> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-hospital.md).

# HTB - Hospital

## Initial Enumeration

### NMAP

```bash
PORT      STATE SERVICE           VERSION
22/tcp    open  ssh               OpenSSH 9.0p1 Ubuntu 1ubuntu8.5 (Ubuntu Linux; protocol 2.0)
53/tcp    open  domain            Simple DNS Plus
88/tcp    open  kerberos-sec      Microsoft Windows Kerberos (server time: 2026-06-04 23:00:49Z)
135/tcp   open  msrpc             Microsoft Windows RPC
139/tcp   open  netbios-ssn       Microsoft Windows netbios-ssn
389/tcp   open  ldap              Microsoft Windows Active Directory LDAP (Domain: hospital.htb, Site: Default-First-Site-Name)
443/tcp   open  ssl/http          Apache httpd 2.4.56 ((Win64) OpenSSL/1.1.1t PHP/8.0.28)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http        Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ldapssl?
1801/tcp  open  msmq?
2103/tcp  open  msrpc             Microsoft Windows RPC
2105/tcp  open  msrpc             Microsoft Windows RPC
2107/tcp  open  msrpc             Microsoft Windows RPC
2179/tcp  open  vmrdp?
3268/tcp  open  ldap              Microsoft Windows Active Directory LDAP (Domain: hospital.htb, Site: Default-First-Site-Name)
3269/tcp  open  globalcatLDAPssl?
3389/tcp  open  ms-wbt-server     Microsoft Terminal Services
5985/tcp  open  http              Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
6404/tcp  open  msrpc             Microsoft Windows RPC
6406/tcp  open  ncacn_http        Microsoft Windows RPC over HTTP 1.0
6407/tcp  open  msrpc             Microsoft Windows RPC
6409/tcp  open  msrpc             Microsoft Windows RPC
6613/tcp  open  msrpc             Microsoft Windows RPC
6642/tcp  open  msrpc             Microsoft Windows RPC
8080/tcp  open  http              Apache httpd 2.4.55 ((Ubuntu))
9389/tcp  open  mc-nmf            .NET Message Framing
20006/tcp open  msrpc             Microsoft Windows RPC
```

Domain: `hospital.htb` and DC : `DC.hospital.htb` : add to hosts

#### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJ31iDdV1eNiniJnDmWID%2Fimage.png?alt=media&amp;token=0d85a700-7da0-4dc1-ba23-f1e9eb59d0ba" alt=""><figcaption></figcaption></figure>

No anonymous or Guest acces enabled on the machine.

#### DNS

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fh1SMELtJSgJ02UbTQvvI%2Fimage.png?alt=media&amp;token=c8184ccf-7ddf-435a-bdb1-ce8c6713c0ba" alt=""><figcaption></figcaption></figure>

No DNS Zone transfer.

#### HTTPS - 443

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5EOqMmUJcITGToSPwKW3%2Fimage.png?alt=media&amp;token=821babe4-91a1-450e-9d67-f57e524f100e" alt=""><figcaption></figcaption></figure>

Login page for a web mail client.

### HTTP - 8080

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fb2hXEr08AbuugXxkdLMl%2Fimage.png?alt=media&amp;token=592e3235-bae3-4abd-8111-064f1fcac3f7" alt=""><figcaption></figcaption></figure>

There is registration link too. we can make an account and enumerate further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuAtVO851eGbbzFPTTxr0%2Fimage.png?alt=media&amp;token=b83e29b4-53c7-4914-a995-14edb92bc28f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoMeqGl44tyMkVrjltt5t%2Fimage.png?alt=media&amp;token=b8f738a6-4e9d-4014-96c3-9152ba7ac7dd" alt=""><figcaption></figcaption></figure>

