TGViewer
OpenBSD OpenBSD @openbsd · 1.23K subscribers
Post #243 1.05K
OpenBSD Authentication Bypass | HTTP Header Tampering | Kernel OS Local Root Exploit

Summary. User - This machine is running an OpenBSD httpd site which has a login portal with only a sign-in feature working. Upon research, it was found to have a vulnerability that exposes the user’s private key enabling us to login using SSH. Root - A local exploit was found for openbsd; executing which gave me the root!

https://medium.com/bugbountywriteup/htb-openkeys-writeup-531264648200

#security
More from @openbsd
  1. Oct 22, 2025OpenBSD 7.8 released. #release
  2. Oct 22, 2025Channel photo updated
  3. Sep 14, 2025How to perform common FreeBSD tasks on OpenBSD. This post will serve as reminder for mysel…
  4. Sep 14, 2025Adventures in porting a Wayland Compositor to NetBSD and OpenBSD. #video #wayland
  5. Apr 28, 2025OpenBSD 7.7 released! #release
  6. Apr 28, 2025Channel photo updated
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →