Heal
Heal
Heal 640
Heal
RETIRED MACHINE

Heal

Heal - Linux Linux
Heal - Medium Medium

4.5

MACHINE RATING

5230

USER OWNS

4976

SYSTEM OWNS

14/12/2024

RELEASED
Created by rajHere

Machine Synopsis

Heal is a medium-difficult Linux machine that features a website vulnerable to arbitrary file read, allowing us to extract sensitive credentials. The server also hosts a LimeSurvey instance, where the leaked credentials can be used to log in as an administrator. Since administrators can upload plugins, we can exploit this to upload a malicious plugin and gain a reverse shell as the `www-data` user. Further enumeration reveals the database password for LimeSurvey, which is reused by the system user `ron`, allowing us to escalate access. The server also runs a local instance of the Consul Agent as `root`. By registering a malicious service via the Consul API, we can escalate privileges and gain root access.

Machine Matrix

Ready to start your
hacking journey?