Feline - HackTheBox Writeup (10.10.10.205)

Posted on Tue, Mar 2, 2021 Hard Linux Insecure Deserialisation SaltStack Salt Docker
Hard-difficulty Linux box on exploiting Apache Tomcat CVE-2020-9484 and abusing docker.sock exposure.

Recon

Enumeration

HTTP Enumeration

Exploitation

Privilege Escalation

Persistence

Resources

  1. https://www.redtimmy.com/apache-tomcat-rce-by-deserialization-cve-2020-9484-write-up-and-exploit/
  2. https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/coinminers-exploit-saltstack-vulnerabilities-cve-2020-11651-and-cve-2020-11652
  3. https://github.com/jasperla/CVE-2020-11651-poc
  4. https://dejandayoff.com/the-danger-of-exposing-docker.sock/
  5. https://dreamlab.net/en/blog/post/abusing-dockersock-exposure/