I just solved Layover from Hack the Box!
Layover Machine Summary
Layover is a medium-difficulty Linux machine on Hack The Box that simulates an airport corporate environment where the primary attack surface is hidden behind an internal wireless network. The machine demonstrates how an attacker can chain together weak remote access controls, an unsecured Wi-Fi network, plaintext HTTP credentials, a vulnerable Craft CMS installation, exposed application secrets, and a vulnerable CUPS service to achieve full system compromise.
The attack begins with RDP access to an airport jump box using the provided contractor credentials. Although SSH authentication is unavailable for the contractor account, RDP provides access to the airside-ws01 workstation, which also grants unrestricted sudo privileges. From this system, network-interface enumeration reveals two simulated wireless interfaces powered by mac80211_hwsim, exposing an open HTB International WiFi network.
After connecting to the wireless network with one interface and placing the second interface into monitor mode, I used TShark to passively inspect HTTP POST requests. Because the wireless network was unencrypted and the airport portal used HTTP rather than HTTPS, another user's login credentials were captured in plaintext. These credentials provided access to the internal airport portal and its Craft CMS 5.9.8 administration interface.
The next stage involved exploiting a Yii2 behavior-injection vulnerability in Craft CMS. Despite the captured account having limited administrative privileges, the vulnerable element-search functionality allowed arbitrary PHP classes and methods to be instantiated. By abusing Psy\Readline\Hoa\ConsoleProcessus through an AttributeTypecastBehavior configuration, commands could be executed on the CMS server, resulting in remote code execution as the web server account.
With command execution established, I accessed the application's .env file and recovered the Craft security key. The CMS database contained an encrypted mail-relay password belonging to the aporter account. Because the application server contained both the encrypted credential and the key required to decrypt it, the password could be recovered using Craft/Yii's native decryption functionality. The resulting credentials provided SSH access as aporter and allowed retrieval of the user flag.
The final stage focused on CUPS 2.4.16 running as root. Enumeration showed that the CUPS daemon was active locally, while the aporter account had no sudo privileges or other obvious privilege-escalation path. The machine was vulnerable to CVE-2026-34990, which allows a local user to capture a CUPS Authorization: Local token and abuse it to create a persistent printer targeting a file:// URI. Printing through the malicious queue causes the root-owned CUPS daemon to write attacker-controlled content to a file as root.
I used this primitive to overwrite a file under /etc/sudoers.d/ with a rule granting aporter passwordless sudo privileges. After the file was successfully written by CUPS, sudo could be executed without a password, resulting in a root shell and access to the root flag.
Protected Page
a
b
c
f
g
h
i
j
x
y
z
Keywords:
Layover HTB Walkthrough
aporter@portal
Layover HTB Writeup
I just solved Layover from Hack the Box
Layover - HackTheBox
layover.htb
HackTheBox - Season 12 Layover Machine Write Up
portal.international.htb
contractor@airside-ws01
root@airside-ws01
HTB International WiFi
aporter@10.13.37.10
layover hack the box writeup
layover hack the box walkthrough
wifi.international.htb

1 Comments
To current members, the password to access this encrypted page and other pages has been sent to your email address. If you haven't received it yet, reach out to me at isiaqibrahim.tr@gmail.com
ReplyDeleteNote: This write up includes the complete code blocks and commands. The password for each write up is different. I have sent the password to your inbox on Buy Me A Coffee.
Happy Hacking!!!😈😈