HackTheBox "Analytics"
December 5th, 2023

Introduction
Analytics is an easy box released on October 7th, 2023 by 7u9y and TheCyberGeek.
User Own
An Nmap scan reveals a website at analytical.htb:
The website has a login page which goes to the data.analytical.htb subdomain. This login page is using Metabase. A quick search for Metabase exploits gives us CVE-2023-38646. A GitHub repository demonstrating this CVE can be used to gain a reverse shell.
This reverse shell logs in as metabase. Doing a quick check of env reveals a plaintext password:
The META_USER and META_PASS credentials can be used to login to the machine through SSH:

System Own
The system is running Ubuntu 22.04.3 LTS, which is vulnerable to CVE-2021-3493. Running this exploit on the machine will grant root access.

And that's the box!

Last updated