This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Previse is a fun Linux box on HackTheBox that has insecure redirect implementation which leaks information on the page. This can then be used to create a new user in the application and get access to backup.zip of it. Backup revels that there is a command injection vulnerability present in the logs fetching feature, which gets us a basic shell. We have a MySQL server running inside the box which…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.