Overview
the machine starts by finding a file that discovers version of the service which is vulnerable to unauthenticated RCE with our foothold on the machine we find database with a weird hash stored. with some research and hash analysis we got the password and with SSH to the machine we find a local service running to store patients data which is vulnerable to SSTI that leads to root access
Enumeration
start with nmap
jimmex@attacker ➜ nmap -sC -sV -vv -oA initial 10.129.244.184
Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-01 ...
