HTB CDSA
Certified Defensive Security Analyst by Academy. Get started now!
Machine Synopsis
Traceback is an easy difficulty machine that features an Apache web server. A PHP web shell uploaded by a hacker is accessible and can be used to gain command execution in the context of the `webadmin` user. This user has the privilege to run a tool called `luvit`, which executes Lua code as the `sysadmin` user. Finally, the Sysadmin user has write permissions to the `update-motd` file. This file is run as root every time someone connects to the machine through SSH. This is used to escalate privileges to root.
Machine Matrix