Summary
Unbalanced is a Linux, hard box is a created by polarbearer & GibParadox. Initial Enumeration was finding and download EncFS folder, and cracking that and opening the squid.conf and getting the squid password to look at Fully qualified domain name cache which gave us few IPs. Looking on those we found XPATH injection on removed IP from load-balancer.
Using the injection we can find some usernames and again using Blind injection we can crack the password. Which give us access to ssh Enumerating we find pi-hole running. Exploiting that we get a shell as www-data which have access to docker root which have few scripts and one of them contained root password. using which we get root.




