skip to content
~/bokkapig
_
machines
refs
tags
search
hack the box machine writeups
← cd ../tags
grep -l "Privilege Escalation" ./machines
(2)
Connected
[Linux]
Easy
2026-06-06
FreePBX
Asterisk
SQL Injection
Default Credentials
Database Manipulation
Sysadmin Hook
+2
▲ pwned // not yet retired
Expressway
[Linux]
Easy
2025-11-20
IKEv1 Aggressive Mode PSK hash capture and offline brute-force reveals SSH credentials; custom sudo 1.9.17 binary is exploited via CVE-2025-32463 NSS library injection to achieve root.
ike
ikev1
aggressive-mode
psk
ipsec
sudo
+3
● pwned