Enumeration

1
export target=10.129.229.88

Port Scanning

1
rustscan -a $target --ulimit 10000 -g
1
nmap -Pn -sC -sV -n -p22,80 -T5 $target

Add cozyhosting.htb to hosts

1
echo "10.129.229.88    cozyhosting.htb" | sudo tee -a /etc/hosts

Web Application (80)

Portfolio page

There is a login page as well:

Vhost fuzz

1
ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u http://cozyhosting.htb/ -H 'Host: FUZZ.cozyhosting.htb' --ac

Nothing shows up.

1
dirsearch -u http://cozyhosting.htb/

A lot of output, but the actuator is interesting:

Observe that this application is a Spring Boot application.

From actuator/sessions, we get a username and its session:

We can hijack this sesion by adding it to our cookie

And we are in:

There is a connection functionality sending a POST request executessh

Initial Foothold

We can try to inject OS commands: When injecting ; to username, app treats the IP as a command:

Whitespaces are not allowed, so we have to bypass it with either bracket expansion, IFS, or %09 tab.

My payload:

The app jar file, transfer it to host:

In application.properties, there is a postgre database connection credential:

With the credential, we connect to the database via reverse shell and get the admin’s password hash:

Crack the hash with john:

Then SSH as josh with the password:

Privilege Escalation

josh can run ssh with root privileges

GTFOBins:

bum

Key Takeaways

  • In Spring Boot applications, check /actuator endpoints; actuator/sessions can leak active session tokens for session hijacking.
  • When whitespace is filtered in OS Command Injection, use bypass techniques like ${IFS}, %09 (tab), or {echo,payload}.
  • If sudo -l output contains a binary found on GTFOBins (ssh, vim, find, etc.), apply the abuse method for a direct root shell.