HTB CDSA
Certified Defensive Security Analyst by Academy. Get started now!
Machine Synopsis
AI is a medium difficulty Linux machine running a speech recognition service on Apache. This service is found to be vulnerable to SQL injection and is exploited with audio files. The injection is leveraged to gain SSH credentials for a user. Enumeration of running processes yields a Tomcat application running on localhost, which has debugging enabled. This port is forwarded and exploited to gain code execution as root.
Machine Matrix