// htb writeup HackTheBox 2026-05-24
PingPong
HackTheBox Insane HackTheBox
seasonal
root obtained // PWNED

🏓 PingPong

Difficulty: Insane OS: Windows Release: HTB Season 10

A two-forest Active Directory box that lives up to the Insane rating. The core mechanic is a bidirectional trust between PING.HTB and PONG.HTB — every major step involves crossing or exploiting that trust. You’ll touch ESC13, JEA jail-breaking, cross-domain gMSA abuse, RBCD to MSSQL, GodPotato, DCSync, and finally ESC4 into ESC1 to close the forest loop. A lot of distinct techniques stacked end to end — none of the individual steps are especially obscure, but you need all of them.


📸 Proof


🧠 Concepts Covered


💡 Hints (No Spoilers)

Foothold

User (PING → PONG)

Root (PONG → PING)


📚 Useful Reading