Cap attack path and techniques
Cap is a easy Linux machine on Hack The Box that I solved myself. This page is my short attack path summary and the techniques it trains.
| Platform | Hack The Box |
|---|---|
| Operating system | Linux |
| Difficulty | Easy |
| Time to user | 25m |
| Time to root | 1h 0m |
| User owned | 2026-08-20 |
| Root owned | 2026-08-20 |
Attack path summary
Cap is an easy difficulty Linux machine running an HTTP server thus allowing users to capture the non- enrypted traffic. Improper controls result in Insecure Direct Object Reference (IDOR) giving access to another user's capture.
Techniques
HTB IDOR
Related solved machines
Other machines I solved that share techniques with Cap.
- Bank (HTB Linux Easy)
- Bashed (HTB Linux Easy)
- Beep (HTB Linux Easy)
- Blocky (HTB Linux Easy)
- Knife (HTB Linux Easy)
- Lame (HTB Linux Easy)
Track Cap in ZeroBox. Log your progress, notes and flags offline in your browser, and follow the pentest methodology checklist.
Cap belongs to Hack The Box. This page contains only my own notes.