<- HTB

Facts


7 minutes to read

Facts
Hack The Box. Linux. Easy machine. This machine has an outdated version of Camaleon CMS that is vulnerable to Local File Read. With this vulnerability we can read the private SSH key of a user, crack the passphrase and access the machine. Then, this user has sudo permissions to run command facter as root, which can be used to escalate privileges using a Ruby script