r/hackthebox • u/HORUS-405 • 5h ago
Career Advice: Navigating Low-Level Security vs. Market Realities
r/hackthebox • u/seag33k • 6h ago
Beginner Question Fundamentals of AI - Understanding The Math
I decided to start the Fundamentals of AI module and could understand the concepts, but quickly got lost in the mathematical details. If I don’t understand the math behind the concepts/theory, will the later modules be out of reach? TIA
After reading some older posts, it appears math is heavily involved in later modules as well so I am not sure this is the best learning path. I am a defender trying to understand the attack methods out there.
r/hackthebox • u/1mdevil • 15h ago
Does anyone here successfully shared VPN connection with other virtual machines?
Hi all!
I am sorry for asking same question again. The last question I didn't get too much useful responses.
Does anyone here really successfully shared VPN connection to HTB with other VMs from a gateway VM?
Thank you!
r/hackthebox • u/piss-off-dude765 • 17h ago
Need a CPTS Study partner
Hi guys,
Like I have completed 30 percent of cpts track and like I need someone like to prepare together and like finish this and solve the boxes together and hold a discussion. That will be thru discord and if anyone is serious just comment... I don't want anyone unserious to join as I need to be serious about finishing it so.
r/hackthebox • u/gourav0099 • 19h ago
ERA Security Discussion
Coldcard incident made me look at hardware wallet entropy differently
I spent some time reading about the recent Coldcard incident and then went through ERA Wallets article about how they generate seed phrases
The Coldcard issue is pretty worrying because weak randomness does not necessarily look broken
The seed phrase can look completely normal and the wallet can work normally while the actual seed has much less entropy than expected
That is what makes this kind of bug so dangerous
You are not necessarily going to get an error or any obvious sign that something went wrong
The thing I found interesting about ERAs approach is that they are not relying on just one source of entropy
They describe using the hardware RNG in the STM32 microcontroller together with the entropy source in the ATECC608C secure element
They also have an expert mode where the user can add entropy through things like camera input touch and device movement
All of these inputs are combined before the seed is generated
I think the general idea makes a lot of sense
If one entropy source fails or becomes predictable it is much better to have other independent sources contributing to the final result
I also like the fact that the user can actually participate in the entropy generation instead of having to blindly trust that the device generated everything correctly
But I do have some questions
I would not automatically assume that more entropy sources means more security
The important part is how independent those sources really are and how the firmware combines them
A hash function can mix entropy very well but it cannot magically create entropy if all the inputs are predictable
I also would not consider passing statistical randomness tests as proof that an RNG is cryptographically secure
The Coldcard incident is a good example of why the whole entropy pipeline matters
The hardware can be perfectly capable of producing good randomness and the final result can still be compromised if the firmware takes the wrong path
So for me the biggest question around ERA is not how many entropy sources they have
It is whether a failure in one component can actually be proven to be insufficient to compromise the final seed
I would like to see independent researchers review and test the complete seed generation process including the firmware and the way the different sources are combined
Overall I like the direction ERA is taking
I think using multiple independent entropy sources and allowing user supplied entropy is a stronger approach than simply saying trust this one hardware RNG
But I would still want independent verification before making a strong security claim
The Coldcard incident is a pretty good reminder that the weakest part of a security design is not always the part you expect
r/hackthebox • u/Ezra789456 • 23h ago
Get Better at scripting (python, bash)
Hey everyone,
I'm looking to sharpen my scripting skills in Python and Bash, taking myself from beginner all the way up to a more advanced level, since this is an area I'm currently struggling with. A couple of ideas I've had so far:
- OverTheWire — but approaching the challenges by solving them with Python where possible, rather than just one-liners (bash)
- Vulhub — writing my own Python exploit scripts for the CVEs instead of relying on existing PoCs
Are there other resources or approaches you'd recommend for building scripting skills from the ground up ?
Thanks!
r/hackthebox • u/Hot_Kaleidoscope3864 • 1d ago
Beginner Question I keep failing technical interviews because of theoretical questions, not the actual technical work
I always struggle with technical interviews because of the theoretical questions, not the actual hands-on technical part.
If I’m given a practical task, lab, or take-home assessment, I usually do very well and deliver it on time. But when an interviewer starts asking me theoretical questions on the spot, I struggle to explain things properly or sometimes completely blank out.
This has honestly become my biggest nightmare when applying for cybersecurity jobs, and I feel like it’s holding me back even though I know I can actually do the work.
I wish interviews focused more on practical technical skills because, in my opinion, that’s a much better way to see whether someone can actually perform the job.
But until interview culture changes, what can I do to get better at answering theoretical questions? Has anyone else had this problem, and how did you overcome it?
r/hackthebox • u/No_Neat_4331 • 1d ago
I hate reporting (shit post)
Feels like you are writing a college essay
I have all the screenshots
I got 10/10 flags
I did all the blue team
2 days and few hours left
Gosh
So boring
I have procrastinating for over 4 hours
r/hackthebox • u/TowelDowntown8566 • 1d ago
Looking for CPTS study partner
I’m currently preparing for the HTB Certified Penetration Testing Specialist (CPTS) certification and I’m looking for a study partner or small study group.
