> For the complete documentation index, see [llms.txt](https://akshaydeepakshinde.gitbook.io/hackthebox-linux/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://akshaydeepakshinde.gitbook.io/hackthebox-linux/hackthebox-scavenger.md).

# HackTheBox - Scavenger

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY4rQ-jzdnj_JcU0YfT%2F-MY4rdklvCbq9TLDvDV1%2Fimage.png?alt=media\&token=4ea2c0a1-b598-4633-b38a-1a2b68fe76d3)

### Nmap scan results&#x20;

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY4rQ-jzdnj_JcU0YfT%2F-MY512hbbo4dhWBEsKp6%2Fimage.png?alt=media\&token=4a4f5110-89c2-4dca-b066-4da0dcef18d4)

### Enumerating DNS and performing Zone transfer attack

Adding supersechosting.htb to `/etc/hosts` file.&#x20;

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5Y7963U9IDlwCW2t_%2F-MY5Z6etHgQ4s2_vwsWA%2Fimage.png?alt=media\&token=f529183a-b283-4cee-86c9-c44d0da23d44)

{% hint style="info" %}
&#x20;**Zone transfer** is the process of copying the contents of the **zone** file on a primary DNS server to a secondary DNS server. Using **zone transfer** provides fault tolerance by synchronizing the **zone** file in a primary DNS server with the **zone** file in a secondary DNS server.
{% endhint %}

DNS Zone transfer using `dig` command in Linux System.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5Y7963U9IDlwCW2t_%2F-MY5ZLKbHIuktTK4OtPQ%2Fimage.png?alt=media\&token=ea962d0c-79e8-4444-bb3b-a1cc73e12dcd)

### Enumerating Whois (SQL Injection)

Reference: <https://book.hacktricks.xyz/pentesting/43-pentesting-whois>

We can use whois to lookup the information about a particular domain. With this we can also perform SQL Injection.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5Y7963U9IDlwCW2t_%2F-MY5_J4lM496V7uSiiCJ%2Fimage.png?alt=media\&token=44a8f34f-ff11-46ea-bcac-cb8b319f8669)

We get a SQL Error and thus we can inject some payload to get the data. Common payload is `') or 1=1-- -`

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5Y7963U9IDlwCW2t_%2F-MY5_dKUg5mdmXLYFtUM%2Fimage.png?alt=media\&token=9e21b467-daa5-400f-ab93-e2d19b7eeac6)

This query returned us all the data present in the database. We have the following domains hosted on `supersechosting.htb`

```
supersechosting.htb
justanotherblog.htb
pwnhats.htb
rentahacker.htb
```

Lets add all of these domains to `/etc/hosts` file. We can also perform zone transfer on this domains using a single script.

```
for i in $(cat domains.txt);do dig axfr @10.10.10.155 $i > zone_transfer/${i}.txt;done
```

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5Y7963U9IDlwCW2t_%2F-MY5auea0ClDMn_zwQHH%2Fimage.png?alt=media\&token=c56831cc-e8f2-4b91-9a53-eb53b8c105a7)

### Exploiting sec03.rentahacker.htb subdomain

So we have a new subdomain for `rentahacker.htb` and that is `sec03.rentahacker.htb`

After adding all the domains and subdomains, the hosts file should look like this.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5bwT27Zo4V60KmZIU%2Fimage.png?alt=media\&token=251deba4-a5ef-46d2-9b33-4be08f6b4238)

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5d0Wl9hp3PdVHWTwU%2Fimage.png?alt=media\&token=dcaf35f8-d26d-492c-b4b9-30f8faf8fd52)

We can start of a gobuster scan in the background for all the websites with extensions as `.php,.html and .txt`

We get something malicious content on the following domain : <http://sec03.rentahacker.htb/>

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5ddSeKJvFIazQryPQ%2Fimage.png?alt=media\&token=a1a79c2a-eebb-40b1-990e-3919d7343626)

This was the same comment found on the wordpress page and this can lead us to something very interesting.

