$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Pentest machine with web service and SSH. Solution: Default credentials on BoidCMS, CVE-2023-38836 file upload bypass with .phtml, MD5 hash cracking, privilege escalation via PHP cap_setuid capability.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar