$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: boot2root machine with exposed .git repo, ProFTPD 1.3.5, and a PHP command panel; flag split across protected files owned by user jonah and root. Solution: dump .git with git-dumper to recover hardcoded admin creds and a shell_exec RCE panel, abuse ProFTPD mod_copy (CVE-2015-3306) SITE CPFR/CPTO to copy jonah's protected files into world-readable /tmp, SSH in, then escalate via a sudo NOPASSWD wildcard (cat /etc/apache2/*) path-traversal to read root's last flag part.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar