HTB Writeup – Sightless
Posted on 2024-09-09
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor
CVE-2023-41425 for WonderCMS RCE with malicious themes module.
Pluck CMS RCE, and fun Depix to reveal pixelized passwords.
Cloud hacking: MinIO, Vault, Symlink Race, Linux MOTD Hijack