HTB Writeup – Sightless
Posted on 2024-09-09
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
LargeBin Attack is the future for heap exploitation.
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor
CVE-2023-41425 for WonderCMS RCE with malicious themes module.
There is no excerpt because this is a protected post.
CVE-2024-32002 for Git RCE, CVE-2024-20656 for Visual Studio PE
A classic example for Hash Length Extension Attack.
Pluck CMS RCE, and fun Depix to reveal pixelized passwords.