Machine Synopsis
Manage is an easy Linux machine that features an exposed `Java RMI` service. Exploiting the underlying vulnerable `JMX` service leads to remote code execution and gaining a remote shell as the `tomcat` user. Lateral movement to the `useradmin` account can be achieved by discovering a misconfigured backup archive which leaks sensitive files, including `SSH` keys and `OTP` codes. Finally, a `sudo` misconfiguration allows for creating a privileged user and achieving full privilege escalation.
Machine Matrix