
From deobfuscating code.js to root, CVE-2023-0386
| port | service | details |
|---|---|---|
| 22/tcp | ssh | syn-ack ttl 63 OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0) |
| 80/tcp | http | syn-ack ttl 63 nginx 2million.htb |
I added 2million.htb to my /etc/hots file
I performed a path discovery across 2million.htb using gobuster
During enumeration, I discovered the /invite endpoint

After navigating the /invite page

While inspecting the page, I noticed it loaded a Javascript file named inviteapi.min.js contained obfscated code :
eval(function(p,a,c,k,e,d){e=function(c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('1 i(4){h 8={"4":4};$.9({a:"7",5:"6",g:8,b:\'/d/e/n\',c:1(0){3.2(0)},f:1(0){3.2(0)}})}1 j(){$.9({a:"7",5:"6",b:\'/d/e/k/l/m\',c:1(0){3.2(0)},f:1(0){3.2(0)}})}',24,24,'response|function|log|console|code|dataType|json|POST|formData|ajax|type|url|success|api/v1|invite|error|data|var|verifyInviteCode|makeInviteCode|how|to|generate|verify'.split('|'),0,{}))
I deobfuscated the code using de4js, which produced the following readable JavaScript:

function verifyInviteCode(code) {
var formData = {
"code": code
};
$.ajax({
type: "POST",
dataType: "json",
data: formData,
url: '/api/v1/invite/verify',
success: function (response) {
console.log(response)
},
error: function (response) {
console.log(response)
}
})
}
function makeInviteCode() {
$.ajax({
type: "POST",
dataType: "json",
url: '/api/v1/invite/how/to/generate',
success: function (response) {
console.log(response)
},
error: function (response) {
console.log(response)
}
})
}
makeInviteCode() : generates a new invite code
verefyInviteCode(code) : checks if a code is valid
and to understood more, I intercepted the verification request :

the API uses JSON responses
I went to the browser console and executed makeInviteCode()

I noticed that data were encrypted in ROT13 cipher

Atfer decryption, I found the endpoint /api/v1/invite/generate, I then generated the invite code

Base64 Deryption

Key
The key 2F4BN-YI8OH-B0SCL-L8OE6 was inserted and accpeted successfuly

Regisitration

Home Page

Access Page
No many pages on this site work properly, the access page is where things get interesting

API Endpoints Enumeration
I uplaod vpn file by clicking on connection pack button, and intecrepted the GET request

I then executed a curl request with verbose and silent options to enumerate availaible API endpoints


The server responded withJSON list ofAPI endpoints
The admin had 3 API endpoints with GET, POST and PUT methods
When I attempted to generate admin key with the admin ednpoint /api/v1/admin/vpn/generate, the key was not generated due to I was not the admin, and the first asmin endpoint /api/v1/admin/auth confirmed this


After discovering the correct PUT request format with Content-Type: application/json and the required parameters, I successfully escalated my user to an administrator