Helix - CTF
May 15, 2026Chaining an Apache NiFi H2 Database RCE for initial access to exploit an internal OPC UA service, manipulating PLC safety variables to trigger a conditional sudo privilege escalation for root access.
./view_writeup.shChaining an Apache NiFi H2 Database RCE for initial access to exploit an internal OPC UA service, manipulating PLC safety variables to trigger a conditional sudo privilege escalation for root access.
./view_writeup.shChaining an unauthenticated Mirth Connect RCE with database credential recovery for initial access to exploit a Python-based server-side template injection for root access.
./view_writeup.shChaining an Apache CXF SSRF with a Hoverfly middleware RCE for initial access to exploit a world-writable system binary for root access.
./view_writeup.shChaining an unauthenticated password reset with a Flowise RCE for initial access to exploit a symlink-based vulnerability in an internal Gogs service for root access.
./view_writeup.shChaining API credential leaks with Cacti command injection, and a Docker api exposure to gain root access.
./view_writeup.sh