Oopsie
Oopsie
Oopsie 288
Oopsie
RETIRED MACHINE

Oopsie

Oopsie - Linux Linux
Oopsie - Very Easy Very Easy

4.3

MACHINE RATING

87789

USER OWNS

85872

SYSTEM OWNS

25/10/2021

RELEASED
Created by MrR3boot

Machine Synopsis

Oopsie is a very easy Linux machine that highlights the impact of information disclosure and broken access control in web applications. Website enumeration reveals a guest login with manipulatable cookies and user IDs allowing escalation to an admin role and access to a file upload feature. A PHP reverse shell is then uploaded to gain an initial foothold. Further enumeration exposes hardcoded credentials enabling lateral movement to another user. Finally, privilege escalation is achieved by abusing a misconfigured SUID binary through PATH hijacking.

Machine Matrix

Ready to start your
hacking journey?