PROJECT REPORT

HACK THE BOX NeuroSync | NeuroSync™ is a leading suite of products focusing on developing cutting edge medical BCI devices, designed by the Korosaki Coorporaton

$19.00
Secure checkout
Instant digital download
PDF document

Document details

Pages
29
File size
1.66 MB
Format
Digital PDF
About this ebook
NeuroSync 25th March 2025 Difficulty: Hard Classification: Official Synopsis Next.JS authentication bypass (CVE-2025-29927) => Curl SSRF => LFI with filter bypass => Leakage of secret => Redis injection => Issuing of arbitrary commands via crafted signature => RCE Description NeuroSync™ is a leading suite of products focusing on developing cutting edge medical BCI devices, designed by the Korosaki Coorporaton. They recently fell victim to an APT group which exploited an N-day vulnerability on their infrastructure and was able to hijack a big number of online devices. The admins were locked out of their systems and your task is to discover and use the same techniques the hackers used in order to recover the accessibility of the control panel. Skills Required Understanding of NodeJS and Golang Understanding of Redis Intermediate knowledge of web vulnerabilities Skills Learned Exploiting an authentication bypass N-day in Next.JS Abusing SSRF Abusing LFI via filter bypass Abusing curl's gopher protocol to send arbitrary commands to redis Crafting fake signatures using leaked secrets Issuing arbitrary commands to cause RCE on distributed devices

File included

PDF
NeuroSync.pdf.pdf 1.66 MB

Topics