<- HTB

Vessel


15 minutes to read

Vessel
Hack The Box. Linux. Hard machine. This machine has a website that exposes a Git repository. Here we can read the source code of the web application and find out a way to bypass authentication in MySQL with Type Juggling. Then, we find another subdomain that has a public exploit to get RCE. After that, we discover a password generator tool that can be reverse-engineered to generate multiple passwords and crack a password-protected PDF document. Then, we get access via SSH and see that we can use sysctl as root with pinns as SUID binary. With this, we can modify the kernel configuration to run an arbitrary script with a program crashes, which leads to the privilege escalation