Hackthebox writeups
Writeups for HacktheBox 'boot2root' machines
Writeups for HacktheBox machines (boot2root) and challenges written in Spanish or English. The project is distributed under the GNU General Public License v3.0 license, first published in 2018. It has gained significant community traction with 2,040 stars and 496 forks on GitHub. Key topics include: boot2root, ctf, hackplayers, hackthebox, hackthebox-writeups.
hackthebox-writeups
Writeups for HacktheBox machines (boot2root) and challenges written in Spanish or English.
Important notes about password protection
Machines writeups until 2020 March are protected with the corresponding root flag. But since this date, HTB flags are dynamic and different for every user, so is not possible for us to maintain this kind of system. So from now we will accept only password protected challenges, endgames, fortresses and retired machines (that machine write-ups don't need password). For endgames or fortresses, the password should be all the flags concatenated.
Since June 2023, to verify flag challenges first contact us (oscar.alfonso.diaz@gmail.com).

Disclaimer
It is totally forbidden to unprotect (remove the password) and distribute the pdf files of active machines, if we detect any misuse will be reported immediately to the HTB admins.
Anyway, all the authors of the writeups of active machines in this repository are not responsible for the misuse that can be given to the corresponding documents. Please think that this is done to share techniques not for spoilers.
Submissions
If you want to incorporate your own writeup, notes, scripts or other material to solve the boot2root machines and challenges you can do it through a 'pull request' or by sending us an email to: hackplayers_at_Ymail.com.
In this way, you will be added to our top contributors list (see below) and you will also receive an invitation link to an exclusive Telegram group where several hints (not spoilers) are discussed for the HacktheBox machines.
Please consider protecting the text of your writeup (e.g. not allowing to be copied) so that it can not be easily shared on platforms such as Pastebin. Of course, if someone leaks a writeup of an active machine it is not the responsibility of the author. If we detect someone who does it, they will immediately report to the HTB Staff so they can take the appropriate measures.
Note: the minimum requirement to enter the "special" Telegram group is also to have a hacker level or higher (no script kiddies).
Star contributors (+5 writeups)
Occasional contributors (2-5 writeups)
Fleeting contributors (1 writeup)
| Ctry | nick | avatar | team | machines | challenges |
|---|---|---|---|---|---|
| <img src="./images/countries/kosovo.png" height="24" width="24"> | absolutezero | <img src="./images/absolutezero.png" height="42" width="42"> | Sentry | Fighter | |
| <img src="./images/countries/world.png" height="24" width="24"> | xephrox | <img src="./images/xephrox.png" height="42" width="42"> | solitaire wolf | Mischief | |
| <img src="./images/countries/usa.png" height="24" width="24"> | worldunruled | <img src="./images/worldunruled.png" height="42" width="42"> | hackmethod | Active | |
| <img src="./images/countries/usa.png" height="24" width="24"> | rtheory | <img src="./images/rtheory.png" height="42" width="42"> | FlavorTown | Reddish | |
| <img src="./images/countries/uk.png" height="24" width="24"> | thereverend | <img src="./images/thereverend.png" height="42" width="42"> | solitaire wolf | Active | |
| <img src="./images/countries/spain.png" height="24" width="24"> | Zaiuss | <img src="./images/zaiuss.png" height="42" width="42"> | L1k0rD3B3ll0t4 | Celestial | |
| <img src="./images/countries/spain.png" height="24" width="24"> | attl4s | <img src="./images/attl4s.png" height="42" width="42"> | juankeres | Falafel | |
| <img src="./images/countries/world.png" height="24" width="24"> | kauffman | <img src="./images/kauffman.png" height="42" width="42"> | solitaire wolf | Poison | |
| <img src="./images/countries/spain.png" height="24" width="24"> | revil | <img src="./images/revil.png" height="42" width="42"> | solitaire wolf | Sunday | |
| <img src="./images/countries/spain.png" height="24" width="24"> | k4nj1d | <img src="./images/k4nj1d.png" height="42" width="42"> | solitaire wolf | nibbles | |
| <img src="./images/countries/italy.png" height="24" width="24"> | giovii | <img src="./images/giovii.png" height="42" width="42"> | criuz | Mischief | |
| <img src="./images/countries/world.png" height="24" width="24"> | 3zculprit | <img src="./images/3zculprit.png" height="42" width="42"> | solitaire wolf | Olympus | |
| <img src="./images/countries/greece.png" height="24" width="24"> | FuxSocy | <img src="./images/fuxsocy.png" height="42" width="42"> | PhobosGroup | Dev0ops | |
| <img src="./images/countries/usa.png" height="24" width="24"> | abselithat | <img src="./images/abselithat.png" height="42" width="42"> | Pratum | Chatterbox | |
| <img src="./images/countries/spain.png" height="24" width="24"> | Killerloops | <img src="./images/killerloops.png" height="42" width="42"> | prosegur | Tear or dear | |
| <img src="./images/countries/italy.png" height="24" width="24"> | Renero | <img src="./images/renero.png" height="42" width="42"> | criuz | Digital Cube | |
| <img src="./images/countries/spain.png" height="24" width="24"> | Gibdeon | <img src="./images/gibdeon.png" height="42" width="42"> | PKTeam | Old Bridge | |
| <img src="./images/countries/spain.png" height="24" width="24"> | therearwindow | <img src="./images/therearwindow.png" height="42" width="42"> | solitaire wolf | Beatles | |
| <img src="./images/countries/russia.png" height="24" width="24"> | malwrecon | <img src="./images/malwrecon.png" height="42" width="42"> | solitaire wolf | Ypuffy | |
| <img src="./images/countries/world.png" height="24" width="24"> | labyrinth | <img src="./images/labyrinth.png" height="42" width="42"> | badwolf | Ebola Virus | |
| <img src="./images/countries/world.png" height="24" width="24"> | zdravich | <img src="./images/zdravich.png" height="42" width="42"> | TMHC | Carrier | Mission Impossible |
| <img src="./images/countries/montenegro.png" height="24" width="24"> | Wh04m1 | <img src="./images/Wh04m1.png" height="42" width="42"> | YoRHa | Ropme | |
| <img src="./images/countries/germany.png" height="24" width="24"> | coldBug | <img src="./images/coldbug.png" height="42" width="42"> | NeatMalwAreParty | Curling | |
| <img src="./images/countries/turkey.png" height="24" width="24"> | dionero | <img src="./images/dionero.png" height="42" width="42"> | solitaire wolf | Jerry | |
| <img src="./images/countries/bangladesh.png" height="24" width="24"> | TheShahzada | <img src="./images/TheShahzada.png" height="42" width="42"> | solitaire wolf | Mischief | |
| <img src="./images/countries/bangladesh.png" height="24" width="24"> | SadClown | <img src="./images/sadclown.png" height="42" width="42"> | solitaire wolf | Redcross | |
| <img src="./images/countries/spain.png" height="24" width="24"> | julianjm | <img src="./images/julianjm.png" height="42" width="42"> | solitaire wolf | Old Bridge | |
| <img src="./images/countries/world.png" height="24" width="24"> | snowman418 | <img src="./images/snowman418.png" height="42" width="42"> | solitaire wolf | Reel | |
| <img src="./images/countries/Romania.png" height="24" width="24"> | jondow | <img src="./images/jondow.png" height="42" width="42"> | Bailando | Help | |
| <img src="./images/countries/ukraine.png" height="24" width="24"> | lolfireball | <img src="./images/Lolfireball.png" height="42" width="42"> | solitaire wolf | Lightweight | |
| <img src="./images/countries/canada.png" height="24" width="24"> | solsanctum | <img src="./images/solsanctum.png" height="42" width="42"> | solitaire wolf | Carrier | |
| <img src="./images/countries/usa.png" height="24" width="24"> | fbbc | <img src="./images/fbbc.png" height="42" width="42"> | solitaire wolf | Conceal | |
| <img src="./images/countries/colombia.png" height="24" width="24"> | 4lexag | <img src="./images/4lexag.png" height="42" width="42"> | EphorSec | Cryptohorrific_es, Cryptohorrific_en | |
| <img src="./images/countries/cyprus.png" height="24" width="24"> | superhedgy | <img src="./images/superhedgy.png" height="42" width="42"> | Solitaire wolf | Netmon | |
| <img src="./images/countries/mexico.png" height="24" width="24"> | blazz3 | <img src="./images/blazz3.png" height="42" width="42"> | PwnD34L3rS | Sizzle | |
| <img src="./images/countries/spain.png" height="24" width="24"> | Marduk | <img src="./images/Marduk.png" height="42" width="42"> | PwnD34L3rS | Helpline | |
| <img src="./images/countries/france.png" height="24" width="24"> | lduros | <img src="./images/lduros.png" height="42" width="42"> | solitaire wolf | SwagShop | |
| <img src="./images/countries/uk.png" height="24" width="24"> | explmuzz | <img src="./images/explmuzz.png" height="42" width="42"> | N00b543V3R | Bastion | |
| <img src="./images/countries/world.png" height="24" width="24"> | AlhA | <img src="./images/AlhA.png" height="42" width="42"> | solitaire wolf | Emdee Five for Live | |
