Port enumeration

Using nmap, I found two open ports, 22 and 80. ee7bc60b6f977676cca0ae40f091f739.png

Web enumeration

Using wfuzz, I found 2 pages in the web.

wfuzz -c --hc 404 -t 300 -w /usr/share/wordlists/dirbuster/directory-list-1.0.1.txt -u http://editorial.htb/FUZZ

ad880324f8f53083060fe8bfc8f6cd8f.png

upload allows me to send a file to the server, but it is not the entrypoint. 1eb7597bd157a02dfc34d685a99ddc80.png

SSRF

This page, allows me to send an URL, and it allow me to interact with local URLs. bbfb101c1a3782716c84d88334385451.png Using burpsuite Intruder, I tried all the ports until I found something in port 5000. 3926ab298272c93b1cc3c0a90440cee3.png This looks like an API. d882df3df7d91888fe3f2ccd012697f9.png Interacting with /api/latest/metadata/messages/authors I found some credentials for dev user. 82300571c269b9ecbbc06f2d2f259e81.png 21172fa724bf8120eb0efb7da6c6251e.png Using ssh, I can log as dev and read the user flag. a0e13370c71988da7ffa997b4702b8b0.png

Local machine enumeration

Inside the local machine, I found a .git directory. 04c5e68aea4b767d8e25dbb58f355a40.png Inside the repo, I found hardcoded credentials. d23da87026e7b3aa7f4b5c4bed609805.png With this credentials, I can log as prod user. 2586a4ccd65ca9d6b7bb35815db21aaa.png

Privilege escalation

prod user can execute a python script as root. 6a60a27a57bfe628fd4799ada1786e02.png Reading the script, I can see that the git library is been imported. bba7998fab98b6b237d1b9e9ea85ced1.png This library alloys RCE. 131a0777aa59f2dd1b653b014b9ca5f6.png Using this code, Im able to execute a reverse shell. 7af4c0d824b364bf3377b50eff6f8cf7.png d1b05931b151624e7564ecc776fbdb5f.png With this, I can read the root flag. 0e6e380e3bf8b91d5c5301ff28f2bb17.png