Orion - HTB Machine Writeup
Difficulty: Easy | OS: Linux | Status: Completed
A detailed walkthrough of the Hack The Box "Orion" machine, covering Craft CMS fingerprinting, exploitation of CVE-2025-32432 (a pre-authentication RCE in Craft CMS's asset transform handling), extraction of database credentials from a `.env` file, bcrypt hash cracking with Hashcat, SSH access, and root privilege escalation via a `USER` environment-variable argument-injection flaw in a local Telnet service.
Tags: craft-cms, cve-2025-32432, telnet-privesc
[ LOADING MACHINE DATA... ]
_