XSS, Deserialization & SeImpersonate - Cereal on HackTheBox

Опубликовано: 24 Апрель 2026
на канале: xct
2,935
128

We are solving Cereal, a 40-point machine on HackTheBox. For user, we will exploit a pretty tricky deserialization vulnerability in a .NET web app. For root, we exploit SeImpersonate.

Join the discord:   / discord  !

[ Timestamps ]
00:00 Intro
00:21 User
20:24 Root

[ Notes & Links ]
• https://www.hackthebox.eu/
• https://notes.vulndev.io/notes/hackth...

[ Desktop ]
• https://github.com/xct/kali-clean

[ About ]
• https://vulndev.io
•   / xct_de  
• https://github.com/xct
• https://vulnlab.com

This is purely educational content - all practical work is done in environments that allow and encourage offensive security training.