HTB Stream Writeup | Airport Infrastructure to Root
Hack The Box Stream overview: investigate exposed airport services, follow a data pipeline to initial access, and trace a scheduled operations task to root.
Due to Hack The Box policies this walkthrough is not publicly served until Stream retires. See the official HTB writeup guidelines.
Machine profile
- Platform
- Hack The Box
- Machine
- Stream
- Difficulty
- Medium
- Published
- Status
- active
Stream is a medium-difficulty Linux machine from Hack The Box, set in an airport's interconnected service environment. The path through the box rewards careful enumeration across web services, databases and the data pipeline joining them.
The techniques include investigating an exposed application diagnostic endpoint, tracing credentials through service data, exploiting unsafe XML processing for local file disclosure, and following a scheduled background task to understand the final privilege escalation. Each discovery provides context for the next part of the chain.
Stream is a good fit for readers comfortable with Linux enumeration who want practice connecting findings across multiple services. The full walkthrough is available to the owner while the machine is active.
What this machine covers
Software, services & tooling
Techniques & attack classes
What the finished writeup contains
When Stream retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.
- Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
- Initial foothold The first authenticated or unauthenticated execution path
- Enumeration Deeper inspection of the exposed services and their configuration
- Exploitation Chaining the weaknesses found into a working exploit
- Credential recovery Secrets, keys and hashes, and how they were obtained
- Privilege escalation The route from the foothold account to a root shell
- Flags User and root flag capture
19 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.
Why is this walkthrough protected right now?
No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.
Topics: Medium Difficulty, ClickHouse, Java Heap Dump, XXE, Kafka, Credential Discovery, Linux Privilege Escalation, Rustscan, Nmap
Comments
No comments yet — be the first to share your thoughts.