pentestProeasy
Том (Tom)
hackerlab
Task: Pentest machine with Tomcat and Flask log viewer. Solution: LFI in Flask app to read tomcat-users.xml, WAR deployment for RCE, SUID make for privilege escalation to root.
$ ls tags/ techniques/
lfi_exploitationtomcat_manager_rcesuid_make_privescwar_webshell
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Обычная страница— hackerlab
- [infra][Pro]Воллхак (Wallhack)— hackerlab
- [web][Pro]Simple Web (d5c47306-5d4f-4ad4-958f-5414a0b85b9b)— hackerlab
- [infra][Pro]Кто там?— hackerlab
- [web][Pro]SWE Intern at Girly Pop Inc — Writeup— scarlet