grep -l "Docker" ./machines (5)

Silentium [Linux]
Easy
FlowiseCVE-2025-58434Password Reset Token DisclosureAccount TakeoverCVE-2025-59528Custom MCP +10
▲ pwned // not yet retired
Kobold [Linux]
Easy
MCP Inspector STDIO RCE for foothold, PHP code injection in PrivateBin container to leak credentials, Docker escape via Arcane container management.
MCPDockerPrivateBinPHP-injectionpassword-reuseArcane
● pwned
CCTV [Linux]
Easy
Default ZoneMinder credentials lead to RCE as www-data. Lateral movement via cracked bcrypt hash to SSH as mark, then sniffing Docker inter-container traffic for sa_mark credentials. Privilege escalation by abusing motionEye running as root to inject a reverse shell into camera event hooks.
ZoneMinderDefault CredentialsDockermotionEyeCredential SniffingRCE
● pwned
AirTouch [Linux]
Medium
WiFi-centric box involving SNMP credential leak, WPA PSK cracking, web app file upload via cookie manipulation, WPA-Enterprise evil twin attack, and hostapd-wpe EAP user file credential disclosure for privilege escalation.
WiFiSNMPWPA-EnterprisePEAPMSCHAPv2Docker +4
● pwned
MonitorsFour [Windows]
Easy
IDOR credential leak, Cacti SQL injection to stacked-query log poisoning RCE, and Docker Desktop API escape to root.
IDORCactiSQLiRCEDockerDocker Desktop Escape +3
● pwned