<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/linux/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 27 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/linux/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Layover</title><link>https://wearethebug.dev/posts/htb-layover/</link><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-layover/</guid><description>Layover is a Medium-rated Linux machine that chains WiFi traffic sniffing and CMS RCE to pivot from a contractor foothold into a web portal's internal secrets, landing user access via password reuse. Root falls to a local CUPS vulnerability that leaks an admin token, used to write privileged files and fully compromise the box.</description></item><item><title>bloodyAD</title><link>https://wearethebug.dev/posts/bloodyad/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/bloodyad/</guid><description>Active Directory privilege escalation swiss-army knife. Quick reference for common bloodyAD operations.</description></item><item><title>NetExec Advanced</title><link>https://wearethebug.dev/posts/netexec-advanced/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec-advanced/</guid><description>Follow-up to the NetExec cheatsheet: deeper Active Directory abuse techniques, delegation attacks, and operational tooling for experienced operators.</description></item><item><title>NetExec</title><link>https://wearethebug.dev/posts/netexec/</link><pubDate>Sat, 25 Jul 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec/</guid><description>Swiss-army knife for Active Directory and network protocol enumeration/exploitation, successor to CrackMapExec.</description></item><item><title>HTB: Reactor</title><link>https://wearethebug.dev/posts/htb-reactor/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-reactor/</guid><description>Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components triggered via a crafted Next-Action header, yielding a shell as node. Credentials are extracted from a SQLite database dump, cracked to reveal valid SSH access for lateral movement to the user engineer. Privilege escalation abuses an exposed Node.js debug port (9229), reached via SSH tunnel, to call process.mainModule.require and execute commands as root.</description></item><item><title>HTB: SmartHire</title><link>https://wearethebug.dev/posts/htb-smarthire/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-smarthire/</guid><description>SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold as the svcweb user. Root falls to a Python .pth injection via a group-writable plugin directory, abused through a passwordless sudo misconfiguration to spawn a SUID shell and fully compromise the box.</description></item><item><title>ERTLabs: Chains</title><link>https://wearethebug.dev/posts/ertlabs-chains/</link><pubDate>Sat, 30 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-chains/</guid><description>4 Chains which consist of 2-3 machines that are meant to be exploited together.</description></item><item><title>VULNLAB: Machine Master</title><link>https://wearethebug.dev/posts/vl-machines/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-machines/</guid><description>43 vulnerable standalone machines with various difficulties from easy to insane.</description></item><item><title>VULNLAB: Chain Master</title><link>https://wearethebug.dev/posts/vl-chains/</link><pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-chains/</guid><description>17 Chains which consist of 2-3 machines that are meant to be exploited together.</description></item><item><title>VULNLAB: Phantom</title><link>https://wearethebug.dev/posts/vl-phantom/</link><pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-phantom/</guid><description>Phantom is a medium-difficulty Windows AD exploitation machine. The foothold involves discovering a publicly accessible SMB share, cracking a VeraCrypt container, and abusing Resource-Based Constrained Delegation (RBCD) to escalate privileges.</description></item><item><title>VULNLAB: Odori</title><link>https://wearethebug.dev/posts/vl-odori/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-odori/</guid><description>Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected credentials. Furthermore we will use SFTP to bypass login restrictions and manipulate a python cache file to gain root privileges.</description></item><item><title>VULNLAB: Barrier</title><link>https://wearethebug.dev/posts/vl-barrier/</link><pubDate>Thu, 02 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-barrier/</guid><description>Barrier is a medium-rated machine that features exposed credentials and exploiting SSO authentication, privileged API access and CI/CD runners. Initial access is gained by discovering credentials in a public repository and then exploiting a SAML authentication bypass in GitLab to obtain administrative access. From there, a CI/CD runner is abused to execute code and extract sensitive information from environment variables. With the authorization token, the Authentik API can be exploited to obtain administrative control of the identity platform. Access to the Authentik admin panel allows user impersonation and access to Apache Guacamole. Then an existing connection within Guacamole provides remote access to the host. Finally, a private SSH key is recovered from MySQL and privilege escalation is achieved through credential disclosure in shell history.