HTB Writeup – Certified
Posted on 2024-11-03
Post-exploitation on AD CS, with PKINITtools and abusing ESC9
Capture the flags!
Post-exploitation on AD CS, with PKINITtools and abusing ESC9
There is no excerpt because this is a protected post.
Deserialization for pymatgen & Directory Traversal on aiohttp
LFI, JWT Forgery, SQLi, Crontab abuse, Mercurial hook, Rsync privesc
High level GLIBC I/O operation exploit: Largebin Attack + FSOP
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
Exploit H2 Database for Java web app & abuse Apache Thrift
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging