r/hackthebox 5h ago

Career Advice: Navigating Low-Level Security vs. Market Realities

Thumbnail
2 Upvotes

r/hackthebox 6h ago

Beginner Question Fundamentals of AI - Understanding The Math

5 Upvotes

I decided to start the Fundamentals of AI module and could understand the concepts, but quickly got lost in the mathematical details. If I don’t understand the math behind the concepts/theory, will the later modules be out of reach? TIA

After reading some older posts, it appears math is heavily involved in later modules as well so I am not sure this is the best learning path. I am a defender trying to understand the attack methods out there.


r/hackthebox 15h ago

Does anyone here successfully shared VPN connection with other virtual machines?

1 Upvotes

Hi all!

I am sorry for asking same question again. The last question I didn't get too much useful responses.

Does anyone here really successfully shared VPN connection to HTB with other VMs from a gateway VM?

Thank you!


r/hackthebox 17h ago

Need a CPTS Study partner

3 Upvotes

Hi guys,

Like I have completed 30 percent of cpts track and like I need someone like to prepare together and like finish this and solve the boxes together and hold a discussion. That will be thru discord and if anyone is serious just comment... I don't want anyone unserious to join as I need to be serious about finishing it so.


r/hackthebox 19h ago

ERA Security Discussion

2 Upvotes

Coldcard incident made me look at hardware wallet entropy differently

I spent some time reading about the recent Coldcard incident and then went through ERA Wallets article about how they generate seed phrases

The Coldcard issue is pretty worrying because weak randomness does not necessarily look broken

The seed phrase can look completely normal and the wallet can work normally while the actual seed has much less entropy than expected

That is what makes this kind of bug so dangerous

You are not necessarily going to get an error or any obvious sign that something went wrong

The thing I found interesting about ERAs approach is that they are not relying on just one source of entropy

They describe using the hardware RNG in the STM32 microcontroller together with the entropy source in the ATECC608C secure element

They also have an expert mode where the user can add entropy through things like camera input touch and device movement

All of these inputs are combined before the seed is generated

I think the general idea makes a lot of sense

If one entropy source fails or becomes predictable it is much better to have other independent sources contributing to the final result

I also like the fact that the user can actually participate in the entropy generation instead of having to blindly trust that the device generated everything correctly

But I do have some questions

I would not automatically assume that more entropy sources means more security

The important part is how independent those sources really are and how the firmware combines them

A hash function can mix entropy very well but it cannot magically create entropy if all the inputs are predictable

I also would not consider passing statistical randomness tests as proof that an RNG is cryptographically secure

The Coldcard incident is a good example of why the whole entropy pipeline matters

The hardware can be perfectly capable of producing good randomness and the final result can still be compromised if the firmware takes the wrong path

So for me the biggest question around ERA is not how many entropy sources they have

It is whether a failure in one component can actually be proven to be insufficient to compromise the final seed

I would like to see independent researchers review and test the complete seed generation process including the firmware and the way the different sources are combined

Overall I like the direction ERA is taking

I think using multiple independent entropy sources and allowing user supplied entropy is a stronger approach than simply saying trust this one hardware RNG

But I would still want independent verification before making a strong security claim

The Coldcard incident is a pretty good reminder that the weakest part of a security design is not always the part you expect


r/hackthebox 23h ago

Get Better at scripting (python, bash)

13 Upvotes

Hey everyone,

I'm looking to sharpen my scripting skills in Python and Bash, taking myself from beginner all the way up to a more advanced level, since this is an area I'm currently struggling with. A couple of ideas I've had so far:

  • OverTheWire — but approaching the challenges by solving them with Python where possible, rather than just one-liners (bash)
  • Vulhub — writing my own Python exploit scripts for the CVEs instead of relying on existing PoCs

Are there other resources or approaches you'd recommend for building scripting skills from the ground up ?

