<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CTF Walkthroughs on HomeBrewedHacker</title>
    <link>/tags/ctf-walkthroughs/</link>
    <description>Recent content in CTF Walkthroughs on HomeBrewedHacker</description>
    <image>
      <title>HomeBrewedHacker</title>
      <url>/images/papermod-cover.png</url>
      <link>/images/papermod-cover.png</link>
    </image>
    <generator>Hugo -- 0.151.0</generator>
    <language>en</language>
    <copyright>PaperMod Contributors</copyright>
    <lastBuildDate>Tue, 20 Jun 2023 10:48:02 -0700</lastBuildDate>
    <atom:link href="/tags/ctf-walkthroughs/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Hack The Box Precious Machine Walkthrough</title>
      <link>/posts/htb-precious/</link>
      <pubDate>Tue, 20 Jun 2023 10:48:02 -0700</pubDate>
      <guid>/posts/htb-precious/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;
&lt;p&gt;Welcome to my first Hack The Box machine walkthrough.  This system is one that I had the privilege of doing live and am now going to
post my process of popping root since the machine has since retired.  Here is a quick overview of the machine as stated directly
from &lt;a href=&#34;https://app.hackthebox.com/machines/Precious/information&#34;&gt;HTB&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Precious is an Easy Difficulty Linux machine, that focuses on the &lt;code&gt;Ruby&lt;/code&gt; language.
It hosts a custom &lt;code&gt;Ruby&lt;/code&gt; web application, using an outdated library, namely pdfkit, which is vulnerable to &lt;code&gt;CVE-2022-25765&lt;/code&gt;,
leading to an initial shell on the target machine. After a pivot using plaintext credentials that are found
in a Gem repository &lt;code&gt;config&lt;/code&gt; file, the box concludes with an insecure deserialization attack on a custom, outdated, &lt;code&gt;Ruby&lt;/code&gt; script.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
