#HackTheBox #Pentest #Security #Web #NodeJS #SSTI #RCE #Burpsuite #Walkthrough
Write-up for HackTheBox machine named “Bike”
💰 Donation
If you request the content along with the donation, it will be uploaded in preference to the reserved content :)
Buy Me a Coffee: https://www.buymeacoffee.com/devsecops91
Toonation: https://toon.at/donate/devops
[Timestamp]
00:00 Port Scanning
01:00 Check that the service is vulnerable to SSTI
02:25 Get SSTI payload
02:56 Send payload after modifying payload and get flag