# CBBH

\
![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2FzGXF5RNI9UGMginNtbIi%2Fimage.png?alt=media\&token=d48bde3e-08b1-4c8e-a194-9b0bc1b7e8da)

![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2FbLfHIJCVWJbkCOFzDuv7%2Fimage.png?alt=media\&token=3da3b28e-e0e6-485f-868d-0586bf3ed313)

Cost = 1410 cubes

**Exam:**

attack multiple websites \
write report + submit\
10 flags = 100 points\
85/100 to pass (so +- 8 or 9 flags)\
admin access or RCE<br>

1. Multiple ways to get in, don't stay stuck for too long
2. use HTB's Academy's search feature
3. schedule a start time which gives you plenty on uninterrupted time
4. Take screenshots and write down as you go to save time on report writing

<br>

## Preparing for CBBH the exam <a href="#a161" id="a161"></a>

After completing the training path, it’s essential to practice and apply one's knowledge on real-world scenarios. One of the best ways to do this is by utilizing HTB's Academy X HTB labs feature, which offers a wide range of labs to test your skills. One cal also take on web security challenges from PortSwigger’s Web Academy to further hone your skills and solidify your understanding of web security concepts. \
\
Challenges which might be super helpful:

1. OWASP-top 10 track on Hackthebox <https://app.hackthebox.com/tracks/OWASP-Top-10>
2. Akvera fortress from hackthebox <https://app.hackthebox.com/fortresses/2>
3. Look also at boxes like

&#x20;[BountyHunter](https://app.hackthebox.com/machines/BountyHunter) - **done**

&#x20;[Horizontall](https://app.hackthebox.com/machines/Horizontall) - **done** to user

![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2F9j0iV7a2gjWzcA9GyysM%2Fimage.png?alt=media\&token=6c9c353c-6938-41fb-9684-45565f2a5726)

&#x20;[Academy](https://app.hackthebox.com/machines/Academy) - **done**

&#x20;[Meta](https://app.hackthebox.com/machines/Meta)&#x20;

&#x20;[Forge](https://app.hackthebox.com/machines/Forge) - **done user flag**

[Nineveh](https://app.hackthebox.com/machines/54) - **done**

more machines metioned:\
backdoor - WP\
apocalyst - WP\
tenet - WP\
~~Steamcloud~~\
~~Ransom~~\ <br>

1. Have a look at the labs on [portswigger](https://portswigger.net/web-security/all-labs) web academy.

HTML Character encoding\
<https://www.w3schools.com/tags/ref_urlencode.ASP>

![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2FOh9Vkt5SYZ6o8bzWyFqW%2Fimage.png?alt=media\&token=5ee3c1af-5192-47b9-8e01-448bbf79c81e)

![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2FI4i1xsMhbwZTDBeljqhQ%2Fimage.png?alt=media\&token=0d49cda2-ee79-4087-8126-509a886e4695)

![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2FmjasyRXAoNrMOcz2JLfl%2Fimage.png?alt=media\&token=725002ac-c42a-4af0-9ae1-e47183f903fc)

![](https://410895813-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MlKjYaxo0rpR2Jsapi3%2Fuploads%2F3o9mrH4r1VNen8vQuiZp%2Fimage.png?alt=media\&token=1ea91a8b-9570-404b-a149-fdb1a04048db)
