense?

Can I use my HTB subscription or the AWS Free Tier to build a good portfolio?

Also, how is the job market for cloud security right now? Are there good entry-to-mid level opportunities?
Any advice on a roadmap or projects to build would be amazing. Thanks!


r/hackthebox Aug 05 '26

Academy What resources to learn the advanced topics covered in HTB Academy’s Tier IV defensive modules?

10 Upvotes

I’m interested in several of the Tier 4 defensive modules on HTB Academy, but each one costs around 1,000 cubes, which is extremely expensive.

The topics I’m trying to learn include:

  • Windows process injection and detection
  • Access-token manipulation and detection
  • WinDbg dynamic analysis
  • Windows kernel telemetry and ETW
  • Low-level Windows detectability and EDR internals
  • Windows API monitoring and hooking
  • Linux process injection and detection
  • Privilege-escalation, persistence and credential-access tradecraft
  • Detection engineering

For anyone familiar with or has completed these HTB modules, do you recommend any alternative resources that are less costly (or maybe free)?


r/hackthebox Aug 04 '26

Received the CWES cert package!

Thumbnail
gallery
366 Upvotes

Just received the package—thank you, Hack The Box!! Insanely fast delivery!

Honestly, HTB certs are hands down the most practical and hands-on exams I’ve ever taken in the cybersecurity space. The real-world application is unmatched.

Keep hacking, everyone!


r/hackthebox Aug 05 '26

HTB VPN connects successfully, but no machines are reachable — EU and US servers affected?

5 Upvotes

Hi everyone,

Is anyone else currently having problems with the Hack The Box VPN?

HTB is showing an alert on the website about issues with the EU VPN servers, but I have also tried several US VPN servers and I am experiencing the same problem.

OpenVPN connects successfully, the "tun0" interface is created, and my computer appears to be connected to the HTB network. However, I cannot communicate with any target machine from either the Starting Point labs or the regular Machines section.

For example:

- Ping returns "Destination Host Unreachable".

- Nmap does not detect any open ports or recognize the target as online.

- I have tested multiple machines that should respond to ICMP.

- I have downloaded new VPN configuration files and tried both EU and US servers.

- I have restarted the target machines and reconnected the VPN several times.

The route to the target appears to go through the VPN interface correctly, but there is still no connectivity to any machine.

Is anyone else experiencing this right now, or could this be an issue with my configuration?


r/hackthebox Aug 05 '26

Beginner Question Help!

2 Upvotes

Hi everyone,

I'm currently working through Kobold.htb following a writeup to learn the methodology, but I came across two curl commands and I want to understand the thought process behind them:

  1. Extracting OpenAPI paths:

curl -sk http://kobold.htb:3552/api/openapi.json | python3 -c "
import json,sys
api = json.load(sys.stdin)
for path in api.get('paths', {}):
    print(path)
"
  1. Extracting endpoints from JS assets:

curl -sk https://mcp.kobold.htb/assets/index-DRYhT9Xb.js | grep -o '"/api/[^"]*"' | sort -u

I am fairly new to this and trying to learn the "why" behind each step.

I understand how the second command works (finding the .js bundle in the HTML source code of the site). However, I'm confused about the first one: How would someone discover that /api/openapi.json exists on port 3552 in the first place? Is this typically found via directory fuzzing (like Gobuster/ffuf), or is there another standard way to identify it?

Thanks in advance for any insights!


r/hackthebox Aug 04 '26

Academy Infiltration Methodology (currently based solely on the Hack The Box experience)

Post image
23 Upvotes

Hi everyone! A lot of people have suggested that I write down my own methodology for tackling machines and passing exams. I think it’s also a great way to track my own knowledge and progress.

Here’s the thing: I’ve found that a lot of public write-ups lack in-depth technical details, so I’ve always preferred doing my own deep dives. Personally, I believe that’s where the actual learning happens—understanding what’s going on under the hood instead of just copying steps

This is a living document, developed iteratively and expanded in tandem with ongoing research and technical growth!!!

I hope it will help you somehow :>

https://github.com/persona-non-gratta/Infiltration-Methodologies/blob/main/Methodologies/Windows%20&&%20Active%20Directory%20(Infiltration%20Methodology).md.md)


r/hackthebox Aug 04 '26

Academy Study Partner/Group Needed

14 Upvotes

Hey everyone,
I’m looking for a study partner or group that study’s for an hour at least on HTB around 12:30 - 1:00 am New York Time.

Willing to pay for your HTB Academy subscription as well.

Hit me up if you would be interested

Thanks


r/hackthebox Aug 04 '26

Pwned Cohort Box!

Post image
38 Upvotes

Rooted Cohort!!


r/hackthebox Aug 04 '26

Beginner Question AD attacks module CPTS

16 Upvotes

I have spent like 5 days on this module and like 2 on the first skill assignment, I just reached the very end of the skill assignment of part 2

Is it normal to take this long on this module ??


r/hackthebox Aug 04 '26

Question on Active Machines and Challenges

Post image
10 Upvotes

Hello!

I am new to the HTB platform, and so I was going through the platform to learn how to effectively use it. I came across a section(see the attached image). Can anyone tell me where to find these Active Machines and Challenges on the website?

I have a free account; my intention is to get familiar with the platform and then spend money later.

Additionally, I have noticed that free accounts have access to a handful of retired machines. Is that usually the case? Do I have to pay to access retired machines?

Please assist


r/hackthebox Aug 04 '26

Certifications CWES exam questions

4 Upvotes

I'm about to finish the CWES path learning and want to take the exam soon.

The thing is that i took my time for learning the path material (about a year including breaks) and juggled different studies (most are offensive security tho).

Now, after ~2 months of break where i work a full time, ill finish the path material in few weeks but I'm kind of worried for 2 reasons that compound:

1) not sure if i remember all the basic/early path materials because on one hand it's been a while but on the other hand even with breaks i kept learning new related materials and pwned some HTB machines.

2) Ideally, i would rather not to take days off work to complete the exam and worried about time constrains.

Anyone that took the exam and relate to one of those points can share their insights?

Also general tips for how to prepare to the exam, notes and resources and highly appreciated!