Blogs
HTB Season 10: WingData
· 1 min readA Linux Easy machine with an exposed FTP service, some credential work, and a sudo misconfiguration that makes the privesc almost too clean.
HTB: Conversor
· 4 min readA Linux Medium built around a file conversion web app. XSLT injection lets you write files to a cron-watched directory, and a vulnerable needrestart version gets you to root.
HTB Season 10: Pterodactyl
· 1 min readA Linux Medium built around a game server management panel. Exploitation leads through database access all the way to root, with a couple of interesting hops in between.