Skip to content
CESTOLIV
297 FR

Write-ups

    • en

    Investigation - HackTheBox Machine

    A vulnerability in ExifTool allows a reverse shell, and the analysis of a binary allows a privilege escalation

    • en

    BountyHunter - HackTheBox Machine

    An XEE vulnerability in a form will allow us to read the connection script to the database and retrieve the identifiers

    • en

    Explore - HackTheBox Machine

    A vulnerability in the Android ES File Explorer application allows us to access the smartphone's file system. Then ADB will allow us to take control of it.

    • en

    Cap - HackTheBox Machine

    The traffic analysis with Wireshark will allow us to find FTP identifiers. Then it's a simple python privilege escalation that will give us the control of the machine.