Writeup

  • HTB: Inject - Easy
    Exploited image parameter LFI to enumerate system, used Spring Cloud Function vulnerability for initial access, and escalated to root through a writable Ansible playbook.
  • HTB: Stocker - Easy
    Exploited NoSQL injection for login bypass, used HTML injection in PDF generation to leak credentials, and escalated to root via sudo NodeJS privileges.