Management
Hack The Box · Easy · Linux
Easy
Linux
User + Root owned
Machine Overview
Flags
Attack Chain
1. Reconnaissance
nmap -p- --min-rate 5000 → 22 (SSH OpenSSH 9.6p1), 80/443 (nginx), 1689 (Java RMI — OpenDJ JMX), 4444 (SSL/LDAP, CN=sso.management.htb), 33771 (Java RMI), 50389 (LDAP, anonymous bind allowed).
- Vhost fuzzing →
sso.management.htb serves OpenAM 16.0.5 (ForgeRock SSO) at /openam, management.htb serves an obfuscated JS SPA.
- The SPA loads an AES-GCM-encrypted bundle
assets/app.enc (key hardcoded in-page: C+XDTUB0EuPY7BE+xzRcMP6dNjWd0h0GPxdt8tWSTVY=); decrypted it to confirm it's just a login shell that fronts the OpenAM SSO.
2. Initial Access — OpenAM Pre-Auth Deserialization RCE (CVE-2026-33439)
- The infamous OpenAM JATO deserialization RCE (CVE-2021-35464) is patched here for
jato.pageSession, but jato.clientSession reaches the same unfiltered ApplicationObjectInputStream — CVE-2026-33439 (affects OpenAM ≤ 16.0.5).
- Used the public PoC
jonaschen0103/cve-2026-33439-poc. Built the gadget chain locally (PriorityQueue → shaded org.openidentityplatform.openam.click.control.Column → TemplatesImpl + Xalan AbstractTranslet), requiring JDK 21 (JDK 25 produces incompatible serialized objects). Downloaded a portable Temurin JDK 21 to compile.
- Vulnerable endpoint:
/openam/ui/PWResetUserValidation (a JATO ViewBean). Interactive-mode payload reads a cmd HTTP header, executes via sh -c, returns stdout inline — no reverse listener needed.
- Achieved RCE as
openam (uid 996).
3. GLPI LDAP Credential Decryption
- Enumerated the box: GLPI installed at
/opt/glpi.
/opt/glpi/config/config_db.php leaked DB credentials: glpi / 8rhu0L6Pw4Y7 @ glpidb.
/opt/glpi/config/glpicrypt.key = 32-byte GLPI master key.
- Queried
glpi_authldaps → rootdn=cn=svc-glpi,ou=services,dc=management,dc=htb, rootdn_passwd = encrypted blob avrqW65aZWKzLAKWhPxZGn1eLj3yYAnwUp08mEazsJUWfI5cqbaP6vM12w0p/ykpmyO3Pw==.
- Decrypted using GLPI's
GLPIKey crypto: XChaCha20-Poly1305-IETF (libsodium), format base64(nonce[24] + ciphertext), AAD = nonce, key = glpicrypt.key. Plaintext: WpczC40GhTbk.
4. Password Reuse → User Flag
- The LDAP bind password
WpczC40GhTbk is reused as the system password for owen.
- SSH as
owen → user flag [REDACTED].
5. Privilege Escalation — rdiff-backup Argument Injection
sudo -l: (root) NOPASSWD: /usr/bin/rdiff-backup --server --restrict-path /opt/backup --restrict-mode read-only *
- The trailing
* wildcard permits extra arguments. rdiff-backup honors the last --restrict-path.
- Exploit: run rdiff-backup as a client with a crafted
--remote-schema that (a) escalates to root via the allowed sudo command and (b) appends a second --restrict-path %s where %s (the "host") is /, overriding the /opt/backup restriction:
rdiff-backup --remote-schema 'sudo /usr/bin/rdiff-backup --server --restrict-path /opt/backup --restrict-mode read-only --restrict-path %s' backup /::/root /tmp/rootbak
cat /tmp/rootbak/root.txt
%s is replaced by / (the host portion of /::/root), so the server runs with --restrict-path / — unrestricted read access — and mirrors /root to /tmp/rootbak (still read-only, no root shell needed).
- Root flag
[REDACTED].
Techniques Demonstrated
- Vhost/subdomain enumeration (OpenAM SSO + obfuscated SPA)
- AES-GCM bundle decryption (hardcoded key)
- Java deserialization RCE (OpenAM
jato.clientSession whitelist bypass, CVE-2026-33439)
- JDK gadget-chain compilation (PriorityQueue → Click
Column → TemplatesImpl)
- GLPI credential recovery: DB creds leak + master-key (glpicrypt.key) + XChaCha20-Poly1305 decryption of
glpi_authldaps.rootdn_passwd
- Credential reuse (LDAP bind password → system user)
- sudo wildcard +
--remote-schema argument injection (rdiff-backup --restrict-path override → arbitrary read as root)
Tools Used
nmap, curl, Python 3, Temurin JDK 21 (javac/java), cve-2026-33439-poc, mysql (target), php/libsodium (target), paramiko (SSH), rdiff-backup.
← all writeups