0xdf hacks stuff
Read post

HTB: DevArea

A detailed walkthrough of the HackTheBox machine 'DevArea', a multi-service Linux target. The attack chain starts with anonymous FTP access to download a Java JAR file, reverse engineering it to identify a vulnerable Apache CXF 3.2.14 SOAP service. CVE-2022-46364 (SSRF/arbitrary file read via XOP:Include in MTOM requests) is exploited to read files including /proc process listings, leaking Hoverfly credentials. CVE-2025-54123, a command injection in Hoverfly's middleware API, then yields a shell as dev_ryan. Privilege escalation proceeds through a custom SysWatch monitoring app by forging a session cookie and bypassing a weak input filter, then exploiting a flawed symlink check in a root-run script to read the root SSH key.

    #security#java
Jul 04•46m read time•From 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as dev_ryanShell as syswatchShell as rootBeyond Root
289 Impressions
0xdf hacks stuff's image
0xdf hacks stuff

64 Followers

•

211 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard