Machine Synopsis
Markup is a very easy Windows machine that explores XML External Entity (XXE) vulnerabilities, insecure file permissions and misconfigured scheduled tasks. A vulnerable web application allows for user-supplied XML input to be parsed allowing the retrieval of sensitive files on the host machine, including the user's private SSH key. Privilege escalation can be achieved by identifying and overwriting a scheduled batch script with insecure permissions to execute a reverse shell.
Machine Matrix