πFact
https://app.hackthebox.com/machines/Facts

Facts Walkthrough
1. Initial Reconnaissance
Service Enumeration
2. Web Enumeration
Directory Enumeration
3. CMS Identification
4. Privilege Escalation to Admin
CVE-2025-2304 --- Role Injection
5. Authenticated Arbitrary File Read
CVE-2024-46987
Vulnerable Endpoint
Example: Reading /etc/passwd
/etc/passwd6. Sensitive File Discovery
Read User Home Directories
Extract SSH Private Key
7. Cracking SSH Private Key
Convert Key for John
Crack with Wordlist
Show Result
8. SSH Access
Fix Permissions (WSL/Linux)
Login Using Key
9. Sudo Enumeration
10. Privilege Escalation to Root
Abusing Facter Custom Facts
Create Malicious Fact
Execute as Root
Verify
11. Impact
Vulnerabilities Summary
Last updated