Description
Vaultline is a small-team password manager — a legacy Java service that has been running, and being patched, for years. Members store logins and secrets; an admin manages users and can back up and restore the workspace. It’s solid-looking enterprise software, and reaching code execution demands genuine source review and a real, multi-link exploit chain rather than a lucky payload.
Difficulty vs OSWE: This is OSWE exam level. Vaultline is representative of the difficulty and style of the exam itself — a legacy codebase, a chain you have to construct, and a fully scripted exploit at the end. If you can own this box unaided and automate it cleanly, you’re in exam shape.
Setup
- Download the
VaultlineOVA from Theosec Labs. - Import into VirtualBox — File → Import Appliance, select the
.ova, and import. - Start the VM. At the console login, sign in and find its IP:
- Username:
dev· Password:vaultline(this account has full sudo) - Run
ifconfig(orip a) and note the address (e.g.192.168.56.x).
- Username:
- Open the in-browser IDE. Browse to
http://<vm-ip>:8080(code-server). Password:vaultline— there is no username.- Open Folder → choose the folder named
vaultlineto read the full source. - A Java debug configuration is provided under Run and Debug. Java debugging is attach-based: it connects to the running service (port 5005). You have full sudo on the box, so you can restart the app with the debug agent and step through requests if you want to. Reading the source is the main event.
- Open Folder → choose the folder named
- Read the source to find the vulnerabilities.
- Write your exploit. The target app is at
http://<vm-ip>/(port 80). Write a script (Python recommended) that automates the whole chain — unauthenticated → admin → remote code execution — and, at the RCE step, fires a reverse shell back to anc -lvnp <port>listener on your machine. Running the script should catch you a shell as the application’s service account. - Capture
local.txtandproof.txt.