HTB STARTING POINT · Tier 2

Base

PHP strcmp() fed an array instead of a string returns 0 and bypasses login. A file manager upload gives shell. sudo find reads root.txt while find runs as root.…

April 27, 2026 · 3 min · crAIzy
PHP Type JugglingSudo Abuse

HTB STARTING POINT · Tier 2

Vaccine

Anonymous FTP yields a ZIP cracked with john. The PHP login is SQL-injectable. pg_dump in a sudo rule lets vi escape to root — classic sudo abuse.…

April 27, 2026 · 3 min · crAIzy
SQLi Auth BypassSudo Abuse