#
Command Injection
2 posts
Enigma — NFS credential leak, OpenSTAManager RCE, and OliveTin command injection to root
Unauthenticated NFS share leaks employee credentials → webmail credential reuse → OpenSTAManager RCE via unrestricted file upload → bcrypt hash cracking → OliveTin argument injection as root → SUID bash.
HTB TwoMillion: A Lesson in API Abuse and Privilege Escalation
JavaScript deobfuscation reveals hidden API endpoints, leading to invite code generation. API route enumeration exposes an admin section with broken access control, enabling self-promotion to admin. Command injection in a VPN generation endpoint provides a shell. A leaked .env file gives SSH credentials, and CVE-2023-0386 (OverlayFS) escalates to root.