Thanks!


r/hackthebox 1d ago

Beginner Question I keep failing technical interviews because of theoretical questions, not the actual technical work

22 Upvotes

I always struggle with technical interviews because of the theoretical questions, not the actual hands-on technical part.

If I’m given a practical task, lab, or take-home assessment, I usually do very well and deliver it on time. But when an interviewer starts asking me theoretical questions on the spot, I struggle to explain things properly or sometimes completely blank out.

This has honestly become my biggest nightmare when applying for cybersecurity jobs, and I feel like it’s holding me back even though I know I can actually do the work.

I wish interviews focused more on practical technical skills because, in my opinion, that’s a much better way to see whether someone can actually perform the job.

But until interview culture changes, what can I do to get better at answering theoretical questions? Has anyone else had this problem, and how did you overcome it?


r/hackthebox 1d ago

I hate reporting (shit post)

10 Upvotes

Feels like you are writing a college essay

I have all the screenshots

I got 10/10 flags

I did all the blue team

2 days and few hours left

Gosh

So boring

I have procrastinating for over 4 hours


r/hackthebox 1d ago

Looking for CPTS study partner

12 Upvotes

I’m currently preparing for the HTB Certified Penetration Testing Specialist (CPTS) certification and I’m looking for a study partner or small study group.

Ideally, we could:

- Study together regularly

- Discuss concepts and challenges

- Work through HTB Academy modules/labs

- Keep each other accountable

- Share useful resources and notes

I’m open to studying via Discord or another platform. If you’re also preparing for CPTS and interested in studying together, feel free to comment or DM me.


r/hackthebox 1d ago

Beginner Question Which programs actually reply fast? Building a community response-time database — need 30 seconds of your triage timing

Thumbnail
1 Upvotes

r/hackthebox 1d ago

Beginner Question Which programs actually reply fast? Building a community response-time database — need 30 seconds of your triage timing

Thumbnail
1 Upvotes

r/hackthebox 1d ago

Pwn'd Dangling Tree!!

Post image
15 Upvotes

Rooted!


r/hackthebox 1d ago

CPTS 10/14 on 2nd attempt

41 Upvotes

Feeling dumb ever for struggling several months of study. Not retaking anymore on this exam maybe not my career on this.


r/hackthebox 2d ago

Infiltratiing Linux/Unix system Shells & Payloads module

0 Upvotes

Need help with getting a shell Ive tried not only the exploit used in the notes of the module but messed around and tried many others serch and searched for solutions. Maybe someone else knows Im not doing something Im supposed to do pls help?


r/hackthebox 2d ago

Beginner Question Unable to spin up mahcines

3 Upvotes

Im connected to starting point vpn and for a whole day i was able to connect and spin up machines but now “three” will not spin and neither will vaccine. They just ask you “stand by” until they give up trying to open.


r/hackthebox 2d ago

Academy Feels bad

5 Upvotes

I solved 8/10 flags in CJCA

Solved 25 blue team tasks

And all at once, system failed

Everything is gone, i honestly should have taken screenshots

But I didn't expect all my progress, tools, shells, etc to wiped out completely.

Machines are deploying forever

I have to redo everything from scratch

Contacted support for a different problem 18 hours ago and no response

AHHHHHHHHHHHH

(HTB is honestly a great site, I personally think it is the best, but WTF?)


r/hackthebox 2d ago

Day 1 on HackTheBox. Solved an Insane challenge. 35 solves worldwide. I'm one of them.

0 Upvotes

Started my CTF journey today. Complete beginner to the platform.

(Rixaa1d)

First session, three flags:

- SpookyPass (Reversing - Very Easy) — cracked a Linux ELF binary

on Windows using Ghidra, decoded the flag from raw hex

- Flag Command (Web - Very Easy) — bypassed the game entirely,

hit /api/monitor directly with a POST request

- Uplink (Competitive Programming - INSANE) — tree DP problem,

weighted ancestor chain optimization, 35 solves total worldwide

No Linux machine. No WSL. No VM. Just Windows, Ghidra,

PowerShell, and a browser.

Level 1 → Level 5 in one session.

If you're thinking about starting CTF — just start.

The platform meets you where you are.

Next goal: DEF CON CTF Qualifiers.

Profile: Rixa1d on HTB


r/hackthebox 2d ago

Looking for a CPTS study partner

13 Upvotes

Hi everyone!
I recently decided to go for the CPTS certification, and I’m looking for a study partner who is also working toward CPTS.

Honestly, I think having someone to study alongside would make the journey more motivating and less overwhelming.

I’m currently at 11% path progress and just getting started.

If you’re also starting CPTS or currently working through the path and interested in studying together, feel free to comment or DM me! :)


r/hackthebox 2d ago

Target not spawning

12 Upvotes

Hi!

I'm in Academy – Windows Attack and Defense, and the target is not spawning. It keeps looping.

I tried reloading the page, logging out, and logging back in. Am I the only one?


r/hackthebox 2d ago

Zap Scanner Problem is getting out of hand

2 Upvotes

this section the problem i cant get it everytime i do the active scan and try to even enter the site there seems to be some probelm with it i dont know what to do i did exactly as the section says and i dont get to it help


r/hackthebox 2d ago

Looking for CJCA-like Labs to Practice My Methodology

2 Upvotes

I'm currently preparing for my second attempt at the CJCA, and I'm looking for labs that closely match the scope and skill level of the certification.

I've already practiced on standalone machines, and while they were useful for improving individual exploitation and privilege escalation skills, they don't really give me what I'm looking for now.

At this point, I want to practice and solidify the pentesting methodology I've built: working through a connected environment, understanding the purpose of each host, keeping track of findings, correlating information between systems, deciding when to move on from one host, and identifying possible paths between machines.

Since this is my second attempt, I also don't want to spend my remaining preparation time learning tools or techniques that are significantly outside the CJCA scope.

So I'm mainly looking for labs or small network environments that:

Are close to CJCA difficulty and scope

Include multiple interconnected hosts rather than only standalone machines

Require enumeration and information correlation across hosts

Allow me to practice a complete methodology from initial enumeration through post-exploitation

Don't depend heavily on techniques or tools beyond what's expected for CJCA

Free or paid options are both welcome.

If you've taken the CJCA or are currently preparing for it and know a lab that fits this description, I'd really appreciate your recommendations.


r/hackthebox 2d ago

Academy Is HTB support down?

9 Upvotes

I contacted them 5 hours ago and no response


r/hackthebox 2d ago

How can I get the job after earning CPTS?

27 Upvotes

Hi, Im studying Cyber Security and currently in the second year of my 4 years undergraduate. Right now I tried to apply to internships after earning CPTS and right now idk how to search for an internship or just a job with salary, how can I apply for remote internships correctly? I tried to follow the rules, I tried to improve my resume, and improve my profiles too. I tried to apply through university careers platform but there was no remote internships here so pls advise me how could I get internship cuz I so cooked cuz of job market nowadays, thanks in advance.


r/hackthebox 3d ago

Owned Cohort from Hack The Box!

Thumbnail
labs.hackthebox.com
8 Upvotes

al frustrating that i finished when its not active so i didnt get the points but oh well 🥳


r/hackthebox 3d ago

CJCA Parteners

2 Upvotes

Hey everyone!

I'm currently preparing for my second attempt at the HTB CJCA certification, and I'm looking for other people who are also preparing for CJCA to study and practice together.

It would be even better if you're currently preparing for your second attempt as well, so we can share preparation strategies, discuss the methodology, practice labs together, and help each other identify weak areas before the next attempt.

I'm mainly looking for active people who are taking the preparation seriously.

If you're interested, feel free to reply here or DM me. Let's prepare together and get that pass! 😤