Blog
About
Tags
LFI
Aug 3, 23
Hack the Box - Agile
Welcome back! Today we’re going to do the same thing we do every day, Hack the Box! Today’s machine is Agile. This machine is listed as a medium Linux machine. Let’s go!
Apr 29, 23
Hack the Box - Pilgrimage
Nov 26, 22
Hack the Box - RedPanda
RedPanda is an easy Linux machine that features a website with a search engine made using the Java Spring Boot framework. This search engine is vulnerable to Server-Side Template Injection and can be exploited to gain a shell on the box as user woodenk. Enumerating the processes running on the system reveals a Java program that is being run as a cron job as user root. Upon reviewing the source code of this program, we can determine that it is vulnerable to XXE. Elevation of privileges is achieved by exploiting the XXE vulnerability in the cron job to obtain the SSH private key for the root user. We can then log in as user root over SSH and obtain the root flag.
Oct 7, 22
Hack the Box - OpenSource
Oct 9, 21
Hack the Box - Monitors
Nov 7, 20
Hack the Box - Tabby
««
«
1
2
»
»»
Follow me
I hack things and tweet about things...
Search
Results
No results found
Try adjusting your search query