Enumeration
| |
Port Scanning
| |
| |

Add cozyhosting.htb to hosts
| |
Web Application (80)
Portfolio page

There is a login page as well:

Vhost fuzz
| |
Nothing shows up.
Directory Search
| |
A lot of output, but the actuator is interesting:

Observe that this application is a Spring Boot application.
From actuator/sessions, we get a username and its session:

We can hijack this sesion by adding it to our cookie

And we are in:

There is a connection functionality sending a POST request executessh

Initial Foothold
We can try to inject OS commands:
When injecting ; to username, app treats the IP as a command:

Whitespaces are not allowed, so we have to bypass it with either bracket expansion, IFS, or %09 tab.

My payload:


The app jar file, transfer it to host:

In application.properties, there is a postgre database connection credential:

With the credential, we connect to the database via reverse shell and get the admin’s password hash:


Crack the hash with john:

Then SSH as josh with the password:

Privilege Escalation
josh can run ssh with root privileges

GTFOBins:

bum
Key Takeaways
- In Spring Boot applications, check
/actuatorendpoints;actuator/sessionscan leak active session tokens for session hijacking. - When whitespace is filtered in OS Command Injection, use bypass techniques like
${IFS},%09(tab), or{echo,payload}. - If
sudo -loutput contains a binary found on GTFOBins (ssh, vim, find, etc.), apply the abuse method for a direct root shell.