HTB Writeup – Giveback
Posted on 2025-11-02
Exploit Kubernetes cluster & container abuse
Transform XSLT to HTML with extensions → special XML “SSTI”
Exploit IKE IPSec via UDP discovery & the SUDO binex privesc
Python SSTI and Django Cache poisoning with Pickle Deserialization
CrushFTP auth bypass (CVE-2025-31161) and Erlang shell manipulation
Next.js auth bypass (CVE-2025-29927) & Hashicorp Terraform abusing
CVE-2024-47533: Cobbler XML-RPC flaw to steal root files