Discussion — Any questions? Ask and discuss freely in the community.
Hack The Box active 172 views

HTB Paperwork Writeup

Hack The Box Paperwork machine overview: LPD command injection, PJL path traversal and file descriptor hijacking with SCM_RIGHTS. Full steps after retirement.

Paperwork
Easy active Hack The Box
Paperwork completion
Protected while the machine is active

Due to Hack The Box policies this walkthrough is not publicly served until Paperwork retires. See the official HTB writeup guidelines.

Machine profile

Platform
Hack The Box
Machine
Paperwork
Difficulty
Easy
Published
Status
active

Paperwork is an easy-difficulty Linux machine from Hack The Box built entirely around printing, and it is unusual in that the whole chain lives in protocols most people have never examined closely.

The skill areas are network printing services, printer command languages, file path handling in print workflows, and Unix inter-process communication — specifically how a privileged process can be handed a file descriptor it should not have access to. There is no web application and no web shell anywhere in the box.

Paperwork is a good pick for anyone who wants to understand how Unix IPC and file descriptor passing work in practice rather than in the abstract, and it makes a deliberate change of pace from the web-focused machines here. The techniques are all real-world service misconfigurations rather than kernel exploits, which makes the box both approachable and directly applicable to assessment work.

What this machine covers

Software, services & tooling

LPD Command Injection PJL Injection PJL Path Traversal CUPS Rustscan Nmap

Techniques & attack classes

Printer Exploitation SCM_RIGHTS File Descriptor Hijacking Lateral Movement Linux Privilege Escalation

What the finished writeup contains

When Paperwork retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.

  1. Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
  2. Initial foothold The first authenticated or unauthenticated execution path
  3. Enumeration Deeper inspection of the exposed services and their configuration
  4. Exploitation Chaining the weaknesses found into a working exploit
  5. Credential recovery Secrets, keys and hashes, and how they were obtained
  6. Privilege escalation The route from the foothold account to a root shell
  7. Flags User and root flag capture

172 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.

Why is this walkthrough protected right now?

No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.

Topics: LPD Command Injection, Printer Exploitation, PJL Injection, PJL Path Traversal, SCM_RIGHTS, File Descriptor Hijacking, CUPS, Lateral Movement, Linux Privilege Escalation, Rustscan, Nmap

Comments