Busqueda Writeup - HackTheBox

Busqueda is an easy Linux machine involving command injection in a Python module for initial access. Privilege escalation is achieved by abusing a root-executable system checkup script with a relative path vulnerability, discovered via Gitea creds and repo analysis.

October 26, 2024 · 6 min · 1087 words · Me

BoardLight Writeup - HackTheBox

BoardLight is an easy Linux machine exploiting Dolibarr CVE-2023-30253 to gain www-data, then SSH access via plaintext creds. Privilege escalation is achieved through a vulnerable SUID Enlightenment binary (CVE-2022-37706) for root access.

October 10, 2024 · 6 min · 1269 words · Me

Editorial Writeup - HackTheBox

Editorial is an easy Linux machine using an SSRF vulnerability to access an internal API and retrieve SSH credentials. Further Git enumeration reveals more creds, with root access gained via CVE-2022-24439 and misconfigured sudo permissions.

October 9, 2024 · 5 min · 961 words · Me

Mailing Writeup - HackTheBox

Mailing is an easy Windows machine using path traversal to access hMailServer configs and crack the admin email password. Access to user maya is gained via CVE-2024-21413 to capture and crack NTLM, with root obtained by exploiting LibreOffice CVE-2023-2255.

September 12, 2024 · 8 min · 1672 words · Me