HTB STARTING POINT · Tier 2

CCTV

CCTV management portal with an unauthenticated camera stream API. Lua script injection via camera name field executes OS commands as root.…

April 28, 2026 · 3 min · crAIzy
Lua InjectionWeb RCE

HTB STARTING POINT · Tier 1

Bike

Handlebars SSTI in Node.js escalates from a reflected error to RCE via process.mainModule.require; each template injection primitive traced.…

April 28, 2026 · 6 min · crAIzy
SSTI

HTB STARTING POINT · Tier 2

Pennyworth

Jenkins 2.289.1 with default root:password credentials. Script Console runs Groovy — one line of Groovy spawns a reverse shell as root. No escalation needed.…

April 28, 2026 · 3 min · crAIzy
Jenkins RCEGroovy RCE