$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Flask store with gRPC backend, admin bot (Firefox 125.0.1), custom curl with gopher support. Solution: 5-vuln chain — negative price payment bypass triggers bot, path traversal steers bot to admin endpoint, CVE-2024-4367 pdf.js XSS executes JS, CSRF+gopher SSRF calls gRPC DebugService to set eval payload, second bot trigger fires eval for RCE.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar