HTB Writeup – Cicada
Posted on 2024-09-29
Windows red teamming machine for beginners.
High level GLIBC I/O operation exploit: Largebin Attack + FSOP
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
ORW ROP chain with magic gadgets to pwn a Sandbox
Exploit H2 Database for Java web app & abuse Apache Thrift
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
LargeBin Attack is the future for heap exploitation.
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor