Htb - Dark Runes ((better))

Machine Difficulty: Medium Category: Web, Cryptography, Binary Exploitation, Linux

rune_decoder is a SUID binary that decodes "rune files" (binary format). Analyze with strings and ltrace : htb dark runes

✅ RCE achieved. Get a reverse shell:

Try re-creating the rune_decoder binary and see if you can find a different way to escalate without touching the root flag. Machine Difficulty: Medium Category: Web

Land in /var/www/darkrunes . Find config.py with PostgreSQL creds: db_user: rune_walker , db_pass: s3cr3t_run3s . Access DB: db_pass: s3cr3t_run3s . Access DB: