Sink
Sink
Sink 313
Sink
RETIRED MACHINE

Sink

Sink - Linux Linux
Sink - Insane Insane

4.9

MACHINE RATING

1643

USER OWNS

1560

SYSTEM OWNS

30/01/2021

RELEASED
Created by MrR3boot

Machine Synopsis

Sink is an insane Linux machine that features an application which is vulnerable to HTTP Desync attack. Exploiting this vulnerability gives access to a high privileged user on the application. This privilege gives access to Gitea service. Enumeration of repositories lead to a private key leak which can be used to gain a foothold on system. Enumerating SecretsManager service reveals credentials which assists in moving laterally. System access can be obtained by decrypting a file using the KMS service.

Machine Matrix

Ready to start your
hacking journey?