angstromctf 2023 - WEB

Posted on 02 May 2023 in security • Tagged with security, ctf, web, SSTI • 7 min read

angstromctf 2023

I participated as a solo player to angstromctf 2023. I focused on Web challenges.


Continue reading

HTB: Late

Posted on 22 Aug 2022 in security • Tagged with security, boot2root, HTB, SSTI, SUID, OCR • 3 min read

Late Card

This article is a writeup about a retired HacktheBox machine: Late publish on April 23, 2022 by kavigihan. This box is rated as an easy machine. It implies an OCR function, a SSTI and a SUID binary.


Continue reading

HTB: Doctor

Posted on 07 Feb 2021 in security • Tagged with security, boot2root, HTB, linux, SSTI, Splunk • 5 min read

Doctor card

This is a writeup about a retired HacktheBox machine: Doctor created by egotisticalSW and publish on September 26, 2020. This box is classified as an easy machine. The user part implied a server side template injection and finding a needle in a haystack. The root part required to use a Splunk exploit to elevate our privileges.


Continue reading