Hackfail.htb

Ensure that configuration files for security tools like Fail2Ban are only writable by the root user.

Look for API keys or database passwords. hackfail.htb

If /var/run/docker.sock is accessible, you can use it to spawn a new container that mounts the host's root filesystem. 👑 Phase 4: Privilege Escalation to Root Ensure that configuration files for security tools like

Disable Git hooks for non-admin users in Gitea's app.ini . 👑 Phase 4: Privilege Escalation to Root Disable

Check the web application for leaked credentials or look for "Register" buttons that might be open.

Navigating to the IP address on port 80 reveals a custom web application. Further directory busting or clicking through links often reveals a development sub-domain or a linked service. In the case of HackFail, you will encounter a instance, a self-hosted Git service popular among developers. 🏗️ Phase 2: Initial Access (Exploiting Gitea)

The first step in any penetration test is understanding the attack surface. Port Scanning A standard Nmap scan reveals two open ports: Open, running OpenSSH. Port 80 (HTTP): Open, serving a web application. Web Discovery

    index: 1x 0.036262989044189s
t_/pages/products/product-new: 1x 0.034295082092285s
t_/blocks/feedbacks: 1x 0.013991832733154s
t_/common/header-new: 1x 0.0061960220336914s
t_/blocks/product/product-sidebar: 2x 0.0032138824462891s
t_/common/footer-new: 1x 0.0027520656585693s
t_/common/head: 1x 0.0020101070404053s
t_/blocks/product/related-products: 1x 0.0014228820800781s
router_page: 1x 0.0010380744934082s
t_/blocks/product/sentiment-pack: 1x 0.00080108642578125s
router: 1x 0.00071501731872559s
t_/blocks/product/top-resources: 1x 0.00064802169799805s
t_/blocks/product/categories: 1x 0.00062394142150879s
t_/common/cookie-banner: 1x 0.0005791187286377s
t_/popups/on-download: 1x 0.00043296813964844s
t_/blocks/product/articles-about: 1x 0.00036811828613281s
service-routes: 1x 0.0001838207244873s
t_/blocks/sidebar-afil: 1x 0.0001680850982666s
router_redirection: 1x 0.00010490417480469s
t_/popups/zoom: 1x 3.4093856811523E-5s
t_/blocks/product/templates-with: 1x 2.4080276489258E-5s
----- END OF DUMP (2026-05-08 21:38:05)  -----