Pollution

Overview Machine author: Tr1s0n. IP: 10.10.10.x. Chain: forum token, escalation to admin, XXE (file / source read), Redis (session replacement), access to developers., LFI + PHP filter chain (RCE as www-data), PHP-FPM / FastCGI (pivot to victor), prototype pollution in a Node.js API (RCE as root). Reconnaissance 1 nmap -sV -sC -p- 10.10.10.x Open: 22 (SSH), 80 (HTTP). Redis (6379) is local only / password protected. 1 10.10.10.x collect.htb developers.collect.htb The vhost developers.collect.htb is protected by Basic Auth. ...

PollutionLinuxHard
September 6, 2026 · 5 min

RedPanda

Overview Ubuntu 20.04. IP: 10.10.10.x. Topics: SSTI (Spring Boot), log poisoning, path traversal, XXE, source code review. Chain: SSTI in the search box, shell as woodenk, credentials in the source, SSH, analysis of a root cron job (a Java jar), a four-vulnerability chain (log poisoning + path traversal + metadata-driven path injection + XXE), the root SSH key, root. Reconnaissance 1 2 ports=$(nmap -p- --min-rate=1000 -T4 10.10.10.x | grep '^[0-9]' | cut -d '/' -f 1 | tr '\n' ',' | sed s/,$//) nmap -p$ports -sV 10.10.10.x 22/tcp: OpenSSH 8.2p1 (Ubuntu) 8080/tcp: HTTP (http-proxy) HTTP (port 8080): ...

RedPandaLinuxEasy
September 6, 2026 · 4 min