<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Password-Reuse on bokkapig</title><link>https://bokkapig.pages.dev/tags/password-reuse/</link><description>Recent content in Password-Reuse on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Tue, 04 Aug 2026 14:45:21 +0100</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/password-reuse/index.xml" rel="self" type="application/rss+xml"/><item><title>Reactor</title><link>https://bokkapig.pages.dev/writeups/reactor/</link><pubDate>Tue, 04 Aug 2026 14:45:21 +0100</pubDate><guid>https://bokkapig.pages.dev/writeups/reactor/</guid><description>A ReactorWatch monitoring dashboard on port 3000 runs Next.js 15.0.3 with React 19.0.0 — vulnerable to React2Shell (CVE-2025-55182 / CVE-2025-66478), an unauthenticated RCE in the React Server Components Flight deserializer. A POST to / carrying a Next-Action header and a forged circular Flight chunk reaches Function via $1:constructor:constructor, giving code execution as the node service account. The app&amp;rsquo;s world-readable SQLite database yields engineer&amp;rsquo;s MD5 password hash, reused verbatim for SSH. Root comes from a root-owned uptime-monitor systemd unit launched with &amp;ndash;inspect=127.0.0.1:9229: the Node debug port is an unauthenticated root eval primitive, driven over the Chrome DevTools Protocol.</description></item><item><title>Silentium</title><link>https://bokkapig.pages.dev/writeups/silentium/</link><pubDate>Sat, 11 Apr 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/silentium/</guid><description>A staging Flowise 3.0.5 instance leaks a live password-reset token straight back in the /api/v1/account/forgot-password response (CVE-2025-58434), giving instant takeover of the &lt;a href="mailto:ben@silentium.htb"&gt;ben@silentium.htb&lt;/a&gt; admin account. Authenticated, the Custom MCP node&amp;rsquo;s mcpServerConfig (CVE-2025-59528) spawns arbitrary processes, yielding root inside the Flowise container — whose environment block hands over SMTP_PASSWORD, reused verbatim as ben&amp;rsquo;s system password over SSH. Root comes from a second internal app: Gogs 0.13.3 running as root with open registration, where CVE-2025-8110 lets the contents API write through a committed symlink to overwrite the repository&amp;rsquo;s pre-receive hook, executed as root on the next push.</description></item><item><title>Kobold</title><link>https://bokkapig.pages.dev/writeups/kobold/</link><pubDate>Sat, 21 Mar 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/kobold/</guid><description>MCP Inspector STDIO RCE for foothold, PHP code injection in PrivateBin container to leak credentials, Docker escape via Arcane container management.</description></item></channel></rss>