🔧 ProgrammierungThis Week In Rust: This Week in Rust 667(02.09.2026 um 06:00 Uhr)
🔧 ProgrammierungThe Rust Programming Language Blog: Announcing Rust 1.98.1(03.09.2026 um 02:00 Uhr)
🔧 ProgrammierungThis Week In Rust: This Week in Rust 668(09.09.2026 um 06:00 Uhr)
🐧 Linux TippsUpdated Debian 13: 13.7 released(12.09.2026 um 02:00 Uhr)
🕵️ SicherheitslückenUSN-8563-5: nginx vulnerability(14.09.2026 um 13:35 Uhr)
🕵️ SicherheitslückenUSN-8752-1: Konsole vulnerability(14.09.2026 um 13:52 Uhr)
🕵️ SicherheitslückenUSN-8753-1: libinput vulnerability(14.09.2026 um 14:28 Uhr)
🕵️ SicherheitslückenUSN-8754-1: Freeciv vulnerability(14.09.2026 um 14:40 Uhr)
🔧 ProgrammierungThis Week In Rust: This Week in Rust 667(02.09.2026 um 06:00 Uhr)
🔧 ProgrammierungThe Rust Programming Language Blog: Announcing Rust 1.98.1(03.09.2026 um 02:00 Uhr)
🔧 ProgrammierungThis Week In Rust: This Week in Rust 668(09.09.2026 um 06:00 Uhr)
🐧 Linux TippsUpdated Debian 13: 13.7 released(12.09.2026 um 02:00 Uhr)
🕵️ SicherheitslückenUSN-8563-5: nginx vulnerability(14.09.2026 um 13:35 Uhr)
🕵️ SicherheitslückenUSN-8752-1: Konsole vulnerability(14.09.2026 um 13:52 Uhr)
🕵️ SicherheitslückenUSN-8753-1: libinput vulnerability(14.09.2026 um 14:28 Uhr)
🕵️ SicherheitslückenUSN-8754-1: Freeciv vulnerability(14.09.2026 um 14:40 Uhr)

🔧 Programmierung 🕛 vor 3 Monaten 4 Min Lesezeit
0

Hack The Box (HTB): Cap Machine (Full Walkthrough)

↗ Quelle (dev.to)
🗣️ Stimme:

Welcome! In this article, we will try to solve the Cap Machine from HackTheBox and provide as many details as we can so it can be a reference for anyone who wants to recall any part of it.





-Pn: if the machine is refusing the ping requests, port scan only.

-p-: if for scanning all ports.

-sC: Scan with default NSE scripts.

-sV: attempts to find the version of the service.

— min-rate 10000: Send packets no slower than 10000 per second.



So, as we can see, it’s 3 ports open: 21 (FTP), 22 (SSH), 80 (HTTP).




Answer: 3








Task 2: After running a “Security Snapshot”, the browser is redirected to a path of the format /[something]/[id], where [id] represents the id number of the scan. What is the [something]?



It’s a web enumeration task, let’s try the http port, so we write this domain in our website:




  • with this side menu:






  • As we can see, the [something] part is data.




Answer: data.








Task 3: Are you able to get to other users’ scans?



We tried some ids from 0 to 10 on the URL instead of 1, and we found that ID 0 gives some packets in a .pcap file:






Username: nathan

Password: Buc**************

Answer: yes








Task 4: What is the ID of the PCAP file that contains sensitive data?




Answer: 0








Task 5: Which application layer protocol in the pcap file can the sensitive data be found in?



As we can see from the screenshot above from the wireshark analysis, it’s communicating via ftp.



Answer: ftp







Task 6: We’ve managed to collect Nathan’s FTP password. On what other service does this password work?



We’ll try getting access using ssh, by writing this command:




CODE
ssh [email protected]






And we got it:






Answer: /usr/bin/python3.8







Conclusion



This machine was a great exercise in enumeration and privilege escalation. It reinforced the importance of carefully analysing exposed services and reviewing file permissions for potential escalation vectors.



Thank you for reading this walkthrough. Any feedback or suggestions for improvement are always appreciated.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
Setting up live captions stuck in Windows 11
1 Quelle
Burn Out, Or Fade Away
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Hack The Box (HTB): Cap Machine (Full Walkthrough)

Thematisch verwandte Begriffe: Hack, Machine, Full, Walkthrough · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...