{"id":1936,"date":"2025-10-24T16:08:39","date_gmt":"2025-10-24T20:08:39","guid":{"rendered":"https:\/\/www.peteonsoftware.com\/?p=1936"},"modified":"2025-10-24T16:08:39","modified_gmt":"2025-10-24T20:08:39","slug":"hack-the-box-walkthrough-the-puppet-master","status":"publish","type":"post","link":"https:\/\/www.peteonsoftware.com\/index.php\/2025\/10\/24\/hack-the-box-walkthrough-the-puppet-master\/","title":{"rendered":"Hack the Box Walkthrough: The Puppet Master"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/peteonsoftware.com\/images\/2025\/puppetmaster_icon.png\" alt=\"An image representing a generic puppet master\" title=\"An image representing a generic puppet master\" style=\"float:left;margin:.5rem;\">This time, we&#8217;re going to be back in a Hack the Box challenge called <a href=\"https:\/\/app.hackthebox.com\/challenges\/The%2520Puppet%2520Master\">The Puppet Master<\/a>.  Its description is &#8220;An anonymous source has shared a photograph of an unidentified military armored vehicle during field operations. Your mission is to conduct a comprehensive OSINT analysis to identify this vehicle and its specifications.&#8221;<\/p>\n<p>The first thing you have to do is click &#8220;Start Instance&#8221; on the HTB page for this challenge.  It will spin up a container and you&#8217;ll get an IP and Port to connect to.  When you get there, you will get a website with these pages.<\/p>\n<p>First, we come to the Dashboard page.  This explains the Scenario, the Objective, and some information about OSINT Investigation as a whole.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/peteonsoftware.com\/images\/2025\/puppetmaster_homepage.png\" alt=\"The Pupppet Master Dashboard Page\" title=\"The Pupppet Master Dashboard Page\"><\/p>\n<p>Next, we come to the Evidence page.  This has the image for us to investigate and some initial observations about that image.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/peteonsoftware.com\/images\/2025\/puppetmaster_evidence.png\" alt=\"The Pupppet Master Evidence Page\" title=\"The Pupppet Master Evidence Page\"><\/p>\n<p>Lastly, we have the Challenge page.  This is the page with the list of questions that we will need to answer.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/peteonsoftware.com\/images\/2025\/puppetmaster_challenge.png\" alt=\"The Pupppet Master Challenge Page\" title=\"The Pupppet Master Challenge Page\"><\/p>\n<p>Now that we&#8217;ve got the lay of the land, let&#8217;s tackle the questions.<\/p>\n<p><strong>Q1. What type of military vehicle is shown in the image? Look at the vehicle&#8217;s characteristics: it&#8217;s wheeled, armored, and appears to be a personnel carrier. Research similar vehicles online.<\/strong><\/p>\n<p>I went to tineye.com and uploaded the image.  I purposely didn&#8217;t select any pages that looked like they were related to solving this challenge.  I went to this blog: <a href=\"https:\/\/defense-studies.blogspot.com\/2023\/05\/\">https:\/\/defense-studies.blogspot.com\/2023\/05\/<\/a> and found an article mentioning that 18 Bushmaster PMVs were delivered to the New Zealand Army.<\/p>\n<p><em><strong>A1. Bushmaster<\/strong><\/em><\/p>\n<p><strong>Q2. Who is the manufacturer\/designer of this vehicle? Research the company that designed and produces this specific armored vehicle.<\/strong><\/p>\n<p>I googled it and was pointed to the Wikipedia article for it and got the answer <a href=\"https:\/\/en.wikipedia.org\/wiki\/Bushmaster_Protected_Mobility_Vehicle\">https:\/\/en.wikipedia.org\/wiki\/Bushmaster_Protected_Mobility_Vehicle<\/a><\/p>\n<p><em><strong>A2. Thales Australia<\/strong><\/em><\/p>\n<p><strong>Q3. When did this vehicle first enter military service? Research the year this specific vehicle type was first deployed operationally.<\/strong><\/p>\n<p>Same wikipedia page<\/p>\n<p><em><strong>A3.1997<\/strong><\/em><\/p>\n<p><strong>Q4. What is the country of origin for this vehicle? Research where this specific vehicle was originally designed and manufactured.<\/strong><\/p>\n<p>Same page, though the name of the manufacturer is also a bit of a giveaway<\/p>\n<p><em><strong>A4. Australia<\/strong><\/em><\/p>\n<p><strong>Q5. What is the passenger capacity of this vehicle? Research how many passengers plus crew it can carry (format: X passengers and Y driver).<\/strong><\/p>\n<p>Wikipedia page again.<\/p>\n<p><em><strong>A5. 9 passengers and 1 driver<\/strong><\/em><\/p>\n<p>After you finish that last question, you submit for final analysis and get the flag to submit back at the Hack the Box Challenge page.  That&#8217;s it.  Very Easy as the chaps promised.  The biggest trick here was knowing how to use TinEye or Google Reverse Image Search and then to investigate from there.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/peteonsoftware.com\/images\/2025\/puppetmaster_pwned.png\" alt=\"The Puppetmaster Pwned\" title=\"The Puppetmaster Pwned\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This time, we&#8217;re going to be back in a Hack the Box challenge called The Puppet Master. Its description is &#8220;An anonymous source has shared a photograph of an unidentified military armored vehicle during field &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[153],"tags":[141,142,158],"class_list":["post-1936","post","type-post","status-publish","format-standard","hentry","category-capture-the-flag","tag-information-security","tag-infosec","tag-osint"],"_links":{"self":[{"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/posts\/1936","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/comments?post=1936"}],"version-history":[{"count":0,"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/posts\/1936\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/media?parent=1936"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/categories?post=1936"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.peteonsoftware.com\/index.php\/wp-json\/wp\/v2\/tags?post=1936"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}