This post covers the HTB Analytics box, including the initial webserver hosting Metabase and the pre-auth RCE exploit to get code execution. It also explores the GameOver(lay) vulnerability used to escalate privileges to root. The post provides detailed steps and tackles the box's enumeration and enumeration results.

14m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as metabase in containerShell as metalyticsShell as root

Sort: