Enumeration
| |
Port Scanning

Add the domain to hosts:
| |
Web Application (port 80)
We see some kind of search engine:
We see a version info on the footer: Searchor 2.4.0. Let’s search it if it is vulnerable.
After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC.
https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection
Download the PoC:
| |

Run listener:
| |
After executing the exploit, we get the reverse shell:

Get the user flag:

Persistence
Generate a key for ssh:
| |

Add your public key to .ssh/authorized_keys:
| |

Then I can ssh to box:
| |

Privilege Escalation
Let’s run linpeas right away:

We find a .git directory under /var/www/app, inside there is a credential of cody for gitea:

Add the gitea.researcher.htb to hosts, then login as cody:

Also we can try the credential on the current user, to see what we can run as root:
| |

| |
| |
| |
Save it as full-checkup.sh
Script uses relative path, so we can give it our script
Run listener on attack machine then,
| |
Root shell. Bum
Key Takeaways
- The web application’s
.gitdirectory may be accessible; config files frequently contain hardcoded credentials. - Try every credential you find on all users in the system (credential reuse); especially for
su, SSH, and web panel logins. - If a script run via sudo uses a relative path, you can create your own file with the same name to execute as root.