Pennyworth attack path and techniques
Pennyworth is a very easy Linux machine on Hack The Box that I solved myself. This page is my short attack path summary and the techniques it trains.
| Platform | Hack The Box |
|---|---|
| Operating system | Linux |
| Difficulty | Very Easy |
| Time to user | 25m |
| Time to root | 1h 0m |
| User owned | 2026-08-20 |
| Root owned | 2026-08-20 |
| Relevant for | HTB-Starting-Point |
Attack path summary
Log into Jenkins on port 8080 with root:password, open Script Console at /script, and execute Groovy reverse shell.
Techniques
Jenkins Groovy RCE Default Credentials
Related solved machines
Other machines I solved that share techniques with Pennyworth.
- Meow (HTB Linux Very Easy)
- Sequel (HTB Linux Very Easy)
- Agent T (THM Linux Easy)
- Explosion (HTB Windows Very Easy)
- Vulnerability Capstone (THM Linux Easy)
Track Pennyworth in ZeroBox. Log your progress, notes and flags offline in your browser, and follow the pentest methodology checklist.
Pennyworth belongs to Hack The Box. This page contains only my own notes.