HTB Writeup – Alert
Posted on 2024-11-25
Classic XSS + LFI exploit combination
Extract information from a Blockchain in Web3 & exploit Foundry cmds
Red Teaming practice on GenericWrite with Targeted Kerberoasting Attack
Post-exploitation on AD CS, with PKINITtools and abusing ESC9
There is no excerpt because this is a protected post.
LFI, JWT Forgery, SQLi, Crontab abuse, Mercurial hook, Rsync privesc
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
Exploit H2 Database for Java web app & abuse Apache Thrift