pentestProeasy

Том (Tom)

hackerlab

Task: Pentest machine with Tomcat and Flask log viewer. Solution: LFI in Flask app to read tomcat-users.xml, WAR deployment for RCE, SUID make for privilege escalation to root.

$ ls tags/ techniques/
lfi_exploitationtomcat_manager_rcesuid_make_privescwar_webshell

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups