Nocturnal
Nocturnal
Nocturnal 656
Nocturnal
RETIRED MACHINE

Nocturnal

Nocturnal - Linux Linux
Nocturnal - Easy Easy

3.8

MACHINE RATING

8323

USER OWNS

7651

SYSTEM OWNS

12/04/2025

RELEASED
Created by FisMatHack

Machine Synopsis

`Nocturnal` is a medium-difficulty Linux machine demonstrating an IDOR vulnerability in a PHP web application, allowing access to other users' uploaded files. Credentials are retrieved to log in to the admin panel, where the application's source code is accessed. A command injection vulnerability is identified, providing a reverse shell as the `www-data` user. Password hashes are extracted from a SQLite database and cracked to obtain SSH access as the `tobias` user. Exploiting [CVE-2023-46818](https://nvd.nist.gov/vuln/detail/CVE-2023-46818) in the `ISPConfig` application grants remote command execution, leading to privilege escalation to the `root` user.

Machine Matrix

Ready to start your
hacking journey?