There is an upload form which allows uploading image files and in the mean time FFUF identified hidden directories among which is `/uploads` directory.

```bash
──(ajay㉿kali)-[~]
└─$ ffuf -u http://10.129.229.189:8080/FUZZ \    
     -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -fs 281

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://10.129.229.189:8080/FUZZ
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 281
________________________________________________

css                     [Status: 301, Size: 321, Words: 20, Lines: 10, Duration: 49ms]
images                  [Status: 301, Size: 324, Words: 20, Lines: 10, Duration: 49ms]
uploads                 [Status: 301, Size: 325, Words: 20, Lines: 10, Duration: 46ms]
.                       [Status: 302, Size: 0, Words: 1, Lines: 1, Duration: 44ms]
fonts                   [Status: 301, Size: 323, Words: 20, Lines: 10, Duration: 45ms]
js                      [Status: 301, Size: 320, Words: 20, Lines: 10, Duration: 2668ms]
vendor                  [Status: 301, Size: 324, Words: 20, Lines: 10, Duration: 43ms]
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FS1zrtkeNpk4mh78GOzBu%2Fimage.png?alt=media&amp;token=b041512f-b329-4d94-99c6-c99e58dac86f" alt=""><figcaption></figcaption></figure>

cant access uploads but i can directly access the  file uploaded.

So the directory listing is disabled but direct file access works also the uploaded file is getting deleted after some time.

#### Abusing File Upload&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxAPtxlMj2f5UIJusRdd2%2Fimage.png?alt=media&amp;token=c7713abf-6b5c-4d30-96fa-92cf0b08aa60" alt=""><figcaption></figcaption></figure>

uploading a `shell.php` redirects to `/failed.php.`

So we need to find an extension that is not blocked and redirects to `/success.php`

Fuzizng through intruder i got the extension `.phar` can be used to bypass.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlQ04XcaWi8YRYGHWwYtz%2Fimage.png?alt=media&amp;token=5195de21-1234-4923-b305-c57fae573f3f" alt=""><figcaption></figcaption></figure>

Using the `.phar` extension to execute php code.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5M764VDTUHK6nyNYGSkf%2Fimage.png?alt=media&amp;token=9fab77f4-fdba-446a-b915-a076b31a6ba2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1MhQxb0zOxjQqkQxVaml%2Fimage.png?alt=media&amp;token=1d0c5c78-ae11-4123-bead-e4be2a3e19c8" alt=""><figcaption></figcaption></figure>

php code executed but `system()` or `shell_exec()` didnot executed.

I will display the `phpinfo()` to see which functions are disabled.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzWCzMAaXP9Iwdkgp2tZC%2Fimage.png?alt=media&amp;token=ee998421-a668-464a-b5f9-4687b9168391" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3F1TxxokqvaCuhqVywN3%2Fimage.png?alt=media&amp;token=795fcd23-2ae2-45a1-b2dc-bc865c12cf82" alt=""><figcaption></figcaption></figure>

`popen` and `mail` are not in the disabled list, we can utilize them to get command execution.

#### Using php popen() to get Shell

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpsAf8gVXayF44DdBY4Qx%2Fimage.png?alt=media&amp;token=da7bfc1b-c6c4-4d74-bb5a-d24bb39a3dc7" alt=""><figcaption></figcaption></figure>

popen works to execute the and give us command injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxwtWUlR6DnlmbDVVuvB0%2Fimage.png?alt=media&amp;token=21b42dfa-d92c-4099-a265-280034885f73" alt=""><figcaption></figcaption></figure>

now i can use popen to give me shell access on my netcat listener.

## Shell as www-data

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIrkAF2OTnST1Iwmgccva%2Fimage.png?alt=media&amp;token=dd2932ce-2b99-497c-98c7-b2459bef2d39" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FV8iN9nzfu4lCEOYeHraF%2Fimage.png?alt=media&amp;token=16830c94-29c7-45ea-b5e6-f9a928a947cf" alt=""><figcaption></figcaption></figure>

found no interesting directories to enumerate further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRxNsXkG7XUJZmYaCIT9c%2Fimage.png?alt=media&amp;token=6dfd8ad7-957b-45af-b09a-a026e3ce6891" alt=""><figcaption></figcaption></figure>

The kernel `version 5.19.0-35-generic` is significantly outdated.

A quick google search revealed the following vulnerabilities.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWA0acGMYz9xZ9ekPQIgh%2Fimage.png?alt=media&amp;token=d96a8d03-7002-49d0-8db2-e6e3bffd27ce" alt=""><figcaption></figcaption></figure>

### Abusing Overlay FS Vulnerability

Found this poc that helped me escalate to root

{% embed url="<https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629?source=post_page-----31870430139d--------------------------------------->" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAneJFhFIbFsw8536RHPb%2Fimage.png?alt=media&amp;token=7985fcd6-c34d-4060-b9d1-838c84dd27cd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqEp14hVHhY4a9qux6huy%2Fimage.png?alt=media&amp;token=27bbce52-a95b-46b0-8758-d67954fa8408" alt=""><figcaption></figcaption></figure>

## Shell as Root

with root access i can read the `/etc/shadow` file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSybb9K2CO9u3ZO85GLOe%2Fimage.png?alt=media&amp;token=42ad86bb-b85d-456e-9d3c-8702d1e68607" alt=""><figcaption></figcaption></figure>

i can crack the hash for `drwilliams` using hashcat or john.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Faup5ErlFWlsPDwnnaLFv%2Fimage.png?alt=media&amp;token=3e156946-2bdc-4225-84e6-141fd4efbedf" alt=""><figcaption></figcaption></figure>

`drwilliams:qwe123!@#`

There is a login portal on port 443. i can use the creds to login there.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3XukZrRw7iWmwznapM4T%2Fimage.png?alt=media&amp;token=22841043-8a06-4206-b568-3caabc9f87d0" alt=""><figcaption></figcaption></figure>

there is a mail in the inbox from `dbrown`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F04yymNVTV11PfpiSCimE%2Fimage.png?alt=media&amp;token=59584b44-dd34-4ebf-873f-208899aa60eb" alt=""><figcaption></figcaption></figure>

There are several clues from the mail.

* Email from <drbrown@hospital.htb>
* Asking for .eps file format
* Will be opened with GhostScript

### Exploiting GhostScript via malicious .eps file&#x20;

What i can do here is generate a malicious `.eps` file and send it to dbrown and once it opened by ghostscript, it gives me shell.

`GhostScript < 10.01.2` are vulnerable to RCE via .eps file.

Found this git repo when searching online.

{% embed url="<https://github.com/jakabakos/CVE-2023-36664-Ghostscript-command-injection>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9bcRsQt0KbWNZY0g8HcG%2Fimage.png?alt=media&amp;token=434ec4f1-9fdb-43df-a4fb-c483bd8584d0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXwQ5IcFnlAHWlfkzTRHH%2Fimage.png?alt=media&amp;token=43b9138c-c25f-4129-a4c7-d134ab81a594" alt=""><figcaption></figcaption></figure>

Used the reverse shell generator to get a rev shell payload and used it with the POC to generate a malicious `.eps` file.

Used powershell payload beacuse nmap revealed that on port 443 there is a windows machine running.

