Hack The Box: Artificial Machine Walkthrough – Easy Diffucilty

Hacking the “Artificial” Machine on Hack The Box!

Conquered the “Artificial” machine on Hack The Box! 🕵️‍♂️ I scanned the target, identified a web server on port 80, and created an account to access its dashboard, where I uploaded a malicious .h5 file to trigger a reverse shell. Using a Docker environment, I gained a shell as the app user, found a SQLite database (users.db), and cracked its password hashes to reveal credentials for user “gael,” allowing me to grab the user flag via SSH from user.txt. For root, I discovered port 9898 running Backrest, forwarded it, and enumerated backup files, finding a bcrypt-hashed password in config.json. Decoding a base64 value yielded a plaintext password, granting access to the Backrest dashboard, where I exploited the RESTIC_PASSWORD_COMMAND to trigger a root shell and secure the root flag from root.txt.

#Cybersecurity #HackTheBox #CTF #PenetrationTesting #PrivilegeEscalation

The post Hack The Box: Artificial Machine Walkthrough – Easy Diffucilty appeared first on Threatninja.net.

October 25, 2025
Read More >>

Indian Army Inducts Advanced Ground-Based Mobile ELINT System

The Indian Army has approved the induction of a cutting-edge Ground-Based Mobile Electronic Intelligence System (GBMES) valued at over ₹1,000 crore.Developed to enhance India’s battlefield awareness and electronic warfare superiority, this system will track, intercept, and analyse enemy radar and communication emissions round the clock, providing the Army with a sustained electronic edge in both

October 25, 2025
Read More >>