Machine Synopsis
Trickster is a medium-difficulty Linux machine featuring a PrestaShop application vulnerable to [CVE-2024-34716](https://nvd.nist.gov/vuln/detail/CVE-2024-34716). Exploiting this vulnerability grants access to the remote server as the `www-data` user. Further enumeration reveals PrestaShop configuration files containing database credentials, allowing us to dump and crack password hashes to obtain the password for user `james`. We can then SSH into the server as `james`. A Docker container running ChangeDetection.io is also present, vulnerable to [CVE-2024-32651](https://nvd.nist.gov/vuln/detail/CVE-2024-32651), which can be exploited to gain a root shell inside the container. Inside the container, backup files from ChangeDetection.io reveal the password for user `adam`, which allows SSH access as `adam`. Finally, privilege escalation to root is achieved by exploiting [CVE-2023-47268](https://nvd.nist.gov/vuln/detail/CVE-2023-47268) in the PrusaSlicer tool.
Machine Matrix