```bash
443/tcp   open  ssl/http          Apache httpd 2.4.56 ((Win64) OpenSSL/1.1.1t PHP/8.0.28)
```

now send the mail using the malicious eps file and make sure your nc is running.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FU7GQi0wUI5KaY9bO7vwA%2Fimage.png?alt=media&amp;token=53c3a70d-ae01-4383-b320-d8fe178c5a8e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGlCqcfQlXC1KQxg5uSGv%2Fimage.png?alt=media&amp;token=f9d5248f-b12c-4992-b662-b5c8fea99aa8" alt=""><figcaption></figcaption></figure>

## Shell as drbrown

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiM9appSeYn0uWJPVIFzD%2Fimage.png?alt=media&amp;token=20d26db1-f2e0-46df-80cd-dec5883cb4f6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9kh4ozdsMU019zNgRASp%2Fimage.png?alt=media&amp;token=680f2e61-d3d5-4f93-9270-f7e13216fd2f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBMxh5RIQRQ9dJDZRqg50%2Fimage.png?alt=media&amp;token=2c24de0b-f742-4628-bee7-8ec18d0a5556" alt=""><figcaption></figcaption></figure>

There is a script in the documents folder which opens the mail we have sent, upon reading the script, revealed password for drbrown user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FG8hjKUXOOih606c047o7%2Fimage.png?alt=media&amp;token=c540e22b-1c10-4746-a7dd-bb9f117ed7ec" alt=""><figcaption></figcaption></figure>

Nxc validated that the password is valid and confirms winrm access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRBHap31bxKWsTXNWiifh%2Fimage.png?alt=media&amp;token=4463d987-730b-40b6-a518-4003215778f6" alt=""><figcaption></figcaption></figure>

### DrBrown Winrm Access

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXQNpcIqlURLaP8OzMwYW%2Fimage.png?alt=media&amp;token=f0a9959f-a31c-4440-87ed-9e879fd6d916" alt=""><figcaption></figcaption></figure>

`qwinsta` (Query Window Station) is a Windows command that shows active user sessions on the machine.

```bash
Evil-WinRM* PS C:\Users\drbrown.HOSPITAL> qwinsta
 SESSIONNAME       USERNAME                 ID  STATE   TYPE        DEVICE
>services                                    0  Disc
 console           drbrown                   1  Active
 rdp-tcp                                 65536  Listen
*Evil-WinRM* PS C:\Users\drbrown.HOSPITAL> 

```

drbrown is active on console (local session) and RDP is listening.

i can either use the metasploit to capture the keystrokes drbrown is typing or connect to the rdp shell and view what is happening.

logging through rdp gave this screen.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FSzJmzQxTsUtpaINPGoJX%2Fimage.png?alt=media&amp;token=91afe12f-8379-453d-99fe-72f434ccc05f" alt=""><figcaption></figcaption></figure>

Drbrown is typing administrator password, used the explored feature to save the password for future use and enumerated the saved passwords and extracted the administrator password.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwVM0ZNtsoXXGbLouD3ud%2Fimage.png?alt=media&amp;token=66e3a473-8b10-4917-b7bd-10397b220c23" alt=""><figcaption></figcaption></figure>

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FN9HycjK0fije0djTBYbA%2Fimage.png?alt=media&amp;token=acf52819-1616-405b-abd7-c9b2c127df8a" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-hospital.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
