Summary Bamboo is a Hackthebox machine that chains together a Squid proxy pivot, an authentication bypass in PaperCut NG (CVE-2023-27350), and a PATH hijack privilege escalation to reach root. The exposed Squid proxy on port 3128 acts as a gateway into internal services. Using the proxy to reac...
Source: [Dev.to](https://dev.to/exploitnotes/hackthebox-bamboo-writeup-ehg)