Unrested
Unrested
Unrested 639
Unrested
RETIRED MACHINE

Unrested

Unrested - Linux Linux
Unrested - Medium Medium

4.7

MACHINE RATING

144

USER OWNS

140

SYSTEM OWNS

05/12/2024

RELEASED
Created by TheCyberGeek

Machine Synopsis

Unrested is a medium difficulty `Linux` machine hosting a version of `Zabbix`. Enumerating the version of `Zabbix` shows that it is vulnerable to both [CVE-2024-36467](https://nvd.nist.gov/vuln/detail/CVE-2024-36467) (missing access controls on the `user.update` function within the `CUser` class) and [CVE-2024-42327](https://nvd.nist.gov/vuln/detail/CVE-2024-42327) (SQL injection in `user.get` function in `CUser` class) which is leveraged to gain user access on the target. Post-exploitation enumeration reveals that the system has a `sudo` misconfiguration allowing the `zabbix` user to execute `sudo /usr/bin/nmap`, an optional dependency in `Zabbix` servers that is leveraged to gain `root` access.

Machine Matrix

Ready to start your
hacking journey?