HackTheBox "Analytics"

December 5th, 2023

Info Card
Info Card

Introduction

Analytics is an easy box released on October 7th, 2023 by 7u9y and TheCyberGeek.

User Own

An Nmap scan reveals a website at analytical.htb:

The website has a login page which goes to the data.analytical.htb subdomain. This login page is using Metabase. A quick search for Metabase exploits gives us CVE-2023-38646. A GitHub repository demonstrating this CVE can be used to gain a reverse shell.

This reverse shell logs in as metabase. Doing a quick check of env reveals a plaintext password:

The META_USER and META_PASS credentials can be used to login to the machine through SSH:

USER OWN

System Own

The system is running Ubuntu 22.04.3 LTS, which is vulnerable to CVE-2021-3493. Running this exploit on the machine will grant root access.

SYSTEM OWN

And that's the box!

PWNED

Last updated