For some reason, I am extremely sure that nodejs will be tested in the OSWE exam (lol). In this case, I would like to practice some nodejs exploits. I notice that the box “Holiday” contains some nodejs code injection exploits, so I just wrap my sleeves and get started. The target machine is Holiday (10.10.10.25), which is a very hard box with 5.0 score. I’m not expecting myself to resolve this box individually, and the goal of working on this box is to learn nodejs in the process.
All articles in this blog are licensed under CC BY-NC-SA 4.0 unless stating additionally.
Comment