Json

Community friends!

I’m reaching out a hand here for the initial foothold. I’ve identified the attack vector and also tried shooting my payloads against it, but I just can’t get it to perform any RCE.

So back to roots, I did spend some time to setup a local target environment and I have successfully got RCE on that system.

I have double/triple checked everything, but there must have been something I have missed here on json.htb.

Any help would be greatly appreciated!

I’ll share details of my findings in PM if needed :slight_smile:

EDIT: rooted.

I used the reversing path to gain root :slight_smile: