webmedium
Conversor (Full Box)
hackthebox
Task: Full HackTheBox machine with an XML-to-HTML converter web app and Linux privilege escalation. Solution: Exploited XSLT injection via exsl:document to write a Python reverse shell through a cron job for user access, then used CVE-2024-48990 needrestart PYTHONPATH injection for root.
$ ls tags/ techniques/
rcemd5_crackingprivilege_escalationsource_code_leakxslt_injectionexsl_documentcron_exploitationcve-2024-48990needrestartpythonpath_injection
hash_crackingdatabase_extractionxslt_file_writecron_job_abuseshared_library_injectionconstructor_hijacking
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]