Unified
Unified
Unified 441
Unified
RETIRED MACHINE

Unified

Unified - Linux Linux
Unified - Very Easy Very Easy

4.3

MACHINE RATING

44659

USER OWNS

44554

SYSTEM OWNS

02/02/2022

RELEASED
Created by ch4p

Machine Synopsis

Unified is a very easy Linux machine that demonstrates the exploitation of the Log4Shell (CVE-2021-44228) vulnerability in the UniFi Network application. Enumeration reveals a vulnerable UniFi instance where a remote execution can be achieved by crafting and injecting a JNDI payload into a POST request. Then a local MongoDB database can be leveraged to reset the administrator password and gain access to the UniFi admin panel. Plaintext SSH credentials can be discovered in the application settings leading to final privilege escalation.

Machine Matrix

Ready to start your
hacking journey?