
TryHackMeMedium
TryHackMe: Interceptor
Two-factor login bypassed via OTP mass assignment (brute force also works, but was not the intended path), then a curl-injection bug in a feed importer used to read /var/www/user.txt off the box.
- #web
- #mass-assignment
- #brute-force
- #rce