1xTrashPanda@127.0.0.1:~/home/new_posts  
[ PID: 2535 ]

Helix - CTF

Chaining an Apache NiFi H2 Database RCE for initial access to exploit an internal OPC UA service, manipulating PLC safety variables to trigger a conditional sudo privilege escalation for root access.

./view_writeup.sh
[ PID: 4856 ]

Interpreter - CTF

Chaining an unauthenticated Mirth Connect RCE with database credential recovery for initial access to exploit a Python-based server-side template injection for root access.

./view_writeup.sh
[ PID: 1885 ]

DevArea - CTF

Chaining an Apache CXF SSRF with a Hoverfly middleware RCE for initial access to exploit a world-writable system binary for root access.

./view_writeup.sh
[ PID: 5582 ]

Silentium - CTF

Chaining an unauthenticated password reset with a Flowise RCE for initial access to exploit a symlink-based vulnerability in an internal Gogs service for root access.

./view_writeup.sh
[ PID: 6840 ]

MonitorsFour - CTF

Chaining API credential leaks with Cacti command injection, and a Docker api exposure to gain root access.

./view_writeup.sh