Protected: HTB Writeup – University
Posted on 2024-10-28
There is no excerpt because this is a protected post.
There is no excerpt because this is a protected post.
LFI, JWT Forgery, SQLi, Crontab abuse, Mercurial hook, Rsync privesc
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
Exploit H2 Database for Java web app & abuse Apache Thrift
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
LargeBin Attack is the future for heap exploitation.
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor