ls -la ./machines (19)

total
19
pwned
19
locked
4
easy
12
medium
7
Reactor [Linux]
Easy
Next.jsReact Server ComponentsCVE-2025-55182CVE-2025-66478React2ShellInsecure Deserialization +7
▲ pwned // not yet retired
Cohort [Linux]
Easy
marimoCVE-2026-39987Pre-Auth RCEWebSocketSSRFPackageKit +4
▲ pwned // not yet retired
Connected [Linux]
Easy
FreePBXAsteriskSQL InjectionDefault CredentialsDatabase ManipulationSysadmin Hook +2
▲ pwned // not yet retired
Silentium [Linux]
Easy
FlowiseCVE-2025-58434Password Reset Token DisclosureAccount TakeoverCVE-2025-59528Custom MCP +10
▲ pwned // not yet retired
DevArea [Linux]
Medium
Anonymous FTP exposed a Java SOAP service JAR; an MTOM XXE attack against the CXF endpoint leaked the Hoverfly admin password from a systemd unit file, then authenticated RCE via Hoverfly middleware yielded a shell as dev_ryan; privilege escalation exploited a world-writable /bin/bash by writing a SUID-creating wrapper triggered by a root-owned systemd timer.
FTPXXESOAPMTOMApache CXFHoverfly +4
● pwned
Kobold [Linux]
Easy
MCP Inspector STDIO RCE for foothold, PHP code injection in PrivateBin container to leak credentials, Docker escape via Arcane container management.
MCPDockerPrivateBinPHP-injectionpassword-reuseArcane
● pwned
VariaType [Linux]
Medium
Exploited fonttools CVE-2025-66034 designspace path traversal to write a PHP webshell, escalated to user via FontForge archive command injection, then root via setuptools PackageIndex arbitrary file write to cron.d.
fonttoolsCVE-2025-66034path-traversalPHP-injectionLFIgit-exposure +5
● pwned
CCTV [Linux]
Easy
Default ZoneMinder credentials lead to RCE as www-data. Lateral movement via cracked bcrypt hash to SSH as mark, then sniffing Docker inter-container traffic for sa_mark credentials. Privilege escalation by abusing motionEye running as root to inject a reverse shell into camera event hooks.
ZoneMinderDefault CredentialsDockermotionEyeCredential SniffingRCE
● pwned
Interpreter [Linux]
Medium
Pre-auth RCE via CVE-2023-43208 XStream deserialization in Mirth Connect 4.4.0, lateral movement through MySQL credential extraction and password hash replacement, privilege escalation via Python eval() injection in an internal Flask notification app running as root.
XStream DeserializationMirth ConnectCVE-2023-43208HL7/MLLPPython eval() Injection
● pwned
WingData [Linux]
Easy
Unauthenticated RCE in Wing FTP Server v7.4.3 via NULL byte Lua injection (CVE-2025-47812), lateral movement through cracked FTP user password hash, and root via Python tarfile data filter PATH_MAX bypass (CVE-2025-4517).
Wing FTP ServerCVE-2025-47812Lua injectionpassword crackinghashcattarfile filter bypass +3
● pwned
Pterodactyl [Linux]
Medium
Unauthenticated RCE via Pterodactyl Panel LFI (CVE-2025-49132), credential reuse for SSH, then privilege escalation via PAM session injection (CVE-2025-6018) chained with udisks2 XFS resize race condition (CVE-2025-6019) to obtain root.
CVE-2025-49132LFIpearcmdRCECVE-2025-6018CVE-2025-6019 +6
● pwned
Facts [Linux]
Easy
Exploited CamaleonCMS path traversal (CVE-2024-46987) to extract MinIO credentials and an encrypted SSH key, then escalated via sudo facter --custom-dir to root.
CamaleonCMSCVE-2024-46987LFIMinIOSSH Key CrackingFacter Sudo Abuse
● pwned
Overwatch [Windows]
Medium
Windows AD DC with anonymous SMB share leaking .NET app credentials, MSSQL linked server DNS poisoning for credential capture, and WCF SOAP service command injection for SYSTEM access.
Active DirectoryMSSQLWCFCommand InjectionDNS PoisoningLinked Server +1
● pwned
AirTouch [Linux]
Medium
WiFi-centric box involving SNMP credential leak, WPA PSK cracking, web app file upload via cookie manipulation, WPA-Enterprise evil twin attack, and hostapd-wpe EAP user file credential disclosure for privilege escalation.
WiFiSNMPWPA-EnterprisePEAPMSCHAPv2Docker +4
● pwned
Browsed [Linux]
Medium
Malicious Chrome MV3 extension uploaded to server-side browser achieved RCE via bash arithmetic evaluation in a Flask/bash backend, then escalated to root via .pyc injection into a world-writable __pycache__ directory of a sudo-allowed Python script.
Chrome extensionbash arithmetic evaluationPython pyc injectionsudo abuseGiteaFlask
● pwned
MonitorsFour [Windows]
Easy
IDOR credential leak, Cacti SQL injection to stacked-query log poisoning RCE, and Docker Desktop API escape to root.
IDORCactiSQLiRCEDockerDocker Desktop Escape +3
● pwned
Expressway [Linux]
Easy
IKEv1 Aggressive Mode PSK hash capture and offline brute-force reveals SSH credentials; custom sudo 1.9.17 binary is exploited via CVE-2025-32463 NSS library injection to achieve root.
ikeikev1aggressive-modepskipsecsudo +3
● pwned
Baby [Windows]
Easy
LDAP anonymous bind leaks an initial password in a user description; the target user (Caroline.Robinson) has STATUS_PASSWORD_MUST_CHANGE set, allowing password reset via SAMR; Backup Operators group membership enables direct flag read via FILE_OPEN_FOR_BACKUP_INTENT over SMB.
active-directoryldappassword-must-changebackup-operatorssebackupprivilegewindows-server-2022
● pwned
Eighteen [Windows]
Easy
Windows Server 2025 DC with MSSQL impersonation leading to credential extraction, password spray for WinRM access, and BadSuccessor dMSA privilege escalation to Domain Admin.
MSSQLSQL ImpersonationPBKDF2dMSABadSuccessorActive Directory +1
● pwned