Apache Strut CVE-2024-53677: HackTheBox Strutted

Опубликовано: 08 Август 2026
на канале: Константин Романов: Кибердружинник 🤖
1,069
34

👉 Boost your thinking and skills in information security: https://boosty.to/kiberdruzhinnik

Hello! My name is Konstantin Romanov, and I've been in information security for over 9 years. My journey has included reverse engineering, digital forensics, AppSec/DevSecOps, GenAi redteaming, information security business partnerships—and it's still ongoing.

This channel isn't just videos; it's my public logbook. Here I analyze real-life cases, hone my skills, and share knowledge that can be useful to both beginners and current professionals.

Subscribe if you want to grow in information security together—consciously, consistently, and effectively.
Try harder.

Let's look at an average Linux machine and CVE-2024-53677 in Apache Struts, which allows us to upload an arbitrary JSP file to the server and execute arbitrary code. Privilege escalation is achieved via GTFOBins. We'll be following the official walkthrough from TheCyberGeek.

Machine Solution: https://app.hackthebox.com/machines/S...

Text walkthrough: https://blog.kiberdruzhinnik.ru/2025/...

Announcements on the Telegram channel: https://t.me/kiberdruzhinnik

Support with a boost: https://boosty.to/kiberdruzhinnik

My resources:
https://boosty.to/kiberdruzhinnik
   / @kiberdruzhinnik  
https://rutube.ru/channel/35510579/
https://blog.kiberdruzhinnik.ru