pentesteasy

Том (Tom)

hackerlab

Task: Pentest machine with Tomcat and Flask log viewer. Solution: LFI in Flask app to read tomcat-users.xml, WAR deployment for RCE, SUID make for privilege escalation to root.

$ ls tags/ techniques/
lfi_exploitationtomcat_manager_rcesuid_make_privescwar_webshell

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]