logo

Hack-From-Home Challenge Walk Through

ID: 44ab687e-574d-5f54-a20a-6bec98ce7bcf

STIX ID: report--44ab687e-574d-5f54-a20a-6bec98ce7bcf

Feed Name: SensePost Blog

Threat Score
65/100

Date Published: 2020-04-24

Date Updated: 2026-04-29

...
...

This SensePost CTF walkthrough documents a multi-step compromise of a vulnerable web application: initial information disclosure and steganography to obtain a first flag, a PHP system() unsanitised command injection leading to remote command execution, discovery and extraction of a flag from an exposed Redis instance, and final privilege escalation to root by abusing sudo permissions for vim.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.