webmedium

Blueprint Heist

hackthebox

Task: Web app with wkhtmltopdf PDF generation, GraphQL API, JWT auth, and EJS templating. Solution: Chain SSRF via wkhtmltopdf to access internal GraphQL, bypass regex SQLi filter with newline, write malicious EJS template via INTO OUTFILE, trigger SSTI for RCE.

$ ls tags/ techniques/
ssrf_via_wkhtmltopdfsqli_regex_bypassejs_ssti_rcejwt_secret_bruteforcegraphql_injectionmysql_into_outfile

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]