xsspresso
xsspresso
Tags/ SUID

SUID

5 writeups tagged with SUID

WebEasyLinux

HTB — Dog

Backdrop CMS with exposed .git repository leaks DB credentials. Password reuse for SSH. SUID bee binary grants root.

#CMS#Git Disclosure#Password Reuse
Mar 15, 2025HackTheBox
WebMediumLinux

HTB — Magic

Magic Portfolio with SQLi bypass on login. File upload bypass with double extension for PHP webshell. mysqldump credential extraction and SUID sysinfo for root.

#SQLi#File Upload Bypass#SUID
Jan 20, 2025HackTheBox
WebEasyLinux

HTB — BoardLight

Dolibarr CRM CVE-2023-30253 PHP injection for RCE. Enlightenment window manager SUID binary exploit for local privilege escalation to root.

#Dolibarr#CVE-2023-30253#SUID
Jan 19, 2025HackTheBox
MiscEasyLinux

HTB — Irked

UnrealIRCd 3.2.8.1 backdoor for foothold. Hidden steganography in an image reveals credentials. SUID viewuser binary abuse.

#IRC#Backdoor#Steganography
Apr 18, 2022HackTheBox
WebMediumLinux

HTB — Node

Node.js API endpoint exposes hashed admin credentials. MongoDB backup decryption and SUID binary analysis for root.

#Node.js#MongoDB#API
Apr 5, 2022HackTheBox