Hack The Box: Silentium Machine Walkthrough β Easy Difficulity
Completed another Hack The Box machine, Silentium.
Initial access was achieved by exploiting a password-reset vulnerability in the staging Flowise application, followed by abusing a custom MCP endpoint to obtain a root shell inside the Flowise container. Credentials exposed through the container environment were then used to SSH into the underlying host as ben and retrieve the flag.
For privilege escalation, an internal Gogs instance was discovered through local port forwarding. A malicious symlink was pushed and manipulated through the Gogs API to target /etc/sudoers.d/ben, allowing a passwordless sudo rule to be written and ultimately providing full root access.
#HackTheBox #HTB #CyberSecurity #PenetrationTesting #OffensiveSecurity #Linux #PrivilegeEscalation #WebSecurity #CTF β¦
Learn MoreHack The Box: Silentium Machine Walkthrough β Easy Difficulity
The post Hack The Box: Silentium Machine Walkthrough β Easy Difficulity appeared first on Threatninja.net.