Feb. 18, 2023, 6:36 a.m. | Dimitar

DEV Community dev.to

This machine took me a couple of days due to its complexity and some minor stuff that were a hassle to get right.


You will find the following vulnerabilities:

- Local File Inclusion

- Command Injection or RCE





Flag 1

I started by looking through the website to get some idea of its functionality. I saw that this is some sort of converter of data, like binary to hex and so on. But the interesting part was this:



If required, …

binary box command command injection complexity data encoding file find flag hack hacking hack the box hackthebox hex inclusion injection local machine medium rce sort vulnerabilities walkthrough website

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Engineer II, Offensive Security Penetration Testing

@ Amazon.com | US, TX, Virtual Location - Texas

Cybersecurity Specialist (Security Engineering)

@ Triton AI Pte Ltd | Singapore, Singapore, Singapore

Information Systems Security Officer (ISSO)

@ ARA | Arlington, Virginia, United States

Lead - IT Risk compliance & Info Security

@ First Advantage | Bengaluru-560042, Karnataka

Embedded VSOC Analyst

@ Sibylline Ltd | Australia, Australia