October 2, 2026
Orion — Hackthebox writeup
I solved ORION, one of the most famous HTB machines, today. I approached this machine using different methods, exploring the enumeration…

By PRiTi.EX
3 min read
I solved ORION, one of the most famous HTB machines, today. I approached this machine using different methods, exploring the enumeration, exploitation, and privilege escalation steps in detail.
Enumeration:
I do a simple nmap scan:
Got 22(SSH) & a web service is running on 80.
Normally web page it not opens so i add the domain to my /etc/hosts:
Got the web page:
Web Enumeration:
Next, i do directory fuzzing:
got /admin directory with a login page:
It runs on Craft CMS 5.6.16, so i search for its CVE:
It basically allows unauthenticated attackers to execute arbitrary PHP code and gain remote access to the hosting server.
CVE Exploit using msfconsole:
I next use many exploit for this but nothing works. So, i move to msfconsole:
It gives a very large outputs:
But, finally got the meterpreter shell:
So for better interactive i use revershell:
Linux Enumeration:
I take some time & do a simple enumeration:
From .env i got some mysql credentials:
So, i login mysql using these:
From here i got one users table:
I use Use users; to select that tables.
Next, using describe users; got the password and username columns.
Now i have password hash of admin users so i crack it using john:
Privilege Escalation to adam:
Done now i use these credentials in machine for user adam:
Works i am adam user now & i got user.txt flag
From next enumeration i got this machine has runs telnet in locally & it's version is 2.7:
From simple google search i got the CVE for this:
I use it:
USER="-f root" → inject login option telnet -a → pass username/login information localhost → hit Orion's internal Telnet
Got root shell:
Also got the root flag.
Note: You can also use CVE for this or do directly like me.