← back to writeups
Vulnhub

Vulnhub: Venom

Venom is a Linux boot-to-root that rewards patient enumeration over clever exploitation. The whole first half is a treasure hunt — a hash hidden in page source, an FTP foothold, and a chain of encodings that eventually spits out a CMS admin password — and the back half is a public exploit for an outdated CMS followed by a wide-open sudo rule. The lesson of the box is that most of the work in a real assessment is reading carefully, not launching exploits.

The walkthrough below shows every step with screenshots; this intro frames what each phase is actually doing and why it works.

Attack chain at a glance

  • Recon — nmap finds FTP (21), HTTP (80), SMB (139) and HTTPS (443).
  • Clue chain — a hash commented into the port-80 page cracks to a username; that logs into FTP, where hit.txt holds a further chain of encodings that decodes to the domain and the CMS admin password (information disclosure).
  • Foothold — logging into Subrion CMS 4.2.1 and running the public Exploit-DB exploit for that version gives a shell as www-data (an authenticated file-upload / RCE flaw).
  • User — pivot to hostinger, run linpeas, read the user flag out of a backup file.
  • Root — pivot to Nathan, whose sudo -l allows sudo bash directly — an instant root shell.
Techniques in play: layered-encoding clue chains (base64 and friends — decode one layer at a time), a known-version CMS exploit, and the single most common Linux privilege escalation of all — a permissive sudo rule. Enumeration tooling: nmap, FTP, an online hash cracker, Exploit-DB, and linpeas.

Venom is a beginner-to-intermediate Vulnhub box. The path runs through a hash hidden in page source, an FTP foothold, a chain of encoded clues leading to a Subrion CMS login, a public CMS exploit for the shell, and finally a trivial sudo misconfiguration for root.

Reconnaissance

Venom VM booted in the hypervisor
The Venom VM imported from Vulnhub and booted.

With the box running, netdiscover on the local network finds the target.

netdiscover output showing the target IP
The target comes back as 192.168.0.113.

An nmap scan maps the attack surface.

nmap scan results showing open ports
Ports 21 (FTP), 80 (HTTP), 139 (SMB) and 443 (HTTPS) are open.

Web & FTP enumeration

Visiting port 80 shows the default web page. Viewing the page source turns up a hash left in an HTML comment.

Default web page with a hash in an HTML comment
The default page — a hash is commented out in the source.

Running that hash through an online cracker resolves it to a word.

Online hash cracker returning the plaintext 'hostinger'
The hash cracks to hostinger.

That looks like a username, so it is worth trying against FTP.

FTP login attempt using the recovered name
Authenticating to FTP with hostinger…
Successful FTP session
…succeeds.

The FTP share holds a file, hit.txt, which is pulled down to Kali.

Downloading hit.txt from the FTP server
hit.txt retrieved from the share.

Opening it reveals more encoded hashes and a domain name.

Contents of hit.txt showing encoded data
hit.txt — more encoded material and a hostname.
Decoding the first layer of the hash chain
Working through the chain of encodings, step one…
Decoding the next layer
…step two…
Decoding a further layer
…step three…
Decoding the final layer of the chain
…and the final layer.

The decoded chain yields the next clue and a link.

Decoded clue pointing to a link
The decoded clue and the link it points to.

Following the link lets the admin password be decoded.

Decoding the admin password from the link
The admin password, recovered.

Admin login & Subrion CMS

After adding the hostname venom.box to /etc/hosts, the site resolves to a login page.

Login page served after adding venom.box to /etc/hosts
The application login, reachable once the host entry is added.

Using the username dora and the decoded password logs straight in.

Logging in with dora and the decoded password
Authenticating as dora…
Authenticated admin dashboard
…lands on the admin dashboard.

The panel identifies the software as Subrion CMS 4.2.1.

Subrion CMS 4.2.1 version banner
The target runs Subrion CMS 4.2.1.

Since the panel allows file uploads, the first attempt is a malicious .phar payload to pull a reverse shell.

Preparing a malicious phar upload
Crafting a .phar payload…
Uploading the phar file through the CMS
…uploading it through the CMS…
Upload accepted by the application
…which the application accepts.

The upload does not yield a shell, so a different route is taken.

Reviewing the failed upload approach
The .phar route does not call back — time for a known exploit.

Exploit-DB has a public exploit for this exact Subrion version, which is downloaded.

Exploit-DB page for Subrion CMS 4.2.1
The matching Subrion 4.2.1 exploit on Exploit-DB.

Running the exploit with the known credentials returns a shell.

Running the Subrion exploit with valid credentials
Launching the exploit with dora's credentials.
Shell obtained through the exploit
A foothold shell on the box.

A second Python one-liner upgrades this into a proper reverse shell caught by a local listener, landing as www-data.

Reverse shell caught as www-data
Interactive shell as www-data.

Privilege escalation

Switching to the hostinger user and moving to /tmp, linpeas is staged over from Kali with python -m SimpleHTTPServer and wget.

Switching to the hostinger user
Becoming the hostinger user.
Serving linpeas from Kali with SimpleHTTPServer
Hosting linpeas from Kali.
Downloading linpeas onto the target with wget
Pulling it onto the target into /tmp.

After making it executable, linpeas runs.

Making linpeas executable and running it
chmod +x and run.

It surfaces a backup file; opening it reveals the user flag.

Backup file containing the user flag
The user flag, recovered from a backup file.

The same output points at the user Nathan; switching to that account with the hash recovered alongside the flag works.

Switching to the Nathan user
Pivoting to Nathan.

sudo -l shows Nathan may run sudo bash directly — an instant root shell.

sudo bash giving a root shell and root.txt
sudo bash → root, and root.txt in /root completes the box.
Venom is a clue-chasing box: the real work is enumeration and patiently decoding one layer at a time. The actual exploitation — a public CMS exploit and a wide-open sudo rule — is straightforward once the credentials are in hand.

Defender's notes

  • Never leave hashes, hostnames, or credentials in HTML comments or world-readable files — that is textbook sensitive data exposure.
  • Lock down anonymous FTP and don't reuse a discovered name as a login.
  • Patch or replace end-of-life CMS software; Subrion 4.2.1 has a public authenticated-RCE exploit.
  • Audit sudo rules — ALL/sudo bash for a non-admin user is full root. Grant least privilege and log sudo use.