Skip to main content
Qubicweb logo

HackTheBox - Reactor

October 3, 2026

Description

00:00 - Introduction 00:55 - Start of nmap 02:45 - Looking at the page source, do see react in the JavaScript Source. Then installing React Dev Tools, which gives us the actual version running 05:02 - Doing a recursive wget to download all the source code, cleaning up the javascript and then grepping the version out 08:00 - Running Nuclei which also shows it is vulnerable, looking at the detection script and seeing it exploits it 13:20 - Grabbing a POC off GitHub then proxying the requests module so we can see how the exploit works 15:58 - Stepping through React2Shell talking about the exploit a little bit 19:55 - Getting a reverse shell 22:45 - Discovering Node runs as root, with the inspect flag. Looking into this and finding out we can connect to the port to run commands 26:10 - Showing we skipped a step (finding credentials in a database) 27:30 - Little bit of a rant on some trouble I had with the root step when solving the box

Watch on Original Source

Trust cues for videos

Internal ReadExternal SourceQubicweb AnalysisCommunity signalMixedSource-only