HTB Writeup – MonitorsFour
Posted on 2025-12-07
CVE-2025-24367 (Cacti Auth RCE), CVE-2025-9074 (Docker Desktop Escape)
Hackthebox CTF writeups.
CVE-2025-24367 (Cacti Auth RCE), CVE-2025-9074 (Docker Desktop Escape)
SQL injection abusing PDO substitution in PHP Prepared Statement
BadSuccessor attack by creating a malicious dMSA object in AD
Transform XSLT to HTML with extensions → special XML “SSTI”
There is no excerpt because this is a protected post.
Ticket Forgery & Token Abuse with a service account in Win AD
From bi-directional MSSQL linked servers in to CVE-2024-30088 LPE