HTB - Dog Machine [help]
by edimirbahia - Sunday March 30, 2025 at 03:06 PM
#1
I'm currently working on the "DOG" box  and I was able to gain a shell as www-data by exploiting Backdrop CMS and uploading a webshell module. From there, I upgraded my shell using Python (pty.spawn("/bin/bash")) and verified that I have basic shell access.

I've already run LinPEAS and Linux Exploit Suggester, which pointed out potential privesc vectors like CVE-2021-4034 (PwnKit), but that led me straight to root. What I'm really trying to figure out now is how to escalate from www-data to the user account that owns the user.txt
flag.


I still can’t seem to find a way to pivot from www-data to the target user.
Any nudges or suggestions would be much appreciated — even just a hint toward what to focus on would help a lot.
Thanks in advance! ?
Reply
#2
where is the file ,git has a username and pasword
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 365 113,297 Yesterday, 07:30 PM
Last Post: N1GHTC0D3
  HTB Eloquia User and Root Flags - Insane Box 69646B 14 17,578 08-21-2026, 07:27 PM
Last Post: tangol
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 94 26,193 08-21-2026, 06:20 AM
Last Post: jamoski
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 25 19,469 08-15-2026, 06:06 PM
Last Post: m4573rx
  HTB - ALL Challenges you Stuck in osamy7593 3 17,624 08-15-2026, 01:58 AM
Last Post: 0xIDA



 Users browsing this thread: 1 Guest(s)