webmedium

Prison Pipeline

hackthebox_business_ctf_2024

Task: abuse an SSRF in node-libcurl-backed prisoner import to read local files and steal the private Verdaccio token. Solution: publish a compatible malicious prisoner-db update through a local Host-header proxy, let cron install it, then read the written flag back through file:// SSRF.

$ ls tags/ techniques/
ssrf_file_readnpm_package_hijackingverdaccio_token_reusemodule_load_rce

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]