FireFlow Writeup - HackTheBox
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
HackIndex
Language
Showing 1–9 of 9
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
Exploiting a cloud misconfiguration in a hard Linux HackTheBox machine involving AWS/cloud enumeration, privilege escalation through misconfigured services.
Exploit MongoDB misconfiguration with unauthenticated access to enumerate databases and retrieve credentials, ultimately gaining root on an easy Linux box.
Exploit a Flask SSTI vulnerability in a developer hub app to gain RCE, then escalate privileges via misconfigured sudo or SUID binaries on Linux.
Windows medium box involving log analysis and exploitation of logging mechanisms to gain foothold and escalate privileges through misconfigured services.
Easy Windows box involving LDAP enumeration, custom binary reverse engineering to extract credentials, and Kerberos resource-based constrained delegation abuse for SYSTEM.
Exploiting JWT algorithm confusion and SSTI vulnerabilities on a Linux machine to escalate privileges and capture the flag.
Exploit a Pterodactyl game panel via subdomain enumeration, command injection, and privilege escalation to root on this medium Linux box.
SQL injection in Cacti leads to RCE, followed by port forwarding and privilege escalation techniques to fully compromise this Windows machine.
Other platforms
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.