grep -l "RCE" ./machines (5)
Connected
[Linux]
▲ pwned // not yet retired
Silentium
[Linux]
▲ pwned // not yet retired
CCTV
[Linux]
Default ZoneMinder credentials lead to RCE as www-data. Lateral movement via cracked bcrypt hash to SSH as mark, then sniffing Docker inter-container traffic for sa_mark credentials. Privilege escalation by abusing motionEye running as root to inject a reverse shell into camera event hooks.
● pwned
Pterodactyl
[Linux]
Unauthenticated RCE via Pterodactyl Panel LFI (CVE-2025-49132), credential reuse for SSH, then privilege escalation via PAM session injection (CVE-2025-6018) chained with udisks2 XFS resize race condition (CVE-2025-6019) to obtain root.
● pwned
MonitorsFour
[Windows]
IDOR credential leak, Cacti SQL injection to stacked-query log poisoning RCE, and Docker Desktop API escape to root.
● pwned