This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
BountyHunter is a fun Linux box on HackTheBox that has XXE injection on a PHP form, which exposes DB credentials. This DB credential is reused as a password for a user on the box. The box also has an internal python3 script which could be run as elevated privileges. This script uses eval by which we get command injection, which leads to superuser access to this box.
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.