Summary
Meta was a Medium difficulty Linux box created by Nauten. Initial foothold on the box was to find RCE in exiftool
and uploading the modified image with payload to get a shell we get a shell as www-data
. Running pspy we see an cron running every minute with a script running we upload a modified svg and we get a shell as user. Rooting the box was pretty simple with just modifying the XDF_CONFIG_HOME
and running neofetch
with sudo and we get a shell as root.