EvilCUPS
EvilCUPS
EvilCUPS 629
EvilCUPS
RETIRED MACHINE

EvilCUPS

EvilCUPS - Linux Linux
EvilCUPS - Medium Medium

4.8

MACHINE RATING

579

USER OWNS

548

SYSTEM OWNS

02/10/2024

RELEASED
Created by ippsec

Machine Synopsis

EvilCUPS is a Medium difficulty Linux machine that features a CUPS Command Injection Vulnerability [CVE-2024-47176](https://nvd.nist.gov/vuln/detail/CVE-2024-47176). This CVE allows remote unauthenticated users the ability to install a malicious printer on the vulnerable machine over `UDP/631`. This printer is configured to utilize [Foomatic-RIP](https://linux.die.net/man/1/foomatic-rip) which is used to process documents and where the command injection happens. In order to trigger the command execution, a document needs to be printed. The CUPS Webserver is configured to allow anonymous users access to `TCP/631`. Navigating here makes it possible to print a test page on the malicious printer and gain access as the "lp" user. This user the ability to retrieve past print jobs, one of which contains the root password to the box.

Machine Matrix

Ready to start your
hacking journey?