Skip to content

#BoxFriday27 - Backfire (Medium)

Photo of Fraiser Kilonzo
Hosted By
Fraiser K. and 3 others
#BoxFriday27 - Backfire (Medium)

Details

Join us for this week’s HTB KE Meetup as we dive into the Backfire (Medium) box on Hack The Box!
In this session, our guest speaker—a skilled cybersecurity and digital forensics expert—will walk us through how to exploit an exposed Havoc C2 server using Server-Side Request Forgery (SSRF) to gain Remote Code Execution via its WebSocket API. We’ll then pivot to another local C2, Hardhat, and craft a malicious JWT token using a default hardcoded secret. To wrap it up, we’ll explore how to escalate privileges by abusing `iptables` commands to achieve arbitrary file write.

Photo of Hack The Box Meetup: Kenya group
Hack The Box Meetup: Kenya
See more events
Online event
Link visible for attendees
FREE