HackTheBox: Sea
Sea is an easy Linux machine: a WonderCMS XSS (CVE-2023-41425) hijacks the admin session and leads to RCE via a malicious theme, a Blowfish hash gives SSH access, and a log-reading LFI with command injection gives root.
Sea is an easy Linux machine: a WonderCMS XSS (CVE-2023-41425) hijacks the admin session and leads to RCE via a malicious theme, a Blowfish hash gives SSH access, and a log-reading LFI with command injection gives root.
Curling is an easy Linux machine: a Joomla site leads to admin access and RCE through a template webshell, a hexdump reveals SSH credentials, and PwnKit (CVE-2021-4034) gives root.
OpenAdmin is an easy Linux machine: an outdated OpenNetAdmin panel gives RCE, credential reuse and a hidden internal service lead to an SSH key, and a sudo nano misconfig gives root via GTFOBins.
Heist is an easy Windows machine: a leaked Cisco config exposes crackable password hashes, a password spray gets a foothold, and dumping Firefox from memory with Procdump reveals the admin credentials.
Jab is a medium Windows AD machine: Kerbrute user enumeration and AS-REP Roasting give a foothold, an Openfire XMPP chat room leaks credentials, and CVE-2023-32315 on the Openfire console leads to SYSTEM.
Codify is an easy Linux machine: a vm2 sandbox escape gives RCE, a SQLite database yields a crackable hash, and a bash pattern-matching pitfall in a sudo script (with pspy) reveals the root password.