Skip to main content
Room Banner
Back to all walkthroughs
Room Icon

Looney Tunables

Max room.

CVE-2023-4911: That's all Sec-Folks!

medium

60 min

5,891

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

The identifier -2023-4911 has been assigned to The Qualys Threat Research Unit (TRU) (opens in new tab) on October 3, 2023, due to a critical security flaw in the GNU C Library's dynamic loader, known as ld.so. This vulnerability poses a significant risk since it allows escalating the privileges of a logged-on user and obtaining full control of the vulnerable instance.  

This vulnerability was introduced in glibc version 2.34 through commit 2ed18c. The vulnerability affects recent versions of major Linux distributions such as RHEL, Ubuntu, Fedora, Debian, Amazon Linux, Gentoo and any other distribution that uses glibc.

To deploy the attached VM, press the green Start Lab Machine button at the top of the task and connect to the machine via with the following credentials:

THM key
Usernamenopriv
PasswordPassword321
Answer the questions below
Click and continue learning!