xsspresso
xsspresso
Tags/ Sudo

Sudo

15 writeups tagged with Sudo

WebMediumLinux

HTB — Facts

Cacti LFI via CVE-2024-46987 reads configuration files and credentials. Sudo abuse on a custom binary escalates to root.

#Cacti#LFI#CVE-2024-46987
Mar 8, 2026HackTheBox
WebMediumLinux

HTB — Imagery

ImageMagick policy bypass enables SSRF and local file read to steal credentials. Sudo misconfiguration grants root access.

#ImageMagick#SSRF#File Read
Oct 4, 2025HackTheBox
WebEasyLinux

VHL — Crash

GravCMS on Ubuntu. Unauthenticated scheduler RCE CVE allows arbitrary command execution as the web user, then sudo privesc.

#GravCMS#Scheduler RCE#CVE
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Techblog

WordPress 4.7.2 on CentOS. Exploited outdated plugin for remote code execution and escalated via sudo misconfiguration.

#WordPress#RCE#Sudo
Feb 8, 2025Virtual Hacking Labs
MiscEasyLinux

HTB — UnderPass

daloRADIUS web interface default credentials expose user hashes. Cracked MD5 hash for SSH. Mosh binary sudo privesc for root shell.

#daloRADIUS#Default Creds#MD5
Jan 8, 2025HackTheBox
WebEasyLinux

HTB — Knife

PHP 8.1.0-dev backdoor via User-Agentt header for RCE. Sudo knife binary used as a GTFOBin for instant root shell.

#PHP Backdoor#RCE#GTFOBins
Nov 25, 2024HackTheBox
WebEasyLinux

HTB — Sau

Maltrail 0.53 SSRF on a request-basket service. CVE-2023-27163 chained to unauthenticated OS command injection for initial access, sudo privesc.

#SSRF#Command Injection#CVE-2023-27163
Nov 19, 2024HackTheBox
WebMediumLinux

HTB — UpDown

Site availability checker with .htaccess allowlist bypass. PHP phar deserialization for code execution, proc_open for shell, developer sudo suid binary.

#PHAR Deserialization#LFI#Bypass
Nov 19, 2024HackTheBox
WebMediumLinux

HTB — Jarvis

SQL injection in hotel booking app. Sqlmap writes a PHP webshell. Sudo script with command injection, SUID systemctl for root.

#SQLi#Webshell#Sudo
Apr 30, 2022HackTheBox
WebEasyLinux

HTB — Swagshop

Magento 1.9 SQLi creates an admin account; Magento Froghopper achieves RCE. Sudo vim executes a shell as root.

#Magento#SQLi#RCE
Apr 13, 2022HackTheBox
WebMediumLinux

HTB — Tartarsauce

Gwolle Guestbook WordPress RFI via robots.txt discovery. Lateral move through sudo tar with --checkpoint shell execution.

#WordPress#RFI#Sudo
Apr 13, 2022HackTheBox
MiscEasyLinux

HTB — Sunday

Finger service enumerates valid usernames. Weak SSH credentials, troll binary, sudo wget for arbitrary file write to root.

#Finger#Weak Credentials#Sudo
Apr 11, 2022HackTheBox
WebEasyLinux

HTB — Nibbles

Nibbleblog CMS with guessable admin credentials leads to arbitrary PHP file upload and remote code execution.

#Nibbleblog#File Upload#RCE
Mar 25, 2022HackTheBox
WebEasyLinux

HTB — Bashed

phpbash webshell discovered via directory fuzzing. Lateral movement through sudo scriptmanager, cron-based root.

#Webshell#Fuzzing#Cron
Mar 24, 2022HackTheBox
WebEasyLinux

HTB — Shocker

Shellshock (CVE-2014-6271) via a CGI endpoint found with gobuster. Sudo perl for a trivial privilege escalation.

#Shellshock#CGI#Sudo
Mar 23, 2022HackTheBox