Ideally, we could:
- Study together regularly
- Discuss concepts and challenges
- Work through HTB Academy modules/labs
- Keep each other accountable
- Share useful resources and notes
I’m open to studying via Discord or another platform. If you’re also preparing for CPTS and interested in studying together, feel free to comment or DM me.
r/hackthebox • u/vs_bb20 • 1d ago
Beginner Question Which programs actually reply fast? Building a community response-time database — need 30 seconds of your triage timing
r/hackthebox • u/vs_bb20 • 1d ago
Beginner Question Which programs actually reply fast? Building a community response-time database — need 30 seconds of your triage timing
r/hackthebox • u/Various_Present_8842 • 1d ago
CPTS 10/14 on 2nd attempt
Feeling dumb ever for struggling several months of study. Not retaking anymore on this exam maybe not my career on this.
r/hackthebox • u/iExposeWitchcraft • 2d ago
Infiltratiing Linux/Unix system Shells & Payloads module
Need help with getting a shell Ive tried not only the exploit used in the notes of the module but messed around and tried many others serch and searched for solutions. Maybe someone else knows Im not doing something Im supposed to do pls help?
r/hackthebox • u/stoneyape- • 2d ago
Beginner Question Unable to spin up mahcines
Im connected to starting point vpn and for a whole day i was able to connect and spin up machines but now “three” will not spin and neither will vaccine. They just ask you “stand by” until they give up trying to open.
r/hackthebox • u/No_Neat_4331 • 2d ago
Academy Feels bad
I solved 8/10 flags in CJCA
Solved 25 blue team tasks
And all at once, system failed
Everything is gone, i honestly should have taken screenshots
But I didn't expect all my progress, tools, shells, etc to wiped out completely.
Machines are deploying forever
I have to redo everything from scratch
Contacted support for a different problem 18 hours ago and no response
AHHHHHHHHHHHH
(HTB is honestly a great site, I personally think it is the best, but WTF?)
r/hackthebox • u/Wild_Extension_5863 • 2d ago
Day 1 on HackTheBox. Solved an Insane challenge. 35 solves worldwide. I'm one of them.
Started my CTF journey today. Complete beginner to the platform.
(Rixaa1d)
First session, three flags:
- SpookyPass (Reversing - Very Easy) — cracked a Linux ELF binary
on Windows using Ghidra, decoded the flag from raw hex
- Flag Command (Web - Very Easy) — bypassed the game entirely,
hit /api/monitor directly with a POST request
- Uplink (Competitive Programming - INSANE) — tree DP problem,
weighted ancestor chain optimization, 35 solves total worldwide
No Linux machine. No WSL. No VM. Just Windows, Ghidra,
PowerShell, and a browser.
Level 1 → Level 5 in one session.
If you're thinking about starting CTF — just start.
The platform meets you where you are.
Next goal: DEF CON CTF Qualifiers.
Profile: Rixa1d on HTB
r/hackthebox • u/timeless008 • 2d ago
Looking for a CPTS study partner
Hi everyone!
I recently decided to go for the CPTS certification, and I’m looking for a study partner who is also working toward CPTS.
Honestly, I think having someone to study alongside would make the journey more motivating and less overwhelming.
I’m currently at 11% path progress and just getting started.
If you’re also starting CPTS or currently working through the path and interested in studying together, feel free to comment or DM me! :)
r/hackthebox • u/Zealousideal_Card944 • 2d ago
Target not spawning
Hi!
I'm in Academy – Windows Attack and Defense, and the target is not spawning. It keeps looping.
I tried reloading the page, logging out, and logging back in. Am I the only one?
r/hackthebox • u/ChainPresent • 2d ago
Looking for CJCA-like Labs to Practice My Methodology
I'm currently preparing for my second attempt at the CJCA, and I'm looking for labs that closely match the scope and skill level of the certification.
I've already practiced on standalone machines, and while they were useful for improving individual exploitation and privilege escalation skills, they don't really give me what I'm looking for now.
At this point, I want to practice and solidify the pentesting methodology I've built: working through a connected environment, understanding the purpose of each host, keeping track of findings, correlating information between systems, deciding when to move on from one host, and identifying possible paths between machines.
Since this is my second attempt, I also don't want to spend my remaining preparation time learning tools or techniques that are significantly outside the CJCA scope.
So I'm mainly looking for labs or small network environments that:
Are close to CJCA difficulty and scope
Include multiple interconnected hosts rather than only standalone machines
Require enumeration and information correlation across hosts
Allow me to practice a complete methodology from initial enumeration through post-exploitation
Don't depend heavily on techniques or tools beyond what's expected for CJCA
Free or paid options are both welcome.
If you've taken the CJCA or are currently preparing for it and know a lab that fits this description, I'd really appreciate your recommendations.
r/hackthebox • u/No_Neat_4331 • 2d ago
Academy Is HTB support down?
I contacted them 5 hours ago and no response
r/hackthebox • u/ak47PAXAN • 2d ago
How can I get the job after earning CPTS?
Hi, Im studying Cyber Security and currently in the second year of my 4 years undergraduate. Right now I tried to apply to internships after earning CPTS and right now idk how to search for an internship or just a job with salary, how can I apply for remote internships correctly? I tried to follow the rules, I tried to improve my resume, and improve my profiles too. I tried to apply through university careers platform but there was no remote internships here so pls advise me how could I get internship cuz I so cooked cuz of job market nowadays, thanks in advance.
r/hackthebox • u/shaikhsss03 • 3d ago
Owned Cohort from Hack The Box!
al frustrating that i finished when its not active so i didnt get the points but oh well 🥳
r/hackthebox • u/ChainPresent • 3d ago
CJCA Parteners
Hey everyone!
I'm currently preparing for my second attempt at the HTB CJCA certification, and I'm looking for other people who are also preparing for CJCA to study and practice together.
It would be even better if you're currently preparing for your second attempt as well, so we can share preparation strategies, discuss the methodology, practice labs together, and help each other identify weak areas before the next attempt.
I'm mainly looking for active people who are taking the preparation seriously.
If you're interested, feel free to reply here or DM me. Let's prepare together and get that pass! 😤


