Cozyhosting
Gaining Access
$ nmap -p- --min-rate 3000 10.129.121.30
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-04 13:22 +08
Nmap scan report for 10.129.121.30
Host is up (0.16s latency).
Not shown: 65533 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http$ nmap -p 80 -sC -sV --min-rate 4000 10.129.121.30
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-04 13:23 +08
Nmap scan report for 10.129.121.30
Host is up (0.17s latency).
PORT STATE SERVICE VERSION
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to http://cozyhosting.htb
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelWeb Enum -> Spring Boot -> Admin




Admin Dashboard -> RCE




Privilege Escalation
CloudHosting Jar -> SQL + User Creds


Sudo Privileges -> Root

Last updated