HackTheBox | Secret 🤐 (Linux | Easy) | Beginners Walkthrough

Опубликовано: 22 Март 2026
на канале: SecAura
509
16

Today we root the Secret 🤐 (Linux | Easy) machine from HackTheBox! - Like and Subscribe :)

⏱️Timestamps/Steps:
➡️ 00:00 - Port scan
➡️ 00:30 - Web enum
➡️ 01:00 - Web review
➡️ 03:00 - Source code review
➡️ 04:40 - API review
➡️ 09:00 - Using git to find JWT secret token
➡️ 10:00 - JWT review
➡️ 12:00 - Forging an admin token following code review
➡️ 15:00 - Code review to get remote access
➡️ 20:00 - System enumeration to priv esc
➡️ 23:00 - SUID binary priv esc review of C code
➡️ 28:00 - Crahing C program to dump root id_rsa
➡️ 30:40 - SSHing as root using root id_rsa
➡️ 31:37 - Outro / why havent been uploading - sorry!!

For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE    • HackTheBox | Web/OSWE  
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert)    • OSWE "Build and Break it" Guide (Offensive...  
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.

⭐️Linux Hacking + Priv esc -    • HackTheBox | Linux  
⭐️Windows Hacking + Priv esc-    • HackTheBox | Windows  
⭐️Active Directory Hacking -    • HackTheBox | ActiveDirectory  
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...
⭐️Link to box:
🔗 https://app.hackthebox.com/machines/408