HackTheBox | Horizontall↔️ (Easy | Linux)

Опубликовано: 10 Март 2026
на канале: SecAura
447
26

Today we root Horizontall↔️ (Linux | Easy) machine from HackTheBox! - Like and Subscribe :)⏱️Timestamps/Steps:
➡️ 00:00 - Intro
➡️ 00:10 - Port scan
➡️ 00:38 - Web directory/subdomain enumeration
➡️ 01:10 - Dirbusting the newly found subdomain
➡️ 01:20 - Finding vuln STRAPI CMS service
➡️ 01:50 - ExploitDB Blind RCE on STRAPI
➡️ 03:10 - RCE to Reverse shell
➡️ 04:00 - Enumeration of Linux system (linpeas+linenum)
➡️ 05:30 - Enumeration of file system to find DB credentials
➡️ 08:40 - Database enumeration
➡️ 09:20 - Attempting to hashcat found hash
➡️ 10:20 - Reviewing of enum scripts to find local service running on 8000
➡️ 11:40 - Using SOCAT to create a tunnel to the internal service at 8000
➡️ 12:30 - Accessing internal 8000 service, finding vuln LARAVEL service
➡️ 12:40 - Exploiting LARAVEL to get root RCE
➡️ 16:20 - Root
➡️ 16:35 - Outro / link to SQL injection Videos

For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE    • HackTheBox | Web/OSWE  
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert)    • OSWE "Build and Break it" Guide (Offensive...  
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.

⭐️Linux Hacking + Priv esc -    • HackTheBox | Linux  
⭐️Windows Hacking + Priv esc-    • HackTheBox | Windows  
⭐️Active Directory Hacking -    • HackTheBox | ActiveDirectory  
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...