<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>File Descriptor Leak on bokkapig</title><link>https://bokkapig.pages.dev/tags/file-descriptor-leak/</link><description>Recent content in File Descriptor Leak on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 11 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/file-descriptor-leak/index.xml" rel="self" type="application/rss+xml"/><item><title>Paperwork</title><link>https://bokkapig.pages.dev/writeups/paperwork/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/paperwork/</guid><description>The Intake Portal on paperwork.htb hands out its own source as paperwork-archive-v1.02.zip, and server.py interpolates the RFC 1179 &amp;lsquo;J&amp;rsquo; control-file field straight into a shell=True Popen — unauthenticated RCE on the custom LPD daemon on tcp/1515 as lp (its queue check is a substring test that an empty queue passes). Loopback-only jetdirect.py on 127.0.0.1:9100, a fake HP LASERJET 4ML running as archivist, normpath-joins attacker paths onto /home/archivist/printer with no containment check, so PJL FSUPLOAD/FSDOWNLOAD read user.txt and plant an SSH key in archivist&amp;rsquo;s authorized_keys. Root: paperwork-daemon holds an fd on root-only /etc/paperwork/admin_pins.conf and hands it to any archivist-group client over mgmt.sock via SCM_RIGHTS whenever its log looks malicious, leaking ADMIN_PASSWORD for a straight su. Every service is custom to the box — no CVEs.</description></item></channel></rss>