Post

Hack The Box Season 11 writeups

Tracker for my Hack The Box Season 11 writeup repository covering Reactor, DevHub, Connected, Checkpoint, Enigma, Paperwork, MakeSense, Bedside, DarkZeroReturns, Cohort and DanglingTree.

Hack The Box Season 11 writeups

Overview

My Hack The Box Season 11 writeups live in a public repository:

1
https://github.com/ALLAKORI/htb-season-11-writeups

The season is over and the machines have retired, so the full notes are now public. The repository contains exploitation notes, CVE and vulnerability mapping, commands, evidence, attack-chain summaries, remediation guidance and redacted flags.

Current Season 11 coverage

MachineOSDifficultyStatus
ReactorLinuxEasyWriteup completed
DevHubLinuxMediumWriteup completed
ConnectedLinuxEasyWriteup completed
CheckpointWindowsMediumWriteup completed
EnigmaLinuxEasyWriteup completed
PaperworkLinuxEasyWriteup completed
MakeSenseLinuxMediumWriteup completed
BedsideLinuxMediumWriteup completed
DarkZeroReturnsWindows / Active DirectoryHardWriteup completed
CohortLinuxEasyWriteup completed
DanglingTreeWindows / Active DirectoryMediumWriteup completed

Vulnerability coverage

Each writeup includes a dedicated CVE/vulnerability section when a named vulnerability was part of the chain.

This overview lists the vulnerability names and the broad stage only, not the exploit payloads or target-specific steps.

MachineCVEs / vulnerability names coveredBroad stage
ReactorCVE-2025-55182 React2Shell / React Server Components RCE; CVE-2025-66478 Next.js RSC advisory; Node.js Inspector misconfigurationInitial access; privilege escalation
DevHubCVE-2026-23744 MCPJam Inspector Remote Code Execution; exposed Jupyter token; hardcoded OPSMCP API key and hidden admin toolInitial access; lateral movement; privilege escalation
ConnectedCVE-2025-57819 FreePBX Endpoint Manager SQL injection to RCE; Incron / DAHDI local misconfigurationInitial access; privilege escalation
CheckpointActive Directory object recovery, ACL abuse, dMSA / BadSuccessor abuse, memory forensics, Pass-the-HashActive Directory chain
EnigmaCVE-2026-38751 OpenSTAManager module-upload RCE PoC; related CVE-2025-69212 OpenSTAManager command-injection context; CVE-2026-27626 OliveTin password argument command injectionFoothold; privilege escalation
PaperworkLPD command injection; PJL path traversal and arbitrary file write; SCM_RIGHTS file descriptor leak; password reuseInitial access; user escalation; privilege escalation
MakeSenseHardcoded client-side encryption key; stored XSS; WordPress administrator account creation; PHP reverse shell; credential reuse; internal OCR-to-PHP root RCEInitial access; lateral movement; privilege escalation
BedsideCVE-2025-64512 pdfminer.six pickle deserialization RCE; internal development-server path traversal; PyTorch checkpoint deserialization through torch.load(); shared datastore permission boundary failureInitial access; container-to-host pivot; privilege escalation
DarkZeroReturnsCVE-2026-33937 Handlebars AST injection RCE; related CVE-2021-23369 Handlebars RCE context; Gitea Actions workflow trust abuse; Kerberos/AD ACL abuse; forest-trust ExtraSID and DCSync chainInitial access; lateral movement; Linux root; domain and cross-forest compromise
CohortCVE-2026-39987 Marimo pre-auth Terminal WebSocket RCE; SSRF loopback bypass through 127.1; nginx/vhost pivot to Marimo; CVE-2026-41651 PackageKit TOCTOU / Pack2TheRootInitial access; privilege escalation
DanglingTreeCVE-2026-23760 SmarterMail password reset authentication bypass; CVE-2026-24423 SmarterMail ConnectToHub RCE; Windows Admin Center pivoting; SmarterMail backup recovery; DPAPI credential decryption; ForceChangePassword ACL abuse; AD CS ESC1 certificate impersonationInitial access; lateral movement; domain compromise

Documentation standard

Each writeup follows the same structure:

SectionPurpose
Machine informationQuick platform, OS, difficulty and attack-focus context
SummaryShort executive explanation of the compromise path
CVEs and vulnerabilities usedNamed vulnerabilities, affected products and where they fit in the chain
Exploitation stepsReproducible notes with commands and evidence
Attack-chain summaryCompact end-to-end view of the compromise
Lessons learnedWhat the lab reinforced technically
RemediationDefensive guidance mapped to the weaknesses found
FlagsRedacted user/root flag status

Season ended, repository now public

Hack The Box active-machine material includes live exploitation chains, credentials, target-specific paths and flags. Full notes were kept private while the machines were active to avoid spoiling the lab for other players.

Season 11 has now ended, the machines have retired, and the material has been reviewed for safe publication. The repository is public.

Takeaway

Season 11 is useful practice for chaining realistic issues across Linux services, web applications and Windows Active Directory environments. The main value of the writeups is not just the final flag, but the discipline of documenting:

  • what was observed,
  • why a pivot made sense,
  • which evidence confirmed the path,
  • and how the same weakness could be remediated defensively.
This post is licensed under CC BY 4.0 by the author.