Academy - HackTheBox Writeup (10.10.10.215)

Posted on Wed, Mar 3, 2021 Easy Linux Web Application Laravel Composer
Easy-difficulty Linux box about exploiting Laravel CVE-2018-15133 and privilege escalation with Composer.

Recon

Enumeration

HTTP Enumeration

Exploitation

Privilege Escalation

Persistence

Resources

  1. https://nvd.nist.gov/vuln/detail/CVE-2018-15133
  2. https://nvd.nist.gov/vuln/detail/CVE-2017-16894
  3. https://serverfault.com/questions/485473/what-is-the-canonical-use-for-the-sys-and-adm-groups
  4. https://getcomposer.org/doc/articles/scripts.md
  5. https://gtfobins.github.io/gtfobins/composer/