HTB STARTING POINT · Tier 2
CCTV
CCTV management portal with an unauthenticated camera stream API. Lua script injection via camera name field executes OS commands as root.…
HTB STARTING POINT · Tier 2
CCTV management portal with an unauthenticated camera stream API. Lua script injection via camera name field executes OS commands as root.…
HTB STARTING POINT · Tier 1
Handlebars SSTI in Node.js escalates from a reflected error to RCE via process.mainModule.require; each template injection primitive traced.…
HTB STARTING POINT · Tier 2
Jenkins 2.289.1 with default root:password credentials. Script Console runs Groovy — one line of Groovy spawns a reverse shell as root. No escalation needed.…