HackTheBox — Pterodactyl
Hard Linux machine on openSUSE Leap 15.6. XFS filesystem vulnerability (CVE-2025-6018/6019), race condition exploitation and privilege escalation.
Overview
Pterodactyl is a Hard-difficulty Linux machine featuring a recent XFS filesystem vulnerability and complex privilege escalation. This machine teaches:
- Advanced enumeration techniques
- Kernel/filesystem vulnerability exploitation
- Race condition exploitation
- Binary compilation for target architecture
Enumeration
Port Scanning
Initial scanning reveals multiple services including:
- SSH service
- Web application
- Additional custom services
Web Application
The web application appears to be related to system management. Key areas to investigate:
- User authentication
- File upload functionality
- System information disclosure
- API endpoints
Initial Foothold
Vulnerability Discovery
The initial access vector involves:
- Finding exposed credentials or authentication bypass
- Exploiting web application functionality
- Gaining shell access through service abuse
Exploitation Hints
Consider:
- How file uploads are processed
- Whether there are default credentials
- What services are accessible after authentication
User Flag Location: /home/[username]/user.txt
Privilege Escalation
System Analysis
Once you have user access, examine:
- Kernel version and patch level
- Filesystem types in use
- Mounted filesystems and permissions
- Recent CVEs for the OS version
The Path to Root
The privilege escalation involves:
- CVE-2025-6018/6019 - XFS filesystem vulnerability
- Race condition exploitation
- Creating SUID binaries through filesystem manipulation
Key Concepts
- Understanding XFS resize operations
- Race conditions in filesystem operations
- Cross-compilation vs native compilation
- Loop device manipulation
Root Flag Location: /root/root.txt
Key Takeaways
- Always check for recent CVEs matching the target OS
- Filesystem vulnerabilities can lead to privilege escalation
- Race conditions require precise timing
- Architecture matters when compiling exploits
Tools Used
nmap- Port scanninggobuster- Web enumerationgcc- Native compilationdd/mkfs.xfs- Filesystem manipulationudisksctl- Disk management- Custom exploit code
Continue the investigation
The complete field notes.
Every command, the full exploitation chain, and all scripts used in this investigation are available to members on Buy Me a Coffee.
Get the full writeup €5 one-off · or monthly membership