Gavel
Gavel
Gavel 811
Gavel
RETIRED MACHINE

Gavel

Gavel - Linux Linux
Gavel - Medium Medium

3.5

MACHINE RATING

3506

USER OWNS

3185

SYSTEM OWNS

29/11/2025

RELEASED
Created by Shadow21A

Machine Synopsis

`Gavel` is a medium-difficulty Linux machine that demonstrates the exploitation of a misused SQL PDO statement to achieve SQL injection and extract data from an internal database. The scenario further highlights a PHP code-injection flaw that is exploited to execute remote commands, thereby enabling initial access to the target. Privilege escalation is achieved by targeting a root-owned daemon that processes user-supplied YAML files; by submitting a crafted YAML payload, PHP code is executed within a sandboxed environment with root privileges.

Machine Matrix

Ready to start your
hacking journey?