Tenet - HackTheBox Writeup (10.10.10.223)

Posted on Tue, Jun 22, 2021 Medium Linux Insecure Deserialisation WordPress Race Condition
Medium-difficulty Linux box about exploiting insecure deserialisation vulnerabilities in a PHP data migration program under development. Privilege escalation by exploiting a race condition between Bash variable references in an SSH backup script.

Recon

Enumeration

HTTP Enumeration

Exploitation

Privilege Escalation

Persistence

Resources

  1. https://medium.com/swlh/exploiting-php-deserialization-56d71f03282a
  2. https://www.exploit-db.com/docs/english/44756-deserialization-vulnerability.pdf
  3. https://book.hacktricks.xyz/pentesting-web/deserialization
  4. https://serverpilot.io/docs/where-to-find-your-database-credentials-in-wordpress/
  5. http://www.cis.syr.edu/~wedu/Teaching/IntrCompSec/LectureNotes_New/Race_Condition.pdf