~ / writeups / orion

Orion

Hack The Box · Easy · Linux

Easy Linux User + Root owned

Machine Overview

Field Value
Name Orion
Difficulty Easy
OS Linux (Ubuntu 22.04, nginx 1.18.0)
IP 10.129.146.187
Vhost orion.htb
Key components Craft CMS 5.6.16 (Yii 2.0.51), MariaDB 10.6, GNU inetutils telnetd
Open ports 22 (SSH OpenSSH 8.9p1), 80 (nginx)

Flags

Flag Path Value
User /home/adam/user.txt [REDACTED]
Root /root/root.txt [REDACTED]

Attack Chain

1. Reconnaissance

2. Initial Access — CVE-2025-32432 (Craft CMS pre-auth RCE)

3. Credential Recovery

4. Password Reuse → User Flag

5. Privilege Escalation — telnetd Auth Bypass (CVE-2026-24061)

USER="-f root" telnet -a localhost
# root@orion:~# cat /root/root.txt

Techniques Demonstrated

  1. Craft CMS version fingerprinting (X-Powered-By, admin footer)
  2. Pre-auth object-injection RCE (CVE-2025-32432 / Yii2 __class precedence)
  3. PHP session poisoning (return-URL side-channel) + PhpManager gadget file inclusion
  4. Raw-URL payload delivery (space-free <?=...?> to bypass HTTP client encoding)
  5. .env database credential disclosure
  6. bcrypt hash extraction + cracking (password darkangel)
  7. Credential reuse (DB user → system user adam)
  8. telnetd authentication bypass (CVE-2026-24061, -f root USER injection)

Tools Used

nmap, curl, Python 3 (requests/paramiko/bcrypt), custom CVE-2025-32432 exploit, mysql (target), telnet (target).

← all writeups