<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NodeJS on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/nodejs/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 24 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/nodejs/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Reactor</title><link>https://wearethebug.dev/posts/htb-reactor/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-reactor/</guid><description>Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components triggered via a crafted Next-Action header, yielding a shell as node. Credentials are extracted from a SQLite database dump, cracked to reveal valid SSH access for lateral movement to the user engineer. Privilege escalation abuses an exposed Node.js debug port (9229), reached via SSH tunnel, to call process.mainModule.require and execute commands as root.</description></item><item><title>VULNLAB: Store</title><link>https://wearethebug.dev/posts/vl-store/</link><pubDate>Fri, 17 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-store/</guid><description>Store is a Hard difficulty box that hosts a Node.js web application, allowing file uploads and storage. The app is vulnerable to Arbitrary File Read, which lets us read configuration files and recover SFTP credentials. We can also dump the host’s environment variables and discover the app was started with --inspect, with the Node inspector listening on port 9229. By abusing SFTP for port forwarding, we can tunnel that internal inspector port to our machine, attach and run JavaScript to spawn a reverse shell as user dev. For privilege escalation, the ChromeDriver service on port 9515 can be abused via its WebDriver API to execute a malicious script and gain a root shell.</description></item></channel></rss>