$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Windows Server 2016 DC running BoidCMS on Apache/XAMPP with default admin credentials and CVE-2023-38836 file upload RCE. Solution: Used existing webshell to discover Firefox saved passwords for Administrator, then read split flag via PowerShell Invoke-Command with stolen credentials.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar