skip to content
~/bokkapig
_
machines
refs
tags
search
hack the box machine writeups
← cd ../tags
grep -l "Facter Sudo Abuse" ./machines
(1)
Facts
[Linux]
Easy
2026-01-31
Exploited CamaleonCMS path traversal (CVE-2024-46987) to extract MinIO credentials and an encrypted SSH key, then escalated via sudo facter --custom-dir to root.
CamaleonCMS
CVE-2024-46987
LFI
MinIO
SSH Key Cracking
Facter Sudo Abuse
● pwned