HackTheBox Writeup — Traverxec

Information Gathering

After a basic port scan I’ve found ports 22 and 80 open which suggest that
we are dealing with a web application.

Getting User

Found a Metasploit Module related to that vulnerability and used it for


Getting Root

The first thing was to check the user’s home directory and something
catchy smiled at me, it was a bash script containing a command that was
executed using sudo.

/usr/bin/sudo /usr/bin/journalctl -n5 -unostromo.service | /usr/bin/cat
/usr/bin/sudo $(less) /usr/bin/journalctl -n5 -unostromo.service