| <img src="./images/countries/uk.png" height="24" width="24"> | liamm | <img src="./images/liamm.png" height="42" width="42"> | PORTKNOCKWHOSTHERE | Jarvis | |
| <img src="./images/countries/greece.png" height="24" width="24"> | cavla | <img src="./images/cavla.png" height="42" width="42"> | Solitaire wolf | Crooked Crockford | |
| <img src="./images/countries/sweden.png" height="24" width="24"> | entropy | <img src="./images/entropy.png" height="42" width="42"> | Solitaire wolf | Crooked Crockford | |
| <img src="./images/countries/brazil.png" height="24" width="24"> | MrP4p3r | <img src="./images/MrP4p3r.png" height="42" width="42"> | Solitaire wolf | Fuzzy | |
| <img src="./images/countries/world.png" height="24" width="24"> | emmanuel | <img src="./images/emmanuel.png" height="42" width="42"> | Solitaire wolf | Craft | |
| <img src="./images/countries/world.png" height="24" width="24"> | Cript0crc | <img src="./images/crypt0crc.png" height="42" width="42"> | Solitaire wolf | Eemedefive for live | |
| <img src="./images/countries/world.png" height="24" width="24"> | bWlrZQo | <img src="./images/bWlrZQo.png" height="42" width="42"> | USCh4ck3r5 | Craft | |
| <img src="./images/countries/world.png" height="24" width="24"> | naveen1729 | <img src="./images/naveen1729.png" height="42" width="42"> | Solitaire wolf | Player | |
| <img src="./images/countries/spain.png" height="24" width="24"> | AmbrotD | <img src="./images/pepelu.png" height="42" width="42"> | Solitaire wolf | USB Ripper | |
| <img src="./images/countries/spain.png" height="24" width="24"> | danielcues | <img src="./images/danielcues.png" height="42" width="42"> | Ripp3rs | Mission Impossible | |
| <img src="./images/countries/germany.png" height="24" width="24"> | arcc | <img src="./images/arcc.png" height="42" width="42"> | Solitaire wolf | json bitlab | |
| <img src="./images/countries/india.png" height="24" width="24"> | CRYPT0HEX | <img src="./images/CRYPT0HEX.png" height="42" width="42"> | Solitaire wolf | Writeup | |
| <img src="./images/countries/pakistan.png" height="24" width="24"> | couchpotato | <img src="./images/couchpotato.png" height="42" width="42"> | Solitaire wolf | Heist | |
| <img src="./images/countries/australia.png" height="24" width="24"> | sneakypanda | <img src="./images/sneakypanda.png" height="42" width="42"> | Mystiko | Zetta | |
| <img src="./images/countries/switzerland.png" height="24" width="24"> | nitrow | <img src="./images/GDK.png" height="42" width="42"> | Solitaire wolf | Image Processing 101 | |
| <img src="./images/countries/colombia.png" height="24" width="24"> | Cyb3rb0b | <img src="./images/Cyb3rb0b.png" height="42" width="42"> | Solitaire wolf | Json | |
| <img src="./images/countries/uk.png" height="24" width="24"> | N7E | <img src="./images/N7E.png" height="42" width="42"> | iamroot | Mango | |
| <img src="./images/countries/india.png" height="24" width="24"> | Parteek Singh | <img src="./images/parteeksingh.png" height="42" width="42"> | D3v1L5 | Sniper | |
| <img src="./images/countries/canada.png" height="24" width="24"> | c1cada | <img src="./images/c1cada.png" height="42" width="42"> | CommandlineKings | Obscurity | |
| <img src="./images/countries/india.png" height="24" width="24"> | Mrigendra Soni | <img src="./images/mrigendra.png" height="42" width="42"> | Solitaire Wolf | Postman | |
| <img src="./images/countries/usa.png" height="24" width="24"> | mikeywayne | <img src="https://www.hackthebox.eu/storage/avatars/57bdca8ee4a702c56371607d6fbc9a7a.png" height="42" width="42"> | Solitaire Wolf | traverxec | |
| <img src="./images/countries/spain.png" height="24" width="24"> | Milo | <img src="https://www.hackthebox.eu/storage/avatars/0430c06bb395df9e041bc729cb70436c.png" height="42" width="42"> | p0t4t03s | ezpz | |
| <img src="./images/countries/india.png" height="24" width="24"> | N1Z4M | <img src="./images/nizam.png" height="42" width="42"> | 7eam4dholokam | OpenAdmin | |
| <img src="./images/countries/indonesia.png" height="24" width="24"> | corshine | <img src="./images/corshine.png" height="42" width="42"> | Solitaire Wolf | OpenAdmin | |
| <img src="./images/countries/usa.png" height="24" width="24"> | SevenLayerJedi | <img src="./images/SevenLayerJedi.png" height="42" width="42"> | Solitaire Wolf | Nest | |
| <img src="./images/countries/singapore.png" height="24" width="24"> | IamKsNoob | <img src="./images/iamksnoob.png" height="42" width="42"> | Solitaire Wolf | Postman | |
