<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/web/</link><description>Recent content in Web on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Mon, 19 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/web/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB-Conversor</title><link>https://hexpysya.github.io/investigations/htb-conversor/</link><pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-conversor/</guid><description>Flask web application vulnerable to path traversal during file uploads. Exploited by uploading Python reverse shell to cron-executed directory → gained www-data shell → extracted MD5 hashes from SQLite database → cracked password for user fismathack → leveraged CVE-2024-48990 in needrestart 3.7 for privilege escalation to root.</description></item></channel></rss>