Carnage
Challenge
Port 81 had SQLi (admin' or 1=1--). Port 82 filtered uploads by extension. Burp with an image/png content type and a name.png.php filename slipped past it, and showimg.php?img=../showimg.php leaked the filter source. That caught a shell as duku, with SSH keys and web-root flags. A root-owned tmux session shared with duku’s group was the privesc route.
Flags
thm{5e7ea083245c2971820ee4d00ed74e29}thm{1de4afafdee712c083aff746991d5345}thm{43f20e3ed108dda8c2383e5fa0286854}thm{9ca1408b352ad45b258afd8d3797f85f}