Analytics

Task 1 - Deploy the machine
Task 2 - Reconnaissance
2.1 - How many open TCP ports are listening on Analytics?
command
result
2.2 - What subdomain is configured to provide a different application on the target web server?
Port 80





2.3 - What application is running on data.analytical.htb?

2.4 - What version of Metabase is the target running?

2.5 - What is the 2023 CVE ID assigned to the pre-authentication, remote code execution vulnerability in this version of Metabase?
2.6 - What is the value of the setup-token used by this Metabase instance?
setup-token used by this Metabase instance?2.7 - Which Metabase API endpoint is used to execute arbitrary commands using the token?

2.8 - Which user is the Metabase application running as?


2.9 - Which environment variable contains the password for the metalytics user?

Task 3 - Find user flag
3.1 - Submit the flag located in the metalytics user's home directory.


3.2 - What kernel version is installed on the host system?
3.3 - What Ubuntu release is the system running?

3.4 - What component used by the Ubuntu operating system on the target system is vulnerable to a privileges escalation vulnerability assigned two 2023 CVEs?
Task 4 - Find root flag
4.1 - Submit the flag located in the root user's home directory.


Last updated