### Fuzzing hidden parameter using ffuf

```
gobuster dir -u http://sec03.rentahacker.htb/ -w /opt/SecLists/Discovery/Web-Content/raft-small-words.txt -x php,txt,html -o gobuster-files-scan.out -b 404,403
```

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5eZ8lJ_mHRpMKH8Jf%2Fimage.png?alt=media\&token=bb7a59e0-ca98-4b67-a4a8-4f95e20a9309)

It looks like the attacker uploaded a malicious shell.php on the server. We can view the file and try to guess the parameter for RCE using wfuzz or ffuf.

```
ffuf -w /opt/SecLists/Discovery/Web-Content/burp-parameter-names.txt -u http://sec03.rentahacker.htb/shell.php?FUZZ=id -fs 0
```

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5exmpGnF9pBEL9HCh%2Fimage.png?alt=media\&token=7cb7ad24-0479-4b9b-a6a3-7a67fbeb6c29)

### Remote Code Execution

And we get Remote Code Execution on the target computer. For some reason, we can't get a reverse shell. So let's explore the common files on the Linux system. I happen to find this interesting mail for the user ib01c03. Let's view the contents of it.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5tNwOcsyiPlFZMwzF%2Fimage.png?alt=media\&token=308ba1cd-071f-4326-b0a5-375785cf8d9a)

`FTP Credentials-  ib01ftp:YhgRt56_Ta`

We can get all the files present on the FTP Server using the following command.

```
wget -m --no-passive ftp://ib01ftp:YhgRt56_Ta@10.10.10.155 
```

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY5boZ7BEilzIXlpIzQ%2F-MY5v0rrktUMlZH290S2%2Fimage.png?alt=media\&token=f6456945-7764-4e8d-99d6-8c54315ad5bc)

### Incident Response (Checking log files)

Checking the logs, we can say that certain POST requests are made and we can analyze that request in the wireshark.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY90oRJCqEq7TQ4M5BM%2Fimage.png?alt=media\&token=d477e36f-22c2-4dc5-8e1c-3233b7bfc8e9)

We get a another set of credentials. `pwnhats@pwnhats.htb: GetYouAH4t!`.We can also grab the credentials from `wp-config.php` file.&#x20;

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY91I35j3vdIG8XZIzv%2Fimage.png?alt=media\&token=5ccb0f3c-25c6-4a32-a79f-341c1f346345)

### Using forward-shell script to get shell access

So the outgoing connections are blocked and for that reason we can't get a reverse shell. We will use forward-shell by Ippsec.

> A forward shell is a concept of shell interaction with a vulnerable Linux machine based on the named pipes mechanism.

Modify certain parameters and domain name in the script.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY924obVASfz76V6MYt%2Fimage.png?alt=media\&token=c5cc023f-bef0-44fd-9cc2-5af0a3a4b71f)

### Analyzing root.c kernel rootkit using Ghidra

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY941BslGieGLReLBf4%2Fimage.png?alt=media\&token=a6b348df-5394-4dd9-a2f4-10bd8bde87cf)

So here to trigger the rootkit, we need to send `g0tR0ot` to `/dev/ttyr0`

We can do that as now we have shell access. Let's try that.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY94SHiJsGoktGrssb_%2Fimage.png?alt=media\&token=91695023-7ea0-4902-966f-cb0f3284986f)

We have this `root.ko` file present in the following directory: `/home/ib01c01/...`

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY97Hw2q-RkNwRMMisf%2Fimage.png?alt=media\&token=60680729-36f5-41d7-955f-1832b1409251)

Let's open this file in ghidra and look at the source code.

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY99L-DV2LjgSuzBi1W%2Fimage.png?alt=media\&token=7ecbafb8-4324-44b2-b07e-d07887c51964)

So if we send `0x743367 i.e g3t` and `0x76317250 i.e Pr1v` to /dev/ttyR0, then we can get root access. The concept is same but the source was a bit modified. (g3tPr1v)

![](https://1033785646-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXzdi_mbSkB5NqqwWVy%2F-MY8zRSghNh72-cFgwNz%2F-MY99uwgabglmaX4ccHb%2Fimage.png?alt=media\&token=416644fd-c4bb-4f35-a0b7-f7fe8543750e)
