Discussion — Any questions? Ask and discuss freely in the community.
Hack The Box active 292 views

HTB Layover Writeup | RDP to Craft CMS RCE (CVE-2026-44011) to Root via CUPS (CVE-2026-34990)

Hack The Box Layover overview: RDP entry, Wireshark credential sniffing, Craft CMS RCE (CVE-2026-44011), security-key decryption and CUPS privesc.

Layover
Medium active Hack The Box
Layover completion
Protected while the machine is active

Due to Hack The Box policies this walkthrough is not publicly served until Layover retires. See the official HTB writeup guidelines.

Machine profile

Platform
Hack The Box
Machine
Layover
Difficulty
Medium
Published
Status
active

Layover is a medium-difficulty Linux machine from Hack The Box, themed around the internal network of a corporate airport. Rather than a single service, the box is built as a workplace: several hosts, several trust levels, and the assumption that being inside the building means you are trusted.

The skills it belongs to are internal network enumeration, web application security, credential hygiene and Linux privilege escalation. What makes it interesting is the combination — the machine is designed so that no single mistake wins the box, and progress depends on noticing which of the ordinary details of a working environment are actually out of place.

It is a good fit for readers who have finished the single-service web boxes and want something that feels closer to a real corporate network, where the hard part is piecing together small observations rather than exploiting one obvious flaw. Expect to spend time reading output carefully rather than guessing at payloads, and expect the writeup to reward that habit once the box retires.

What this machine covers

Vulnerabilities

Software, services & tooling

Wireshark Craft CMS CUPS OpenPrinting CUPS Nmap

Techniques & attack classes

RDP Credential Sniffing Authenticated RCE Linux Privilege Escalation Lateral Movement

What the finished writeup contains

When Layover retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.

  1. Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
  2. Initial foothold The first authenticated or unauthenticated execution path
  3. Enumeration Deeper inspection of the exposed services and their configuration
  4. Exploitation Chaining the weaknesses found into a working exploit
  5. Credential recovery Secrets, keys and hashes, and how they were obtained
  6. Privilege escalation The route from the foothold account to a root shell
  7. Flags User and root flag capture

292 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.

Why is this walkthrough protected right now?

No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.

Topics: RDP, Wireshark, Credential Sniffing, Craft CMS, CVE-2026-44011, Authenticated RCE, CVE-2026-34990, CUPS, OpenPrinting CUPS, Linux Privilege Escalation, Lateral Movement, Nmap

Comments