POSTS

HTB: Layover

Layover is a Medium-rated Linux machine that chains WiFi traffic sniffing and CMS RCE to pivot from a contractor foothold into a web portal's internal secrets, landing user access via password reuse. Root falls to a local CUPS vulnerability that leaks an admin token, used to write privileged files and fully compromise the box.

HTB: Layover
5830 words · 28 min

Overview

Information

As is common in real life pentests, you will start the Layover box with credentials for the following account contractor / Contractor2026!