Chemistry
Chemistry
Chemistry 631
Chemistry
RETIRED MACHINE

Chemistry

Chemistry - Linux Linux
Chemistry - Easy Easy

4.4

MACHINE RATING

15519

USER OWNS

14310

SYSTEM OWNS

19/10/2024

RELEASED
Created by FisMatHack

Machine Synopsis

Chemistry is an easy-difficulty Linux machine that showcases a Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious `CIF` file to the hosted `CIF Analyzer` website on the target. After discovering and cracking hashes, we authenticate to the target via SSH as `rosa` user. For privilege escalation, we exploit a Path Traversal vulnerability that leads to an Arbitrary File Read in a Python library called `AioHTTP` (CVE-2024-23334) which is used on the web application running internally to read the root flag.

Machine Matrix

Ready to start your
hacking journey?