MD2PDF writeup and attack path
MD2PDF is a easy Linux machine on TryHackMe that I solved myself. This page is my short attack path summary and the techniques it trains.
| Platform | TryHackMe |
|---|---|
| Operating system | Linux |
| Difficulty | Easy |
| Time to user | 2m |
| Time to root | 5m |
| User owned | 2026-08-15 |
| Root owned | 2026-08-15 |
Attack path summary
Inject HTML/iframe tags in markdown to trigger SSRF / local file disclosure when generating PDF.
Techniques
XSS SSRF PDF-Conversion
Track MD2PDF in ZeroBox. Log your progress, notes and flags offline in your browser, and follow the pentest methodology checklist.
MD2PDF belongs to TryHackMe. This page contains only my own notes.