Chaos HackTheBox (Writeup)
Reconnaissance:





Exploitation
Port 80 - Web Enumeration



Fuzzing des Directoires




WordPress Enumeration


Password Guessing

Port 993/995 - Webmail




Decrypt Secret Message - AES Encrypted


On execute:


LaTeX Injection Vulnerabilité
LaTeX Injection (file reader)



Document PDF LaTeX:


Exploitation RCE via LaTeX

Reverse Shell

Élévation de Privilège
Pivoting User Ayush - Bypass rbash



Flag user.txt :)

Extraction des Credentials Firefox





Flag root.txt


Mis à jour
