Security Researcher Roots HTB 'Layover' Machine via Multi-Stage Attack Chain

Security researcher Badathala Jaisurya successfully compromised the 'Layover' machine on Hack The Box using a multi-stage attack chain. The process began with RDP access using default contractor credentials, which revealed an internal wireless network reachable only from the compromised Windows host. Analysing wireless traffic from that foothold yielded a second set of credentials, granting access to an internal portal running Craft CMS version 5.9.8. Authenticated exploitation of the CMS led to remote code execution on an underlying Linux server, followed by credential discovery that enabled SSH access as user 'aporter'. Privilege escalation was then pursued through the CUPS service to ultimately achieve root access on the machine.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in