~/mbt
back to writeups
This machine is currently active on the platform. Full writeup is not available.
hack the-boxmachineeasyWindows active

Touch - HackTheBox

Approach

01

Leaked a device serial via an unauthenticated API.

02

Found a stored kiosk credential, used it for RDP in restricted environment.

03

Bypass restricted Kiosk RDP environment to spawn a user shell.

04

Hardcoded credentials in a scheduled script.

05

Abused writable MySQL plugin dir to load a UDF/DLL.

Full writeup is restricted while this machine is active.

The writeup will be published here once the machine is retired.