| <img src="./images/countries/tunisia.png" height="24" width="24"> | Bayrem | <img src="./images/bayrem.jpg" height="42" width="42"> | Cartographer | ||
| <img src="./images/countries/tunisia.png" height="24" width="24"> | Bayrem | <img src="./images/bayrem.jpg" height="42" width="42"> | Solitaire Wolf | Cartographer | |
| <img src="./images/countries/saudiarabia.png" height="24" width="24"> | 3gbCyber | <img src="./images/3gbCyber.png" height="42" width="42"> | KAU | OpenAdmin | |
| <img src="./images/countries/usa.png" height="24" width="24"> | FlapJack | <img src="./images/FlapJack.png" height="42" width="42"> | NashvilleCTF | OpenAdmin | |
| <img src="./images/countries/usa.png" height="24" width="24"> | wazKoo | <img src="./images/wazKoo.png" height="42" width="42"> | ScripTease | Traceback | |
| <img src="./images/countries/world.png" height="24" width="24"> | Shkk | <img src="./images/Shkk.png" height="42" width="42"> | Solitaire wolf | Monteverde | |
| <img src="./images/countries/poland.png" height="24" width="24"> | elklepo | <img src="https://www.hackthebox.eu/storage/avatars/e05d5e9f7f1c8aae15de81b1ba1dcb13.png" height="42" width="42"> | notSoBad | Fatty | |
| <img src="./images/countries/austria.png" height="24" width="24"> | Chr0x6eOs | <img src="https://www.hackthebox.eu/storage/avatars/25cf508b0c1a47dca6ced9166fcdd0fc.png" height="42" width="42"> | SickaLoot | QuickR | |
| <img src="./images/countries/russia.png" height="24" width="24"> | dayld | <img src="./images/dayld.png" height="42" width="42"> | Solitaire wolf | breaking grad | |
| <img src="./images/countries/canada.png" height="24" width="24"> | 7riple7hrea7 | <img src="./images/7riple7hrea7.png" height="42" width="42"> | p0tat0z | Interdimensional Internet | |
| <img src="./images/countries/france.png" height="24" width="24"> | caracal | <img src="./images/caracal.png" height="42" width="42"> | HideAndSec | Mr. Burns | |
| <img src="./images/countries/france.png" height="24" width="24"> | aminegr | <img src="./images/aminegr.png" height="42" width="42"> | Solitaire Wolf | Emdee five for life | |
| <img src="./images/countries/philippines.png" height="24" width="24"> | run3 | <img src="./images/run3.jpg" height="42" width="42"> | hack2tan | Mission Pinpossible | |
| <img src="./images/countries/singapore.png" height="24" width="24"> | Isopach | <img src="./images/isopach.jpg" height="42" width="42"> | Solitaire Wolf | Baby RE | |
| <img src="./images/countries/world.png" height="24" width="24"> | YoavD | <img src="./images/YoavD.png" height="42" width="42"> | Solitaire Wolf | HackyBird | |
| <img src="./images/countries/indonesia.png" height="24" width="24"> | adhkr | <img src="./images/adhkr.png" height="42" width="42"> | Solitaire Wolf | Stocker | |
| <img src="./images/countries/italy.png" height="24" width="24"> | R1D3R | <img src="./images/R1D3R.png" height="42" width="42"> | KernelChaos | Derailed |
Special note
Hack the Box is a superb platform to learn pentesting, there are many challenges and machines of different levels and with each one you manage to pass you learn a new thing. But talking among ourselves we realized that many times there are several ways to get rooting a machine, get a flag ... That's why we created this repository, as a site to share different unofficial writeups to see different techniques and acquire even more knowledge. That is our goal and our passion, to share to learn together.
Some people have been distrustful because in this repository there are writeups of active machines, even knowing that absolutely each one of them is protected with the corresponding password (root flag or challenge). But We did not want to give up this because we think the most interesting thing for a HTB player is to check other users' walkthroughs right after they get it, that is, not wait for weeks or months afterwards. For this reason, we have asked the HTB admins and they have given us a pleasant surprise: in the future, they are going to add the ability for users to submit writeups directly to HTB which can automatically be unlocked after owning a machine. And also, they merge in all of the writeups from this github page. Simply great!
Therefore it is a real pride that they have decided to include the functionality of this repo directly on their platform. When this is done, this Github will be migrated and will be inactive but with a pleasantly fulfilled mission. Until then, Keep pushing!
Hackplayers community, HTB Hispano & Born2root groups.
Contributors
Showing top 12 contributors by commit count.
