
HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager (CVE-2025-69212) through to root via a misconfigured OliveTin service. Full report and evidence appendix to be published once permitted by HTB's active-machine policy.
🛡️ Hack The Box - Enigma Findings Report 📋 Overview This repository contains a comprehensive penetration test report for the Hack The Box machine Enigma.
🔍 Key Findings
haris/bin/bash dropped through OliveTin command injection🛠️ Frameworks Used
🧰 Tools & Scripts Referenced
imaplib.IMAP4_SSL (port 993)BridgerAlderson/CVE-2025-69212-PoC, exploit.py) - OpenSTAManager OS command injectionwww-data, once as haris)StartAction API request for the final command injection📄 Full Report : Will be published after HTB permit to.
--- Not Published Yet --- View the complete report: Enigma.md