Machine Synopsis
Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to [CVE-2024-22120](https://nvd.nist.gov/vuln/detail/CVE-2024-22120), which allows an attacker to gain Remote Code Execution. After getting RCE, the attacker discovers that a web app can be backdoored, allowing them to gain credentials for a user account. The user is allowed to access TeamCity, which is running as root, and an agent terminal is active, allowing an attacker to gain a reverse shell as the root user.
Machine Matrix