[HTB] Frolic — Writeup

bigb0ss
10 min readFeb 18, 2021

This was an easy difficulty box. Good learning path for:

  • Source Code Review (Client-side JavaScript Authentication)
  • Puzzles — Various Encoding Programming
  • Brute-forcing Password Protected .ZIP File
  • playSMS Malicious .csv File Upload RCE
  • x86 Binary Exploit (NX Enabled; ASLR Disabled; ret2libc Attack)

--

--

bigb0ss

OSWE | OSCE | OSCP | CREST | Lead Offensive Security Engineer — All about Penetration Test, Red Team, Cloud Security, Web Application Security