Command-Injection
Jarvis — HTB Medium Writeup & Walkthrough
Writeup de Jarvis (HTB Medium) : injection SQL, accès à phpMyAdmin, passage de www-data à pepper et escalade vers root via systemctl SUID.
Precious — HTB Easy Writeup & Walkthrough
Writeup de Precious (HTB Easy) : exploitation pas à pas de pdfkit 0.8.6, récupération d’identifiants et escalade sudo via YAML.load.