HackTheBox - Editor @ippsec
HackTheBox - Editor  @ippsec
Uploaded December 2025 | Updated September 2026, 3 weeks ago
00:00 - Introduction
00:40 - Start of nmap
04:10 - Noticing the docs link which directs us to xwiki which discloses its version, searching for vulnerabilities
06:20 - Looking into XWIKI CVE-2025-24893
10:00 - Got Code Execution, getting a reverse shell now
15:45 - Finding the xwiki config, getting a password, which lets us SSH as oliver but oddly cannot use SU (go into this at the end of the video)
22:10 - Finding a vulnerable SetUID File, ndsudo from netdata. Vulnerable to Path Injection, lets exploit it
27:40 - Just talking about SetUID vs Sudo
31:40 - Digging into why we could not run SU
36:34 - Why we couldn't run SU, the SystemD Unit file has NoNewPrivileges
HackTheBox - EditorHackTheBox - InfiltratorHackTheBox - BlurryHackTheBox - IntentionsHackTheBox - DogHackTheBox - ResourceHackTheBox - VisualHackTheBox - AirTouchHackTheBox - SorceryHackTheBox - CompiledHackTheBox - PilgrimageHackTheBox - Outbound
IppSec |

HackTheBox - Editor

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER