HackTheBox | EarlyAccess 🎮(Linux | Hard) Detailed Walkthough

Опубликовано: 20 Февраль 2026
на канале: SecAura
1,042
37

Today we root EarlyAccess 🎮(Linux | Hard) machine from HackTheBox! - Like and Subscribe :)⏱️Timestamps/Steps:
➡️ 00:00 - Intro
➡️ 00:10 - Port scan
➡️ 00:38 - Web Enumeration
➡️ 01:30 - Web app first look
➡️ 02:38 - Web app forum review
➡️ 05:20 - HTML injection / XSS
➡️ 06:20 - XSS validation
➡️ 07:00 - Session Hijacking Overview
➡️ 09:00 - Creating an HTTPS python server
➡️ 10:00 - Stealing Admin session via XSS on HTTPS Server
➡️ 11:10 - Loggin in as Admin
➡️ 12:30 - Finding some python code to generate an access code
➡️ 13:00 - Reverse engineering the python code
➡️ 16:05 - Reverse engineering G1
➡️ 21:45 - Reverse engineering G2
➡️ 28:38 - Reverse engineering G3
➡️ 35:13 - Reverse engineering G4
➡️ 38:33 - Reverse engineering G5 (checksum)
➡️ 45:20 - Burp Suite intrudering the generated licenses against the web app
➡️ 48:00 - Accessing game.earlyaccess.htb with key
➡️ 48:30 - Second Order SQL injection via name field
➡️ 55:25 - Logging in as admin to dev.earlyaccess.htb
➡️ 57:00 - Getting LFI via file.php
➡️ 58:00 - Getting hash.php code via php base64 filter
➡️ 59:00 - Reverse Engineering PHP code to find RCE
➡️ 1:03:00 - Getting Reverse shell
➡️ 1:04:40 - Shell as www-data
➡️ 1:05:00 - Password reuse to get www-adm
➡️ 1:06:30 - Find .wgetrc to auth to API:5000 and get creds to drew user
➡️ 1:09:40 - SSH/login as drew
➡️ 1:10:00 - Reading drews mail, hinting toward game server crash to get RCE
➡️ 1:11:00 - Finding ssh creds to a game-server docker container
➡️ 1:12:30 - SSH into game-server
➡️ 1:12:40 - Review game-server files, intuition to get root
➡️ 1:14:50 - Reverse server.js
➡️ 1:16:40 - Crash game server
➡️ 1:17:00 - Use game crash to test writing root file
➡️ 1:19:30 - Use game crash to get Root reverse shell
➡️ 1:21:40 - Docker root
➡️ 1:22:40 - Docker priv esc via shared folder mounting
➡️ 1:23:35 - Real Root
➡️ 1:23:50 - Outro

For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE    • HackTheBox | Web/OSWE  
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert)    • OSWE "Build and Break it" Guide (Offensive...  
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.

⭐️Linux Hacking + Priv esc -    • HackTheBox | Linux  
⭐️Windows Hacking + Priv esc-    • HackTheBox | Windows  
⭐️Active Directory Hacking -    • HackTheBox | ActiveDirectory  
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...