Summary
Unbalanced is a Linux, hard box is a created by polarbearer & GibParadox. Initial Enumeration was finding and download EncFS
folder, and cracking that and opening the squid.conf
and getting the squid password to look at Fully qualified domain name cache
which gave us few IPs. Looking on those we found XPATH
injection on removed IP from load-balancer.
Using the injection we can find some usernames and again using Blind injection we can crack the password. Which give us access to ssh Enumerating we find pi-hole running. Exploiting that we get a shell as www-data
which have access to docker root which have few scripts and one of them contained root password. using which we get root.