Redcross

Again THX for this box. Was awesome but I didn’t like it too much

My Hints

this machine is 2 by 1, to the first part don’t discard the params in POST requests (this will give you RCE)

to get root you need verify app and credentials, enumerate (as usual). When you find the other users, just create yours and give it to him status. Then verify the process executing on the machine and read the forum XD