Doctor - HackTheBox Writeup (10.10.10.209)

Posted on Sat, Feb 27, 2021 Easy Linux Web Application Command Injection Splunk Forwarder
A not-so-easy Linux box about advanced URL command injection and exploiting Splunk Universal Forwarder to gain root and persistence.

Recon

Enumeration

Splunk Enumeration

HTTP Enumeration

Exploitation

Privilege Escalation

Persistence

Resources

  1. https://bash.cyberciti.biz/guide/$IFS
  2. https://eapolsniper.github.io/2020/08/14/Abusing-Splunk-Forwarders-For-RCE-And-Persistence/
  3. https://github.com/cnotin/SplunkWhisperer2/tree/master/PySplunkWhisperer2