Post #52 675 Jan 20, 2021, 22:33 UTC Hack The Box — RopeTwoA write-up for a Hack The Box lab that included a vulnerable kernel module.https://0xdf.gitlab.io/2021/01/16/htb-ropetwo.html 0xdf hacks stuff HTB: RopeTwo RopeTwo, much like Rope, was just a lot of binary exploitation. It starts with a really neat attack on Google’s v8 JavaScript engine, with a couple of newly added vulnerable functions to allow out of bounds read and write. I’ll use that with an XSS vulnerability…