Hack The Box: Chemistry Machine Walkthrough – Easy Difficulty

A vulnerability in **Pymatgen (CVE-2024-23346)** allowed for **Remote Code Execution (RCE)** through a **malicious CIF file**. By injecting code into the **_space_group_magn.transform_BNS_Pp_abc** field and uploading it to the dashboard, nothing happened initially. However, clicking the **View button** triggered execution, leading to a **reverse shell**. With remote access secured, an **SQLite3 database** was explored, revealing **password hashes**, which were cracked to obtain valid credentials and retrieve the **user flag**.

Further exploration uncovered an **aiohttp/3.9.1** service running on **port 8080**, restricting access to the **assets directory** with a **403 Forbidden** response. Leveraging an **LFI attack**, an **SSH key** was extracted, allowing for **privilege escalation** and access to the **root flag**.

This scenario highlights the importance of **sanitizing file uploads, restricting directory access, and keeping dependencies updated** to mitigate security risks.

#CyberSecurity #BugBounty #EthicalHacking #PrivilegeEscalation #RedTeam #WebSecurity #InfoSec #CTF

The post Hack The Box: Chemistry Machine Walkthrough – Easy Difficulty appeared first on Threatninja.net.

March 8, 2025
Read More >>

Gaza ceasefire close to collapse as aid stops

The ceasefire in Gaza is perilously close to collapsing. Food shortages have become acute, and Palestinians living in the territory are struggling to feed their families. All aid into the territory has been stopped as Israel pressures Hamas for a deal.

March 8, 2025
Read More >>

High Degree of Collusivity: Indian Army Chief On Pakistan, China

Indian Army Chief General Upendra Dwivedi recently reiterated the need for India to acknowledge a "high degree of collusion" between Pakistan and China. This assertion highlights the strategic and military cooperation between these two nations, which poses a significant threat to India’s security.General Dwivedi noted that in the virtual domain, the collusion is nearly 100%, and physically, most

March 8, 2025
Read More >>