FireFlow Writeup - HackTheBox
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
HackIndex
Language
Showing 1–9 of 9
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
Linear programming attack on a custom XOR-based encryption scheme to recover the flag by solving constraints derived from the cipher's operations.
Exploiting a cloud misconfiguration in a hard Linux HackTheBox machine involving AWS/cloud enumeration, privilege escalation through misconfigured services.
Exploit MongoDB misconfiguration with unauthenticated access to enumerate databases and retrieve credentials, ultimately gaining root on an easy Linux box.
Exploit a Flask SSTI vulnerability in a developer hub app to gain RCE, then escalate privileges via misconfigured sudo or SUID binaries on Linux.
SSTI via resume upload, exploiting a Flask/Jinja2 template injection in a smart hiring app to achieve RCE and capture the flag.
A writeup covering enumeration, initial access, lateral movement, and privilege escalation through misconfigurations and internal service abuse.
Exploiting JWT algorithm confusion and SSTI vulnerabilities on a Linux machine to escalate privileges and capture the flag.
Exploit a Pterodactyl game panel via subdomain enumeration, command injection, and privilege escalation to root on this medium Linux box.
Other platforms
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.