HTB CDSA
Certified Defensive Security Analyst by Academy. Get started now!
Machine Synopsis
Quick is a hard difficulty Linux machine that features a website running on the HTTP/3 protocol. Enumeration of the website reveals default credentials. The client portal is found to be vulnerable to ESI (Edge Side Includes) injection. This is used to obtain code execution and gain a foothold. A weak password gives access to a printer console, which permits the addition of new printers. Weak file permissions are exploited to move laterally. Plaintext credentials exposed in a configuration are reused to escalate to root.
Machine Matrix