A detailed walkthrough of the HackTheBox machine 'Gavel', a Linux box running a PHP auction website. The attack chain involves recovering source code from an exposed .git directory using git-dumper, exploiting a novel SQL injection that bypasses PDO's backtick-quoted prepared statements, cracking a bcrypt hash to access the
Table of contents
Box InfoReconShell as www-dataShell as auctioneerShell as rootBeyond Root - tmp SandboxesSort: