TryHackMe 'Infinity Pool' CTF: Dual Command Injections Lead to Root Access
A TryHackMe capture-the-flag challenge called 'Infinity Pool' centered on a fictional hotel website called 'Byte Lotus', hosted via Gunicorn on port 80. An unsanitized host parameter in an internal network-check tool allowed OS command injection, granting an initial foothold and the user flag. An internally exposed operations console on port 3000 leaked unrotated FreePBX credentials, and accessing its dashboard via SSH port forwarding revealed a bearer token hidden in a caller-ID field. That token authenticated to a root-run automation service on port 9000, whose report parameter was also unsanitized, enabling a second command injection as root. Chaining these two vulnerabilities — both classic command injection flaws stemming from missing input sanitization — ultimately yielded the root flag.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in