Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TwoMillion-Machine-Writeup — From deobfuscating code.js to root, CVE-2023-0386 | Kitploit
Tools/GitHubGitHub/anxs3c/twomillion-machine-writeup
Privilege EscalationReconnaissanceExploitationLateral MovementReverse EngineeringWeb Application ExploitationCTFPenetration TestingLearning & EducationLabs & Practice
GitHubanxs3c/twomillion-machine-writeup
173 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

TwoMillion-Machine-Writeup

From deobfuscating code.js to root, CVE-2023-0386

View Repository

About Machine

TwoMillion is an Easy difficulty Linux box that was released to celebrate reaching 2 million users on HackTheBox. The box features an old version of the HackTheBox platform that includes the old hackable invite code. After hacking the invite code an account can be created on the platform. The account can be used to enumerate various API endpoints, one of which can be used to elevate the user to an Administrator. With administrative access the user can perform a command injection in the admin VPN generation endpoint thus gaining a system shell. An .env file is found to contain database credentials and owed to password re-use the attackers can login as user admin on the box. The system kernel is found to be outdated and CVE-2023-0386 can be used to gain a root shell

Scan Results

portservicedetails
22/tcpsshsyn-ack ttl 63 OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0)
80/tcphttpsyn-ack ttl 63 nginx 2million.htb

host setup

I added 2million.htb to my /etc/hots file


Path Discovery

I performed a path discovery across 2million.htb using gobuster

During enumeration, I discovered the /invite endpoint


After navigating the /invite page


While inspecting the page, I noticed it loaded a Javascript file named inviteapi.min.js contained obfscated code :

eval(function(p,a,c,k,e,d){e=function(c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('1 i(4){h 8={"4":4};$.9({a:"7",5:"6",g:8,b:\'/d/e/n\',c:1(0){3.2(0)},f:1(0){3.2(0)}})}1 j(){$.9({a:"7",5:"6",b:\'/d/e/k/l/m\',c:1(0){3.2(0)},f:1(0){3.2(0)}})}',24,24,'response|function|log|console|code|dataType|json|POST|formData|ajax|type|url|success|api/v1|invite|error|data|var|verifyInviteCode|makeInviteCode|how|to|generate|verify'.split('|'),0,{}))

Deobfuscation

I deobfuscated the code using de4js, which produced the following readable JavaScript:


function verifyInviteCode(code) {
    var formData = {
        "code": code
    };
    $.ajax({
        type: "POST",
        dataType: "json",
        data: formData,
        url: '/api/v1/invite/verify',
        success: function (response) {
            console.log(response)
        },
        error: function (response) {
            console.log(response)
        }
    })
}

function makeInviteCode() {
    $.ajax({
        type: "POST",
        dataType: "json",
        url: '/api/v1/invite/how/to/generate',
        success: function (response) {
            console.log(response)
        },
        error: function (response) {
            console.log(response)
        }
    })
}

makeInviteCode() : generates a new invite code
verefyInviteCode(code) : checks if a code is valid

and to understood more, I intercepted the verification request :


the API uses JSON responses


Generating invite code and ROT13 decryption

I went to the browser console and executed makeInviteCode()


I noticed that data were encrypted in ROT13 cipher


Atfer decryption, I found the endpoint /api/v1/invite/generate, I then generated the invite code


Base64 Deryption

Key
The key 2F4BN-YI8OH-B0SCL-L8OE6 was inserted and accpeted successfuly

Regisitration

Home Page

Access Page
No many pages on this site work properly, the access page is where things get interesting

API Endpoints Enumeration
I uplaod vpn file by clicking on connection pack button, and intecrepted the GET request


I then executed a curl request with verbose and silent options to enumerate availaible API endpoints



The server responded withJSON list ofAPI endpoints

The admin had 3 API endpoints with GET, POST and PUT methods

When I attempted to generate admin key with the admin ednpoint /api/v1/admin/vpn/generate, the key was not generated due to I was not the admin, and the first asmin endpoint /api/v1/admin/auth confirmed this





Web Application Vertical Privilege Escalation: escalate current standard user to administrator


After discovering the correct PUT request format with Content-Type: application/json and the required parameters, I successfully escalated my user to an administrator

Download Tool