Description
Currents is a self-hosted feed reader: add your blogs and news feeds and it pulls the articles into one clean stream. It has a personal dashboard, an admin area, and a small internal service it talks to behind the scenes. Neither getting in nor getting code execution is a one-shot affair here — each is a short chain of its own.
Difficulty vs OSWE: Approaching OSWE, but still a step below the exam. This is the box where the OSWE mindset clicks: you stop looking for a single silver-bullet bug and start chaining several distinct weaknesses into one automated exploit.
Setup
- Download the
CurrentsOVA from Theosec Labs. - Import into VirtualBox — File → Import Appliance, select the
.ova, and import. - Start the VM. At the console login, sign in and find its IP:
- Username:
student· Password:currents - Run
ifconfig(orip a) and note the address (e.g.192.168.56.x).
- Username:
- Open the in-browser debugger. Browse to
http://<vm-ip>:8080(code-server). Password:currents— there is no username.- Open Folder → choose the folder named
currents. - Click the Run and Debug icon in the left sidebar.
- Click the green ▶ Start Debugging button to launch a debug instance of the app.
- Set breakpoints and step through the code as you investigate.
- Open Folder → choose the folder named
- Read the source to find the vulnerabilities.
- Write your exploit. The target app is at
http://<vm-ip>/(port 80). Write a script (Python recommended) that automates the whole chain — unauthenticated → admin → remote code execution — and, at the RCE step, fires a reverse shell back to anc -lvnp <port>listener on your machine. Running the script should catch you a shell as the app’s user. - Capture
local.txtandproof.txt.