~ / writeups / paperwork

Paperwork

Hack The Box · Easy · Linux

Easy Linux User + Root owned

Machine Overview

Field Value
Name Paperwork
Difficulty Easy
OS Linux (Ubuntu, nginx 1.28.0, OpenSSH 10.0p2)
IP 10.129.248.117
Vhost paperwork.htb
Key components LPD "Archive_Printer" (RFC1179, :1515), JetDirect/PJL simulator (:9100, as archivist), paperwork-daemon (root, Unix socket)
Open ports 22 (SSH), 80 (nginx), 1515 (custom LPD)

Flags

Flag Path Value
User /home/archivist/user.txt [REDACTED]
Root /root/root.txt [REDACTED]

Attack Chain

1. Reconnaissance

2. Source review → LPD command injection

3. JetDirect/PJL path traversal

4. SCM_RIGHTS fd leak → ADMIN_PASSWORD

5. Root

Techniques Demonstrated

  1. LPD (RFC 1179) raw-TCP interaction (port 1515)
  2. Command injection via unsanitized shell=True f-string (x'; cmd; # quote-escape)
  3. JetDirect/PJL file-system ops (FSDIRLIST/FSUPLOAD/FSDOWNLOAD) with UEL framing
  4. Path traversal via os.path.normpath(join(...)) without a root-containment check
  5. Arbitrary file write → SSH authorized_keys injection → interactive shell
  6. Unix-socket SCM_RIGHTS file-descriptor leak (root daemon leaking an already-open secret)
  7. Password reuse (ADMIN_PASSWORD) → su root

Tools Used

nmap, curl, Python 3 (socket for LPD/PJL/SCM_RIGHTS, paramiko for SSH, websocket n/a), ssh-keygen.

← all writeups