<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ssti on 0xMesbaha</title>
    <link>https://hussienmisbah.github.io/tags/ssti/</link>
    <description>Recent content in Ssti on 0xMesbaha</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 25 Jul 2022 12:49:18 +0200</lastBuildDate>
    <atom:link href="https://hussienmisbah.github.io/tags/ssti/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Flushed Emoji challenge Writeup</title>
      <link>https://hussienmisbah.github.io/posts/web-exploitation/2022-07-25-flused-emoji/</link>
      <pubDate>Mon, 25 Jul 2022 12:49:18 +0200</pubDate>
      <guid>https://hussienmisbah.github.io/posts/web-exploitation/2022-07-25-flused-emoji/</guid>
      <description>&lt;p&gt;Lexington Informatics Tournament CTF CTF 2022 was held from the 22nd of July Until the 25th of the month , and we have participated under the team 0xcha0s, we have managed to solve multiple challenges. this challenge was solved less than 50 times in the 3 days and it was really nice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bolt Hackthebox writeup</title>
      <link>https://hussienmisbah.github.io/posts/linux-machines/2022-02-18-bolt/</link>
      <pubDate>Fri, 18 Feb 2022 00:45:12 +0200</pubDate>
      <guid>https://hussienmisbah.github.io/posts/linux-machines/2022-02-18-bolt/</guid>
      <description>&lt;p&gt;In this Hackthebox we will go analyze a docker img files and from there will find some juicy stuff will help us login to a vhost &amp;ldquo;demo&amp;rdquo; which has some functions aren&amp;rsquo;t in the main web application , from there we will exploit SSTI and gain low-privilege shell as www-data , during box enumeration we will find some passwords in the system which will let us get a user access , after that we will connect to a mysql database then will find a PGP encrypted message , somehow will gain the user private gpg key to decrypt the message which contains the root password .&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
