对 Gunicorn 托管的 "Byte Lotus" 酒店站点侦察,发现 robots.txt 禁用了 /internal 和 /status 两条路径。/status 暴露内部员工工具,向 /internal/netcheck 提交 host 参数,后者未过滤就传给 ping,造成 OS 命令注入,以 web 用户身份拿到初始立足点和 user flag。随后内部 "Watchtower" 运维控制台泄露了未轮换的 FreePBX UCP 默认凭据,登录后在 caller-ID 字段发现泄露的 "Automation Key" bearer token,最终在 /jobs/export 端点通过第二个命令注入提权为 root,拿到 root flag。