HackTheBox Writeup — Hawk

NMAP Results

FTP Login (Anonymous)

Web Service (Port 80)

Exploting Drupal

User Flag

Privelege Escalation

>>>import os


python3 exploit.py -H

Root Flag

Vulnerabilities Used To Solve This Box

  • Anonymous FTP Login which leaks an OpenSSL file containing password for Admin Login on Drupal
  • RCE on Drupal by enabling PHP Filter and posting PHP Codes
  • User Password on Drupal Config File which leads to SSH Connection to the user Daniel
  • Vulnerable H2 Database which leads to RCE as Root




