iconBjarne Verschorre

  1. Blog
  2. Write-ups
  3. Private
../hackthebox/

#hackthebox

🔒 Total withheld posts: 2


Usage

Webpage with SQLi and file upload vulnerability. Escalate to root by abusing a script that runs as sudo.


Perfection

A Ruby webserver with a template injection vulnerability, leading to a reverse shell and brute-forcing hashes for a privilege escalation to root.


Headless

Simple webserver with a contact form vulnerable to XSS. Escalate to root by abusing a script that runs as sudo.