Craft

Overview Craft is a medium-difficulty Linux box built around a beer-catalog REST API. The intended path is almost entirely source-review driven: a self-hosted Gogs instance leaks API credentials and the API source, the source reveals a Python eval() injection in the brew endpoint, and code execution drops us into the API container as root. From there the database yields reusable credentials, one of which unlocks a private Gogs repo holding an SSH key. Finally, the box uses HashiCorp Vault’s SSH secrets engine to broker root logins, and a leftover root-capable Vault token lets us mint a one-time password and SSH straight in as root. ...

Hack The BoxCraftLinuxMedium
Released July 13, 2019 · 13 min

RedCross

Overview Machine author: ompamo. Debian. A maze box with multiple paths at every stage. Key concepts: cookie reuse between subdomains, NSS + PostgreSQL as the backend for system accounts, command injection in a setuid wrapper, and a x64 ROP buffer overflow. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +- XSS (contact form) --------------+ admin.redcross.htb +- SQLi -> crack charles -----------+-> reuse PHPSESSID +- guest account -> cookie ---------+ | v +- Haraka SMTP RCE ---------------+ shell as penelope + +-> user.txt +- cmd injection (iptctl) -> www-data -> PostgreSQL creds -> add a user gid=1000 | v +- gid=27 (sudo) -> sudo su ------+ (unintended) root +- unixnssroot -> uid=0 -> su ----+ (intended) +- BOF in iptctl (setuid) -> ROP -+ (BOF path) | v root.txt Reconnaissance 1 2 3 22/tcp ssh OpenSSH 7.4p1 Debian 10+deb9u3 (Debian 9 Stretch) 80/tcp http Apache 2.4.25 443/tcp ssl/http Apache 2.4.25 Script scans (-sC) hang, so there is a WAF. Run only -sV. HTTP GET / redirects (301) to https://intra.redcross.htb. Add it to /etc/hosts. Domain and directory enumeration: ...

Hack The BoxRedCrossLinuxMedium
Released November 10, 2018 · 8 min

Node

Overview Machine author: rastating. Focus: privilege escalation (misconfiguration / service abuse, and a ret2libc BOF). 1 2 3 4 5 6 7 8 9 10 recon +- leaky API /api/users/ -> crack hashes -> login as web admin v download myplace.backup (base64 -> zip) +- crack the zip password (john) -> application source -> Mongo creds v SSH as mark (password reuse) +- privesc #1 (mark -> tom): a Mongo-driven scheduler runs exec() as tom v privesc #2 (tom -> root): SUID /usr/local/bin/backup -> ret2libc BOF (plus unintended methods) Skills: API enumeration, credential reuse, service abuse through a database, SUID binary analysis (ltrace/Ghidra), ret2libc, NX + ASLR bypass, blacklist filter bypass. ...

Hack The BoxNodeLinuxMedium
Released October 14, 2017 · 9 min