Join me as I take down Book! This box had some stability issues, but was a great introduction to LFI via XSS on dynamic PDFs. Combining that with SQL truncation, we’ll gain foothold and use the Logrotten exploit to get a root shell.
#HackTheBox #HTB #Book #BridgingTheGap