For some reason, I am extremely sure that nodejs will be tested in the OSWE exam (lol). In this case, I would like to practice some nodejs exploits. I notice that the box “Holiday” contains some nodejs code injection exploits, so I just wrap my sleeves and get started. The target machine is Holiday (10.10.10.25), which is a very hard box with 5.0 score. I’m not expecting myself to resolve this box individually, and the goal of working on this box is to learn nodejs in the process.