active Retires: October 15, 2026
Easy
HTB Paperwork Complete Writeup - LPD Command Injection, PJL Path Traversal & SCM_RIGHTS FD Leak
A comprehensive penetration testing guide exploiting a classic shell=True command injection in an LPD print server, leveraging PJL filesystem path traversal to plant an SSH key and pivot to a higher-privileged user, and abusing SCM_RIGHTS ancillary data over a Unix domain socket to leak a root-owned file descriptor and bypass filesystem permissions entirely.
Comments