HTB Stories #3 - 0xdf - Creating HTB Machines

Опубликовано: 17 Февраль 2026
на канале: Hack The Box
8,166
308

00:00 - Introductions: Meet 0xdf!
06:03 - What inspired you to start making this content?
09:36 - How submission process work?
12:07 - How long does it take to submit a box and for it to be live at the HTB platform?
13:56 - What are the criteria to accept a submitted machine?
17:47 - Which are unique points that HTB looks for in a vulnerable machine?
18:06 - I saw someone posted their box rejected from HTB. What content of the box that HTB would like to accept? I don't want to waste time after put effort into creating a box.
20:03 - What’s your Methodology when making boxes?
23:58 - How do you create harder and harder challenges and what are your inspirations to do so?
26:12 - How long does usually it take to create a good no guessy hard/insane box for you
28:25 - How do you balance difficulty for medium/hard challenges on topics such as binary exploitation and crypto?
31:30 - In your opinion, what is harder: making an interesting and memorable foothold, or the privesc?
33:05 - Do you think that a privesc should have a logical link with the foothold or is it fine to have completely unrelated topics between the two?"
34;01 - How do you establish the difficulty of a box before submitting it? Do you have a group of people you ask to evaluate or do you do it based on your own experience?
37:16 - Have you ever encountered any 0-day exploits while making a machine?
40:20 - Can a box be developed with more than one intended way or should they have only one intended path?
42:38 - How do you find out what to call or name your machines
45:29 - Which OS to choose for making boxes?
51:15 - What do you do to ensure that there aren’t unintended solutions on boxes?
54:35 - I just wanna know that why they don't make mac os machines?
55:40 - How are the flag file contents created when the box is spawned for every HTB user and synchronized with the HTB platform for submission? I wanted to make a box for HTB and that is where I got stuck.
59:23 - What mitigations are put in place to help make sure that users are not accidentally (or purposefully) being malicious? Like attempting DDOS attack on machines or piggybacking off of others’ progress? I'm guessing the HTB infra has some mechanisms but what should box creators do to help with this?
1:01:54 - What virtualization technology is using to create box?
1:03:52 - I was thinking of making multi-network machines using only docker. Any tips?
1:05:42 - I think submitted machines share a lot, why not create a repo on HTB github with packer/vagrant/ansible common templates and common scripts to build machines.
1:07:26 - Does making HTB machines require skills in the software development side of things?

Ever wondered what's behind the creation of #HTB machines? 🔥
Our amazing Training Lab Architect @0xdf_ is here to explain to you all about how to create successful submissions, what will help you, and what you should be aware of! 🚨
ALL Tips & Tricks in one video!
Read more on our blogpost about Vulnerable Machine Submissions, written by 0xdf & ‪@ippsec‬ here ➡️ https://www.hackthebox.eu/blog/make-v...

Keep on hacking, Keep on Rocking 😎

#AskMeAnything #CyberSecurity #Hacking #HackTheBox #HTB