logo

Player2 HacktheBox Writeup

ID: d3dd58e1-ff5b-56b7-904f-005c151876fe

STIX ID: report--d3dd58e1-ff5b-56b7-904f-005c151876fe

Feed Name: Will's Root

Threat Score
60/100

Date Published: 2020-06-27

Date Updated: 2026-04-19

Author: Unknown

...
...

This write-up documents a full technical walkthrough of compromising the Player2 HTB machine: enumerating services (Twirp RPC, web, MQTT), generating and using credentials via a Twirp GenCreds RPC, bypassing TOTP with backup codes and a type-juggling trick, extracting and patching a signed firmware ELF to execute a reverse shell, capturing an SSH private key leaked over MQTT to access a user account, and finally achieving root via a complex heap exploit (poison null byte, UAF and tcache poisoning) with included PoC exploit scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.