Hey, we’re Web Hackery. See our thoughts, stories and ideas.

See what we’ve
written lately
Chinmay Patel
Meet our author Meet our authors Meet our top authors

HackTheBox: Blocky

Blocky is a simple, real-world–based machine highlighting weak passwords and exposed internal files on public systems. It also shows Minecraft as a large attack surface, with many public servers run by inexperienced administrators.

HackTheBox: Celestial

Celestial is a medium difficulty machine which focuses on deserialization exploits. It is not the most realistic, however it provides a practical example of abusing client-size serialized objects in NodeJS framework.

HackTheBox: Popcorn

Popcorn, while not overly complicated, contains quite a bit of content and it can be difficult for some users to locate the proper attack vector at first. This machine mainly focuses on different methods of web exploitation.

You’ve successfully subscribed to Web Hackery
Welcome back! You’ve successfully signed in.
Great! You’ve successfully signed up.
Success! Your email is updated.
Your link has expired
Success! Check your email for magic link to sign-in.