“An easy little machine for beginners.” HackMyVM machine containing abuse of IPMI service, password cracking to SSH brute force, and credential stealing to access the superuser account.
This machine can be downloaded from HackMyVM. You don’t need to create an account, you only need an account to submit the user/root flags and access the rest of the platform.
To set up this machine inside Proxmox, I used the following resource as a reference: https://benheater.com/proxmox-lab-adding-vulnhub-vms/. Additionally, I had to fix some DHCP issues when booting the machine using the following resource: https://benheater.com/proxmox-lab-adding-hackmyvm-boxes/.
Finally, I set up a simple DHCP server to assign an IP address from my Kali machine to the vulnerable VM. Here’s my own guide on how to configured it based on a previous writeup for the Kioptrix series: Kioptrix Level 2 (1.1) - VulnHub Writeup
Enumeration
Once we start the machine, we can use arpscan to find its designated IP address.
For this scenario, let's stick with 10.0.1.115. Let's continue with our standard nmap enumeration.
└─$ nmap 10.0.1.115 -T4 -p- -oN all-tcp-ports
Starting Nmap 7.95 ( https://nmap.org ) at 2026-08-07 15:54 MDT
Nmap scan report for 10.0.1.115
Host is up (0.00012s latency).
Not shown: 65534 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
MAC Address: BC:24:11:26:17:8C (Proxmox Server Solutions GmbH)
Nmap done: 1 IP address (1 host up) scanned in 1.12 secondsThere isn't really anything interesting on the TCP ports... Let's check common UDP ports for any open services.
Good, let's do some more research on this service. According to HackTricks, this service hosted in UDP/623 refers to IPMI (Intelligent Platform Management Interface), which is used for "remote management and monitoring of computer systems". nmap confirms that this port is hosting an IPMI service with ipmi-version script.
IPMI Abuse → User Credentials
Let's use the page from HackTricks as a reference for abusing this service. The HackTricks page mentions a Metasploit exploit that we can use to test if this is vulnerable to IPMI Authentication Bypass via Cipher 0.
The service is vulnerable to Cipher 0! Now, let's get some user credentials with ipmi_dumphashes.
Great! Now, let's get all user data with user list and save it to userlist.txt .
Using awk, we can process this into a newline-separated list called users.txt.
$ cat userlist.txt | awk 'NR > 1 && $2 != "true" { print $2 }' > users.txtNow, we can use the same ipmi_dumphashes Metasploit module to get all hashes from all of the users in the system.
Let's use john and rockyou.txt to crack these hashes with john --wordlist=/usr/share/wordlists/rockyou.txt john-out. Once we run john, we will see that these passwords will be cracked instantly.
Using awk and cut, we can take the results stored in john --show and store the usernames and passwords separately.
└─$ john john-out --show | head -n 36 | awk '{print $2}' | cut -d ':' -f 1 > user1.txt
└─$ john john-out --show | head -n 36 | awk '{print $2}' | cut -d ':' -f 2 > pass1.txtNow, we can run hydra to find any valid credentials for the SSH service.
hydra -L user1.txt -P pass1.txt ssh://10.0.1.115 -f -t 16Let's login with these credentials.
The user flag will be available in the home directory of onida !
Privilege Escalation: onida → root
After some initial enumeration inside the system, we can find that the current user can't run sudo, belongs to standard groups, and has no available SUID binaries to abuse.
If we keep looking inside the system, we will find the /var/www/html directory, which is often used to store web server files.
onida@atom:/var/www/html$ ls
atom-2400-database.db css img index.php js login.php profile.php register.php videoLooking into the SQLite database, we will find a hashed password belonging to atom.
onida@atom:/var/www/html$ sqlite3 atom-2400-database.db
SQLite version 3.40.1 2022-12-28 14:03:47
Enter ".help" for usage hints.
sqlite> .tables
login_attempts users
sqlite> SELECT * FROM users;
1|atom|$2y$10$Z1K.4yVakZEY.Qsju3WZzukW/M3fI6BkSohYOiBQqG7pK1F2fH9CmThis password might belong to a privileged user in the system, so let's crack it with john.
This password can be used to login as root!
onida@atom:/var/www/html$ su root
Password:
root@atom:/var/www/html# cd
root@atom:~# ls
root.txtThe Atom website
Let's have a look at the website being hosted inside the machine. Using ss -tulnp and looking for apache, we can confirm that there is an HTTP service running on port 80.
Now, let's use port forwarding with our credentials as onida to forward this port back to our machine.
ssh -L 8080:localhost:80 onida@10.0.1.115Once we log in, we can open 127.0.0.1:8080 in our browser to see what the website looks like.
Let's try to register an account inside the Register page to find how the website deals with a new user account.
Upon logging in, we will be received with a simple message inside profile.php.
If we use the credentials for atom inside the SQLite database that we found, we will see this final screen congratulating us for obtaining root in this machine.