Hack The Box: Traverxec
Synopsis: Traverxec is a Linux machine running a nostromo web server. A quick google or searchsploit tells us that version 1.9.6 is vulnerable to a RCE vulnerability that has a metasploit module. Using metasploit allows us a foothold on the system as the www-data user. To elevate privileges a backup file for the user David can be found in the /home/david/public_www/protected-file-area directory. After using netcat to move the file back to kali to work with it we can use John to decrypt the file and locate david’s password. This allows us to ssh as david to the machine and grab his flag. From here we perform a shell escape sequence on journalctl with the aid of gtfobins giving us root access and the ability to grab the root flag.