A detailed walkthrough of the HackTheBox machine 'Pterodactyl', covering exploitation of CVE-2025-49132, an unauthenticated directory traversal in Pterodactyl Panel v1.11.10's locale endpoint. The attack chain involves chaining the LFI with the PEAR pearcmd.php technique to write and execute a webshell, extracting database credentials, cracking a bcrypt hash to pivot to a local user, then escalating to root on openSUSE via a PAM environment-variable flaw abusing Polkit and a libblockdev/udisks vulnerability to mount a crafted XFS image with a SetUID-root shell. Also covers CopyFail and DirtyFrag Linux kernel privilege escalation exploits.

36m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconShell as wwwrunShell as phileasfogg3Shell as rootBeyond Root

Sort: