Skip to content
Get 10% Discount on Every Courses
Login/Register
Call: +91-9930824239
Email: services@macksofy.com
Macksofy TrainingsMacksofy Trainings
  • About Us
    • About Macksofy Trainings — EC-Council Accredited Cybersecurity Training Center
    • Our Esteem Clients
  • Courses

      Beginner

      • SEC-100 CyberCore Security Essentials
      • Certified Ethical Hacker CEHV13 with Artificial Intelligence
      • Certified Ethical Hacker with Artificial Intelligence CEHV13 Practical
      • Certified Ethical Hacker CEHv12
      • The Certified SOC Analyst CSA
      • Certified Threat Intelligence Analyst (CTIA)
      • Computer Hacking Forensic Investigator (CHFI)
      • Foundational Wireless Network PEN 210 Course

      Intermediate

      • SEC-100 CyberCore Security Essentials
      • SOC-200: Foundational Security Operations and Defensive Analysis
      • Foundational Wireless Network PEN 210
      • Certified Threat Intelligence Analyst (CTIA)
      • The Certified SOC Analyst CSA
      • Advanced Windows Exploitation EXP-401
      • Advanced macOS Control Bypasses EXP-312

      Professional

      • Certified Penetration Testing Professional CPENT
      • Advanced macOS Control Bypasses OSMR | EXP 312
      • Windows User Mode Exploit Development OSED | EXP 301
      • OSWE | WEB 300 Advanced Web Attacks and Exploitation
      • OSWA | WEB 200 Foundational Web Application Assessments with Kali Linux
      • OSEP | PEN-300 Advanced Evasion Techniques and Breaching Defenses
      • OSCP | PEN 200 Penetration Testing with Kali Linux
  • Certifications
    • Offsec Certification Voucher
    • EC Council Certification Voucher
  • Our Training
    • OSCP+ Training and Certification
    • Sec 100 Cybercore Security Essentials
    • Certified Ethical Hacker (CEH) V13
    • Certified Ethical Hacker Training
    • Certified Threat Intelligence Analyst (CTIA)
    • OSWE (WEB-300) Training And Certification Offsec India
    • The Certified Penetration Testing Professional (CPENT)
    • Computer Hacking Forensic Investigator CHFI
  • Blog
  • Contact Us
Enroll Now
Macksofy TrainingsMacksofy Trainings
  • About Us
    • About Macksofy Trainings — EC-Council Accredited Cybersecurity Training Center
    • Our Esteem Clients
  • Courses

      Beginner

      • SEC-100 CyberCore Security Essentials
      • Certified Ethical Hacker CEHV13 with Artificial Intelligence
      • Certified Ethical Hacker with Artificial Intelligence CEHV13 Practical
      • Certified Ethical Hacker CEHv12
      • The Certified SOC Analyst CSA
      • Certified Threat Intelligence Analyst (CTIA)
      • Computer Hacking Forensic Investigator (CHFI)
      • Foundational Wireless Network PEN 210 Course

      Intermediate

      • SEC-100 CyberCore Security Essentials
      • SOC-200: Foundational Security Operations and Defensive Analysis
      • Foundational Wireless Network PEN 210
      • Certified Threat Intelligence Analyst (CTIA)
      • The Certified SOC Analyst CSA
      • Advanced Windows Exploitation EXP-401
      • Advanced macOS Control Bypasses EXP-312

      Professional

      • Certified Penetration Testing Professional CPENT
      • Advanced macOS Control Bypasses OSMR | EXP 312
      • Windows User Mode Exploit Development OSED | EXP 301
      • OSWE | WEB 300 Advanced Web Attacks and Exploitation
      • OSWA | WEB 200 Foundational Web Application Assessments with Kali Linux
      • OSEP | PEN-300 Advanced Evasion Techniques and Breaching Defenses
      • OSCP | PEN 200 Penetration Testing with Kali Linux
  • Certifications
    • Offsec Certification Voucher
    • EC Council Certification Voucher
  • Our Training
    • OSCP+ Training and Certification
    • Sec 100 Cybercore Security Essentials
    • Certified Ethical Hacker (CEH) V13
    • Certified Ethical Hacker Training
    • Certified Threat Intelligence Analyst (CTIA)
    • OSWE (WEB-300) Training And Certification Offsec India
    • The Certified Penetration Testing Professional (CPENT)
    • Computer Hacking Forensic Investigator CHFI
  • Blog
  • Contact Us

Hack The Box Writeup – Laboratory

  • Home
  • HackTheBox Writeups
  • Hack The Box Writeup – Laboratory
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
HackTheBox Writeups

Hack The Box Writeup – Laboratory

  • October 25, 2024
  • 0
Picture96 — Macksofy Trainings

About the Laboratory HackTheBox machine

Operating system: Linux  |  Difficulty: Easy  |  Status: Retired

Laboratory is a retired Easy-rated Linux machine built around a self-hosted GitLab Community Edition instance on a git.laboratory.htb subdomain (discovered from the TLS certificate). After registering an account, a GitLab arbitrary-file-read to remote-code-execution chain (CVE-2020-10977) provides the foothold, and a PATH-hijack against a root-run binary delivers privilege escalation. A clean lesson in subdomain enumeration and exploiting a well-known application.

Greetings from Macksofy Technologies. Below is the detailed walkthrough of the Laboratory machine which got retired from HackTheBox
The IP of this box is 10.10.10.216
Port Scan
Running NMAP full port scan on it , we get

We got 3 Open Ports, Port 22 for SSH and Port 80 and Port 443 for Web

Way To User

Checking the NMAP result, we see that the web has redirection to https://laboratory.htb and on the SSL part we see that there is a another domain git.laboratory.htb , so keeping both on our hosts file and checking the web

We confirm from the SSL certificate about the other subdomain

Nothing much interesting on the main domain , so checking the other git domain

We have Gitlab Community Edition installed on the git domain, and we are redirected to the login page where we have options to register a user

We registered a new user and then logged in

Checking the version of the GitLab installed, we see that we have GitLab Community Edition 12.8.1 which has a vulnerability reported on HackerOne for directory traversal

Confirming the exploit by getting the /etc/passwd file

This vulnerability is chained with RCE for which before we have to get the following file
/opt/gitlab/embedded/service/gitlab-rails/config/secrets.yml

Now we followed the report and then create our payload which will be used in Cookie field and for this we have to installed a GitLab instance locally which I did using docker

Our cookie got created and using then ran our curl command and got reverse shell as git user

Picture107 — Macksofy Trainings

Now we create a new user for gitlab using gitlab-rails console where we assign the admin role to the newly created user

We now login with our newly created user

Login successful and then moving towards finding something interested which were accessible to admins and we had ssh key for the user dexter

We now connect to user dexter through SSH

Way To Root
Checking for SUID binaries, we get an interesting one,i.e, docker-security

Just running the cat command against the binary, we see that the binary is running chmod command where the path is not defined, so we can just hijack the path and exploit it

We exploit the vulnerability and then get root

References
devise
user from rails console
https://stackoverflow.com/questions/35909643/devise-user-from-rails-console
GitLab disclosed on HackerOne: Arbitrary file read via UploadsRewriter when moving and issue
https://hackerone.com/reports/827052
Tags: ctf, hack, hackthebox, hard, htb, linux, medium

Skills you practise on Laboratory

  • Extracting subdomains from TLS/SSL certificates
  • Enumerating and registering against a GitLab instance
  • Chaining a GitLab arbitrary-file-read into RCE (CVE-2020-10977)
  • Cracking or recovering application secrets
  • Privilege escalation via PATH hijacking of a root process

How Laboratory maps to your OSCP / PEN-200 preparation

The enumerate → gain a foothold through a web or service vulnerability → escalate to root workflow on Laboratory mirrors the exact methodology assessed in the OSCP exam. If you want to build this skill set under expert mentorship with an exam-focused lab environment, explore Macksofy’s OSCP (PEN-200) training and certification programme.

More HackTheBox writeups from Macksofy

  • HackTheBox Academy (Easy Linux)
  • HackTheBox Passage (Medium Linux)
  • HackTheBox Luanne (Easy NetBSD)
  • HackTheBox Time (Medium Linux)
  • HackTheBox Feline (Hard Linux)

Browse every walkthrough in our HackTheBox writeups collection, or go deeper with our penetration testing articles.

Share on:
Macksofy Expert Trainers

Macksofy Expert Trainers is the collective byline for certified cybersecurity instructors at Macksofy Trainings. Our trainers hold OSCP, OSWE, OSEP, CEH, CPENT, SOC-200, CompTIA, and other industry certifications, and bring combined hands-on experience in commercial penetration testing, red team operations, SOC analysis, threat hunting, and DFIR engagements across Indian BFSI, government, and enterprise clients. Articles under this byline are collaborative pieces written, reviewed, and fact-checked by multiple Macksofy trainers to ensure technical accuracy and exam-relevance.


Active practitioner certifications across the trainer cohort: OSCP, OSWE, OSEP, OSED, OSCC, CEH v13 AI, CHFI, CTIA, CPENT, ECIH, CCISO, SOC-200 (OSDA), CompTIA Security+ / Network+ / CySA+ / Linux+. Commercial engagement experience covers penetration testing, red team operations, SOC analysis, threat hunting, and DFIR for Indian BFSI, fintech, government, and MSSP clients.

HackTheBox Writeup – Time
New High-Severity Vulnerabilities Discovered in Cisco IOx and F5 BIG-IP Products

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

macksofy_white (1)

Welcome To Macksofy Technologies Cyber Security Training Certification Courses Macksofy Ethical Hacking Training Institute develops and delivers proprietary vendor neutral professional certifications like for the cyber security industry.

Popular Courses

  • SEC 100 Course
  • Certified Ethical Hacker (CEH) Version 13
  • PEN 200 Course
  • Penetration Testing Professional CPENT
  • Training Locations

Useful Links

  • Privacy Policy
  • Terms & Condition
  • Refund and Returns Policy

Get Contact

  • Phone: +91-9930824239
  • E-mail: services@macksofy.com
  • Location: Mumbai | Hyderabad | Dubai | Oman | Canada [elfsight_whatsapp_chat id=”1″]
Icon-facebook Icon-linkedin2 Icon-instagram Icon-twitter

Disclaimer: Some graphics used on this website are sourced from public domains and are freely available for use.
This site may also contain copyrighted material whose use has not always been specifically authorized by the copyright owner.
All product names, trademarks, and brands mentioned are the property of their respective owners. Certification titles referenced are trademarks of the issuing organizations.

References to companies, products, and services on this website are for identification purposes only. We do not own, claim copyright over, or have explicit permission to use these names, logos, or trademarks, and their inclusion does not imply endorsement.

For further information or concerns, please contact us directly.

©2024. All rights reserved by Macksofy Technology.
[elfsight_whatsapp_chat id="1"]
Macksofy TrainingsMacksofy Trainings

Sign in

Lost your password?

Sign up

Already have an account? Sign in