dev.to | 📄 原文链接 | 2026-08-27 收录

TryHackMe:Infinity Pool 靶机 Writeup

来源:dev.to — 2026-08-07

📋 概述

对 Gunicorn 托管的 "Byte Lotus" 酒店站点侦察,发现 robots.txt 禁用了 /internal 和 /status 两条路径。/status 暴露内部员工工具,向 /internal/netcheck 提交 host 参数,后者未过滤就传给 ping,造成 OS 命令注入,以 web 用户身份拿到初始立足点和 user flag。随后内部 "Watchtower" 运维控制台泄露了未轮换的 FreePBX UCP 默认凭据,登录后在 caller-ID 字段发现泄露的 "Automation Key" bearer token,最终在 /jobs/export 端点通过第二个命令注入提权为 root,拿到 root flag。

🔑 核心要点

💡 金句

未轮换的默认凭据和未过滤的 shell 调用,是两条通往 root 的路。
← 返回 dev.to 首页