SnakeYAML, Go & WebAssembly - Ophiuchi @ HackTheBox

Опубликовано: 16 Октябрь 2024
на канале: vulnlab
1,433
77

We are going to solve Ophiuchi a 30-point machine on HackTheBox that involves a YAML parser vulnerability and a custom program we can execute with sudo, which loads a web assembly file and executes a shell script without using the absolute path.

Join the discord:   / discord  !

[ Timestamps ]
00:00 Intro
00:19 User
04:00 Root

[ Notes & Links ]
• https://www.hackthebox.eu/

[ Desktop ]
• https://github.com/xct/kali-clean

[ About ]
• https://vulndev.io
•   / xct_de  
• https://github.com/xct
• https://vulnlab.com

This is purely educational content - all practical work is done in environments that allow and encourage offensive security training.