<- HTB


8 minutes to read

Hack The Box. Linux. Easy machine. This machine contains a web application that uses a tool to create PDF documents which is vulnerable to command injection, which leads to Remote Code Execution (RCE). Then, we can find plaintext credentials to switch to another user. And this user has sudo permissions to run a Ruby script that is vulnerable to insecure deserialization in YAML, which can be used to execute commands as root