Odyssey
Odyssey
Odyssey 954
Odyssey
RETIRED MACHINE

Odyssey

Odyssey - Windows Windows
Odyssey - Insane Insane

4.9

MACHINE RATING

212

USER OWNS

207

SYSTEM OWNS

23/06/2026

RELEASED
Created by xRogue

Machine Synopsis

`Odyssey` is an Insane Windows machine that starts with a web application gated behind `WebAuthn` authentication. An endpoint vulnerable to `NoSQL Pipeline Aggregation Injection` provides access to unclaimed onboarding tokens, which can then be used to register a custom-made authenticator to log in to the application. A `userHandle` confusion vulnerability provides admin access to the application. Administrators have access to a template drafting and render preview panel, where a `merge` sink allows `prototype pollution`. Polluting the `allowRawBlocks` prototype enables raw LaTeX blocks to be passed through pandoc, which allows local file contents to be retrieved via special LaTeX primitives that escape catcode encoding. Then, an endpoint vulnerable to CVE-2025-1302 is identified in the application's source code, which provides access to the Linux web server as `webadmin`. Password reuse grants privileged access to the Linux server via `webadmin's` `sudo` group membership. `bulkadmin` privileges on an MSSQL account enable coercion via the BULK INSERT statement. The retrieved NTLMv2 hash can be cracked, providing access to the `MSSQL` server as a sysadmin. Then, enabling `xp_cmdshell` allows command execution on `Odyssey-DB`, where the `SeImpersonatePrivilege` privilege of the account enables privilege escalation. Through local hive extraction, the machine account of `Odyssey-DB` is retrieved, which has `addKeyCredentialLink` rights on `svc-aegis-build` through multiple group membership inheritance. Next, a `dMSA Ouroboros` attack chain provides access to the `svc-aegis-deploy` user, who can access the domain controller via `WinRM`. Finally, a `.NET` pipe application is exploited through unsafe `YAML` deserialization and weak credential management.

Machine Matrix

Ready to start your
hacking journey?