0xdf hacks stuff
Read post

HTB: Facts

A detailed walkthrough of the HackTheBox 'Facts' machine, a Linux box running Camaleon CMS 2.9.0 on Ruby on Rails. The attack chain involves exploiting CVE-2025-2304, a mass assignment vulnerability in Camaleon's password update endpoint, to escalate a regular user account to administrator. Admin credentials are then used to authenticate to a local MinIO S3 service, where an encrypted SSH private key is retrieved from a bucket resembling a home directory. The passphrase is cracked with john using rockyou.txt. For root privilege escalation, a sudo rule allows running 'facter' (Puppet's Ruby-based system inventory tool) as any user, which can load arbitrary Ruby code from a custom facts directory. A 'Beyond Root' section covers an alternative foothold via a path traversal vulnerability in Camaleon's S3 uploader and decrypting Rails session cookies using a leaked master key.

    #security#rails
Jun 06•37m read time•From 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as triviaShell as rootBeyond Root - Alternative Foothold
236 Impressions
0xdf hacks stuff's image
0xdf hacks stuff

64 Followers

•

211 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard