@privesc said:
Hi @TazWake in the context of another HTB user compromising your box. From the HTB page “Use it responsibly and don’t hack your fellow members…”. and this How to be safe on HTB - Off-topic - Hack The Box :: Forums
Ok. In a very simplistic sense “safe” is only something you can assess.
Really, rather than use the vague sense of “safe” (because nothing on HTB will hurt you, ever), you need to think more about what it is you are concerned may happen.
Then you can establish if there is a risk from what you are doing, and if so, decide if it is worth mitigating.
The “Use it responsibility” comment is largely boilerplate and a way of establishing a behaviour standard (which can be enforced), rather than warning you there is a risk of people finding your IP and trying to hack into your machine.
I don’t know enough about the new service to make that determination.
If you identify what you think might be a problem, it might be possible to work out if there is an issue for you or not. The general “am I safe doing this” is difficult to ever answer and someone will always come up with a counter argument to anything you decide.
For further context, I use a Kali VM because of the tools but to also isolate my host while doing HTB.
Ok. If your concern is someone hacking into your Pwnbox OS and then breaking out of the browser it’s running in to attack your host machine, this is probably unlikely but not impossible.
In the same vein, it is unlikely - but not impossible - that someone can hack into your Kali VM and break out of the virtualisation to attack the host.
Largely it boils down to what services you run, how you configure it, how you access it, what you use it for, what credentials you use etc. It is probably the same with the PwnBox machines.