Description
Craftly is a boutique online marketplace for handmade goods — ceramics, textiles and woodwork sold by independent makers. It has customer accounts, product listings, reviews and an admin catalogue, and at a glance it all looks perfectly ordinary. The security is not as tidy as the storefront. Get in, work your way up, and take control of the box.
Difficulty vs OSWE: Below the OSWE exam. A foundational box, a notch above a pure warm-up: you’ll chain a couple of small mistakes rather than pop a single obvious bug, which is the habit OSWE rewards.
Setup
- Download the
CraftlyOVA from Theosec Labs. - Import into VirtualBox — File → Import Appliance, select the
.ova, and import. - Start the VM. At the console login, sign in and find its IP:
- Username:
student· Password:craftly - Run
ifconfig(orip a) and note the address (e.g.192.168.x.x).
- Username:
- Open the in-browser debugger. Browse to
http://<vm-ip>:8080(code-server). Password:craftly— there is no username.- Open Folder → choose the folder named
craftly. - Click the Run and Debug icon in the left sidebar.
- Click the green ▶ Start Debugging button to launch a debug instance of the app.
- Set breakpoints and step through the code as you investigate.
- Open Folder → choose the folder named
- Read the source to find the vulnerabilities.
- Write your exploit. The target app is at
http://<vm-ip>/(port 80). Write a script (Python recommended) that automates the whole chain — unauthenticated → admin → remote code execution — and, at the RCE step, fires a reverse shell back to anc -lvnp <port>listener on your machine. Running the script should catch you a shell as the web server user. - Capture
local.txtandproof.txt.