The Rocket machine presents a layered, multi-service attack surface that rewards methodical enumeration and precise exploit chaining. The entry point is a Rocket.Chat 3.12.1 instance exposed on a virtual host, vulnerable to CVE-2021–22911 — an unauthenticated NoSQL injection in the password reset flow that allows an attacker to extract valid reset...