
Hacker Holidays — Day 2: Room 404
A Flask app leaves .git/ reachable — git-dumper reconstructs the full repo, and a "remove before launch" note in the staging README hands over the flag directly.
- #hacker-holidays
- #web
- #source-code-disclosure
6 writeups

A Flask app leaves .git/ reachable — git-dumper reconstructs the full repo, and a "remove before launch" note in the staging README hands over the flag directly.

Two-factor login bypassed via OTP mass assignment (brute force also works, but was not the intended path), then a curl-injection bug in a feed importer used to read /var/www/user.txt off the box.

White-box Java Spring app: hardcoded/actuator-leaked credentials, a UNION-based SQL injection, mass-assignment privilege escalation to WARDEN, and a commons-collections gadget chain for RCE.
A CeWL-generated wordlist cracks Joomla admin, template editing gets a reverse shell, and hardcoded credentials in an automation script complete a sudo (ALL:ALL) escalation to root.
Drupalgeddon2 (CVE-2018-7600) gets an in-memory shell via Metasploit, then a SUID find binary hands over root through a one-line GTFOBins exploit.
An MD5 hash in a page comment cracks FTP access, a hint file and a Vigenère cipher unlock a CMS admin panel, and a known Subrion CMS RCE leads to root via a hardcoded backup password.