Dificulty: Hard OS: Linux
Summary:
- paramater tampering to become admin
- discovering new subdomain
- jwt tampering to elevate permissions on API
- discovering SSRF
- SSRF to RCE via laravel tokens
- network recon inside docker
- dumping dockers using Docker Registry API
- exploiting LFI in undocumented API endpoint
- find password in log file for user john ==> user
- sudo perms on python script
- bypass network restricions
- bypass volume restricions
- bypass read only flag ==> root