</description></item><item><title>VULNLAB: Ten</title><link>https://wearethebug.dev/posts/vl-ten/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ten/</guid><description>Ten is a Hard difficulty Linux machine that simulates a misconfigured shared-hosting environment. Players enumerate a public sign-up portal that provisions FTP accounts, abuse weak MySQL/FTP integration to pivot into a real local user, and finally achieve root by poisoning an etcd-driven Apache configuration reload.</description></item><item><title>VULNLAB: Down</title><link>https://wearethebug.dev/posts/vl-down/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-down/</guid><description>Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.</description></item><item><title>VULNLAB: Watcher</title><link>https://wearethebug.dev/posts/vl-watcher/</link><pubDate>Wed, 24 Jul 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-watcher/</guid><description>Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to CVE-2024-22120, which allows an attacker to gain Remote Code Execution. After getting RCE, the attacker discovers that a web app can be backdoored, allowing them to gain credentials for a user account. The user is allowed to access TeamCity, which is running as root, and an agent terminal is active, allowing an attacker to gain a reverse shell as the root user.</description></item><item><title>VULNLAB: Manage</title><link>https://wearethebug.dev/posts/vl-manage/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-manage/</guid><description>Manage is an easy Linux machine that features an exposed Java RMI service. Exploiting the underlying vulnerable JMX service leads to remote code execution and gaining a remote shell as the tomcat user. Lateral movement to the useradmin account can be achieved by discovering a misconfigured backup archive which leaks sensitive files, including SSH keys and OTP codes. Finally, a sudo misconfiguration allows for creating a privileged user and achieving full privilege escalation.</description></item><item><title>VULNLAB: Build</title><link>https://wearethebug.dev/posts/vl-build/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-build/</guid><description>Build is an easy-level Linux machine hosted on the VulnLab platform. Its attack path relies primarily on exploiting a PowerDNSAdmin database, a configuration leak, and DNS poisoning to fully compromise the system.</description></item><item><title>VULNLAB: Reset</title><link>https://wearethebug.dev/posts/vl-reset/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reset/</guid><description>Reset is an Easy difficulty Linux machine which showcases abusing a password reset functionality in a web application following a log poisoning attack, to achieve Remote Code Execution. For privilege escalation, Rservices are abused, then a detached tmux session is used to abuse sudo privileges on nano text editor and execute commands as the root user.</description></item><item><title>VULNLAB: Race</title><link>https://wearethebug.dev/posts/vl-race/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-race/</guid><description>Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, but its password is weak. The endpoint leaks credentials for the Grav CMS admin panel, which is accessible to a low-privilege user with permission to create web server backups. The attacker exploits the backup functionality to retrieve the rest token for a user with privileges to add a proxy and install themes. The attacker adds a proxy to intercept the response, uploads a custom theme, and gets a reverse shell. After gaining a reverse shell, the attacker is able to read sensitive files using a hardcoded password for the max user account. The max user account is a racers group member, which has write permission over a file vulnerable to a time-of-check / time-of-use vulnerability in a cron script. As an attacker, we will create named pipes to suspend execution and replace the file, thereby gaining command execution as root.</description></item><item><title>VULNLAB: Forgotten</title><link>https://wearethebug.dev/posts/vl-forgotten/</link><pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-forgotten/</guid><description>Forgotten is an Easy Linux machine on VulnLab that challenges players to exploit an unfinished LimeSurvey installation by deploying a controlled MariaDB instance to gain admin access. Players then upload a malicious plugin for remote code execution inside a Docker container, discover an environment variable for host access, and escalate privileges by chaining low host access with container root privileges via a setuid binary.</description></item><item><title>VULNLAB: Slonik</title><link>https://wearethebug.dev/posts/vl-slonik/</link><pubDate>Fri, 27 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-slonik/</guid><description>Slonik is a Medium-difficulty Linux machine that focuses on NFS, PostgreSQL abuse, and privilege escalation through insecure backup automation. Initial access is obtained by enumerating exposed NFS shares and leveraging UID/GID trust relationships to access a home directory. History files within the share reveal database credentials and reference a locally bound PostgreSQL socket. Although direct SSH access is restricted, the socket is tunneled over SSH to interact with the database, where built-in PostgreSQL functionality is leveraged to achieve remote code execution. Privilege escalation is accomplished by monitoring system processes and identifying a root-executed backup script, ultimately leveraging pg_basebackup behavior and SUID permissions to obtain a root shell.