miscmedium
Chrono Mind
HackTheBox
Task: abuse an AI-themed web service with room-scoped APIs, file-backed context loading, and a code-completion execution endpoint. Solution: chain path traversal into prompt injection to recover the copilot key, then use a minimal Python payload for reliable RCE and flag retrieval.
$ ls tags/ techniques/
path_traversal_exfiltrationprompt_injection_secret_extractionllm_generated_rcemulti_stage_api_chaining
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub to get started.
$ssh [email protected]