MagicGardens
MagicGardens
MagicGardens 602
MagicGardens
RETIRED MACHINE

MagicGardens

MagicGardens - Linux Linux
MagicGardens - Insane Insane

3.3

MACHINE RATING

1295

USER OWNS

1264

SYSTEM OWNS

18/05/2024

RELEASED
Created by m4rsh3ll

Machine Synopsis

MagicGardens is an insane box that starts with an e-commerce store on port 80, where an attacker sets up a rouge HTTP server and exploits an SSRF to escalate privileges on their user account. Followed by the SSRF, the attacker eventually abuses an XSS vulnerability in the form of a QR code, which subsequently leads to the Django Administrator panel, which allows reading of the encrypted hashes and ultimately gives SSH access. Furthermore, the attack path involves reversing and exploiting a traffic analyzer program to move to another user laterally. For privilege escalation, an image is downloaded from the docker registry, which helps abuse insecure deserialization in the Django application, giving us a reverse shell in a container. The attacker creates and loads a kernel module to break out of the docker container and obtain a root shell.

Machine Matrix

Ready to start your
hacking journey?