River

  • Home
  • Archive
  • Categories
  • Tags
  • Search
  • 2026

  • 2026-03-26
    HackTheBox: Kobold

    exploiting CVE-2026-23744 unauthenticated RCE in MCPJAM, pivoting through container bind mounts to leak PrivateBin config, then using Arcane to spin up a root container

  • 2026-03-20
    HackTheBox: Wingdata

    exploiting CVE-2025-47812 lua injection in WingFTP for RCE, cracking a salted sha256 hash, then abusing CVE-2025-4138 PATH_MAX overflow to escape tarfile filter and get root

  • 2026-02-10
    HackTheBox: Pterodactyl

    exploiting a Pterodactyl game panel via path traversal, PAM environment poisoning, and a udisks2 XFS resize bug to get root

Copyright © 2024-2026 River
  • Home
  • Archive
  • Categories
  • Tags
  • Search