</description></item><item><title>VULNLAB: Control</title><link>https://wearethebug.dev/posts/vl-control/</link><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-control/</guid><description>Control is a Hard-rated chains focus on a small multi-host Linux environment that simulates a realistic internal network and endpoint-management infrastructure. The lab contains two primary hosts (os.control.vl and intra.control.vl) and a variety of services (web apps, OSCTRL/osquery, SSH, nginx, Docker) that chain together to a full domain compromise. It focuses on exploiting web applications, abusing management tooling (OSCTRL / osquery), and leveraging operational misconfigurations to move from an initial foothold to full root on multiple hosts.</description></item><item><title>VULNLAB: Bamboo</title><link>https://wearethebug.dev/posts/vl-bamboo/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bamboo/</guid><description>Bamboo is an medium-rated Linux machine that begins with discovering a Squid proxy. The proxy is used to scan internal ports and reveals a PaperCut NG instance. A known PaperCut vulnerability CVE-2023-27350 is exploited to gain a foothold. Local enumeration reveals a writable directory containing a script that runs with root privileges. By modifying the script, we obtain a shell as root.</description></item><item><title>VULNLAB: Sync</title><link>https://wearethebug.dev/posts/vl-sync/</link><pubDate>Tue, 25 Apr 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sync/</guid><description>Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash cracking, and privilege escalation.</description></item><item><title>VULNLAB: Dump</title><link>https://wearethebug.dev/posts/vl-dump/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-dump/</guid><description>Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download functionality of pcap files. The machine demonstrates command argument injection through file naming to obtain initial remote code execution as www-data. Enumeration of the system reveals a sudo rule with tcpdump that can be abused for arbitrary file writes to the system and bypassing AppArmor security policy restrictions. With arbitrary file writes players can write malicious Message of The Day configurations that execute as root during system login.</description></item><item><title>VULNLAB: Store</title><link>https://wearethebug.dev/posts/vl-store/</link><pubDate>Fri, 17 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-store/</guid><description>Store is a Hard difficulty box that hosts a Node.js web application, allowing file uploads and storage. The app is vulnerable to Arbitrary File Read, which lets us read configuration files and recover SFTP credentials. We can also dump the host’s environment variables and discover the app was started with --inspect, with the Node inspector listening on port 9229. By abusing SFTP for port forwarding, we can tunnel that internal inspector port to our machine, attach and run JavaScript to spawn a reverse shell as user dev. For privilege escalation, the ChromeDriver service on port 9515 can be abused via its WebDriver API to execute a malicious script and gain a root shell.</description></item><item><title>VULNLAB: Unchained</title><link>https://wearethebug.dev/posts/vl-unchained/</link><pubDate>Fri, 04 Mar 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unchained/</guid><description>Unchained is a Medium-rated Linux machine available on Vulnlab platform. Starting with NFS share enumeration then a source code analysis allows a JSONPICKLE deserialization to obtain a reverse shell as user. For the privilege escalation, CVE-2021-44730 (Dirty snap-confine LPE) or CVE-2022-0847 (DirtyPipe) can be exploited.</description></item><item><title>VULNLAB: Zero</title><link>https://wearethebug.dev/posts/vl-zero/</link><pubDate>Fri, 25 Feb 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-zero/</guid><description>Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users can create their own HTML pages. This service is exploitable by uploading a malicious .htaccess file to gain arbitrary file read access to the web servers' asset files. By viewing the source code of these files players will find hard coded credentials that allow for access to the target over SSH. The Apache server configuration is periodically managed by a cronjob that checks the integrity of the Apache configurations and can be abused by satisfying the conditions of the cronjob task to include a malicious line into the restored configuration to leak the contents of files owned by root.</description></item><item><title>VULNLAB: Data</title><link>https://wearethebug.dev/posts/vl-data/</link><pubDate>Sun, 23 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-data/</guid><description>Data is an Easy Linux machine that involves exploiting CVE-2021-43798, an arbitrary file read via path traversal in Grafana. By exploiting this vulnerability, the database file for Grafana is extracted, and the hashes in the database are converted to a format readable by Hashcat. The hash is then cracked and can be used for SSH access to the target as user boris. The compromised user has the privileges to execute docker exec as root on the system, allowing the user to escalate and obtain root access by adding the privileged flag to running containers and mounting the host filesystem.</description></item><item><title>VULNLAB: Feedback</title><link>https://wearethebug.dev/posts/vl-feedback/</link><pubDate>Sun, 12 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-feedback/</guid><description>Feedback is an Easy-rated Linux machine centered around exploiting a vulnerable Log4j input field.</description></item></channel></rss>