A detailed TryHackMe CTF walkthrough for the 'Rocket' machine (Hard difficulty, Ubuntu 18.04). The attack chain starts with CVE-2021-22911, a blind NoSQL injection in Rocket.Chat 3.12.1's password reset flow, used to extract reset tokens character by character and take over the admin account. A webhook delivers a reverse shell
Table of contents
2. Initial Access — CVE-2021–22911 NoSQL Injection to Rocket.Chat RCE2.1 Version Confirmation2.2 Account Registration and User Enumeration2.3 Blind NoSQL Token Extraction2.4 Admin Takeover and Webhook ShellSort: