Live data from Hacker News

Hack the Box – Pentesting Labs for Free

hackthebox.eu

41–47 of 47 posts

Re: Hack the Box – Pentesting Labs for Free

#41
post #38

I dont get it. Why not put a pc on your lan and try to hack that? What is the benefit to me here? How do i know that the 'labs' i am participating in are safe? Are they honeypots? or perhaps i am just being used in a covert plan to crowdsource an attack on a vic?

Yeah you dont get it. Have you even read the website? Like...why are you jumping onto the fear bandwagon before understanding what hackthebox is about. When you turn on you fill your car with gas do you worry about an oil tanker spill?

Re: Hack the Box – Pentesting Labs for Free

#42

Earlier quoted context omitted.

I've been trying to learn infosec for a few years now with the eventual goal of either an offense/defense role. Plan to work on my OSCP next. I have a few basic questions please: 1. Aside from: linux cmds, nmap, metasploit, sqlmap, mimikatz, kali's well known tools - what other tools are often used by pen testers ? 2. How is MFA beaten in today's enterprises ? 3. Do most engagements assume one is already in the netwo…

I've replied to your thread level comment, but please do feel free to reach out to me if you want any advice or discussion: i@willcode.it

Foremost, I'd also like to say thank you for providing such a detailed reply to the top level comment

But I also wanted to extend my admiration of that very crafty email address. I'm sorry I didn't think of it first

Re: Hack the Box – Pentesting Labs for Free

#43

Asking the Hive Mind who might play with HTB, vulnhub and other labs (OSCP paid one): 1. Aside from: linux cmds, nmap, metasploit, sqlmap, mimikatz, kali's well known tools - what other tools are often used by pen testers ? 2. How is MFA beaten in today's enterprises ? 3. Do most engagements assume one is already in the network ? If not, how does one scan (basic OSINT towards their externally facing website, but let'…

>>1. Aside from: linux cmds, nmap, metasploit, sqlmap, mimikatz, kali's well known tools - what other tools are often used by pen testers ? I think those + your typical scanners (Nessus, Nexpose, etc). One gap I know of, is proper organizational tooling. I.e how do store your results / reports / findings in an effective manner to be consumed downstream via other tooling. For us, it was a big uplift to standardize how…

This is an amazing reply I am going to read a few times! Will hit you up on your e-mail!

Re: Hack the Box – Pentesting Labs for Free

#46
post #37
post #33

JFYI: There's a rule on HN that "Show HN's" can't just be sign-up pages or require invite codes; people have to be able to actually interact with whatever you're "Showing".

I mean you're kinda supposed to hack your way into getting an invite code...

True. The invite code is a first hacking test. There is this message in the web: "Feel free to hack your way in :)".

No invitation needed, it's just the first puzzle.

Re: Hack the Box – Pentesting Labs for Free

#47
post #14

For those that have been using the service and have actual pentesting experience, how applicable are the challenges to the real world? Similar challenges I took in the past seemed like fun games, but still games.

I must say it presents many scenarios that are easily found "into the wild". Google and Shodan finds tons of vulnerable machines that match some HTB scenarios.
Post reply on HN