> For the complete documentation index, see [llms.txt](https://rouvin.gitbook.io/ibreakstuff/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://rouvin.gitbook.io/ibreakstuff/writeups/hackthebox/medium/backendtwo.md).

# BackendTwo

Builds on the Backend machine with updated security features.

## Gaining Access

Since this builds on the other Backend machine from UHC, there isn't a lot of enumeration to do.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-68e084b68168cad681ad756cf0e5bdf4224eee54%2Fimage.png?alt=media)

Port 80 brings us to an API again, with the admin user still being viewable.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-a7aa8784e385a6a5dca715fbecbe0a888e68bd98%2Fimage.png?alt=media)

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-64c226822ac2e87fe31ef24a9421c3a62e978e3e%2Fimage.png?alt=media)

### Creating User

We can do the same stuff to create, signin as a user and receive the JWT token for it.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-2cd0a744e3761fb48eedeeba93ca17bda09f7ee5%2Fimage.png?alt=media)

Afterwards, we can access the `/openapi.json` endpoint to view the functionalities of this API. There was one new functionality, which was to edit the profiles of users.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-2f658f95434e569103e317bfebdb407e19d7746a%2Fimage.png?alt=media)

This endpoint was rather interesting because it allows us to edit profiles. Checking the JWT token of our current user, we find out that our `id` is 12.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-f6d731eddb8a953a49ab91b00f49bd038d2d8409%2Fimage.png?alt=media)

### Superuser Takeover

With this edit profile stuff, I found out that we can change the attributes related to our account. I changed the profile, email and GUID of the current user to be the same as the administrator's.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-720d77df4185dcc673b0b16eaaffe2940e5e13b9%2Fimage.png?alt=media)

When I found out this worked, I basically also changed the `is_superuser` attribute to `true`.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-9a06eed7bcbd32338951feb530d96d32ca4226c4%2Fimage.png?alt=media)

After changing all of these, we just need to retrieve the new JWT token we can use for further exploitation.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-455786450663b01d8284dc28ab92313f9448cff4%2Fimage.png?alt=media)

### Read and Write Files

The other OpenAPI functionalities included writing files and reading files as the administrator.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-6a49020610c86865bbe32c7881a40361afc01b49%2Fimage.png?alt=media)

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-7171520d8a2555527cff7b29920c5d8290dfa643%2Fimage.png?alt=media)

As usual, I started with reading the code that the application runs on. Since we wcould write files, the only exploit in my mind was to change the some file to include a custom RCE endpoint for us. We can find out all of the locations of the files using the same method as Backend, which involved reading the `/proc/self/environ` file and finding the `/home/htb` directory that had the source code files for the app.

Within the `/home/htb/app/api/v1/endpoints/user.py` file, this was the original code.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-bb17ef56f6e9aaf6efa5dd3526a485451b32b44d%2Fimage.png?alt=media)

I changed the code to include a one-liner reverse shell everytime a unique ID was accessed.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-870a4635d35b406cfd7feedb35ce9c41959754e1%2Fimage.png?alt=media)

Then we need to convert the file contents using the escape string function on Cyberchef.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-f9e5a8ac9d91b217bde382d55846694b8158e586%2Fimage.png?alt=media)

Using this, we can use curl to get the file where we want it. The command would look like this:

```bash
curl http://<IP>/api/v1/admin/file/$(echo -n "/home/htb/app/api/v1/endpoints/user.py" | base64) -H "Content-Type: application/json" -d '{"file": "CODE HERE"}' -H 'Authorization: Bearer <TOKEN>' 
```

Then, we can access the custom endpoint to gain a reverse shell easily.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-c97211bad17a2fb30c79214bf9324f992e5668bc%2Fimage.png?alt=media)

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-b913ac274edf5d3c6a35728e8473a63494244dcf%2Fimage.png?alt=media)

## Privilege Escalation

Once we are in, we can try to read the `auth.log` file and we would find the password for the `htb` user we currently are. This allows us to upgrade our shell via SSH-ing in.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-acbd64c637494fde105662c32e43a53f646f00cb%2Fimage.png?alt=media)

### Wordle

When I tried to check sudo privileges, I was left with this.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-ed69fdee259ceea2ff83e2333ed7789eb65cc451%2Fimage.png?alt=media)

This was basically wordle, and there are better ways to solve this via checking what directories it uses. I used `strings` to see what libraries it called.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-3763e06a0b67fc60227b5b97fa1f77cba23a1615%2Fimage.png?alt=media)

We can then use `find / -name pam_wordle.so 2> /dev/null` to find this library and run strings on it. It would be located in the `/usr/lib/x86_64-linus-gnu/security` directory and is readable by all. We can then use `strings` on it.

From the output, we find that the wordlist for wordle is from `/opt/.words`, which would allow us to scope our guesses.

Afterwords, I used `sudo /bin/bash` and just kept guessing based on the words I had.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-437b588b328b353ddd87fa064d5d0ce268c97a89%2Fimage.png?alt=media)

Fun enough.
