Reactor from HackTheBox features React2Shell, the pre-auth deserialization RCE in React Server Components, hashes in a SQLite DB, and a root process left running with the NodeJS inspector open.
0xdf.gitlab.io
HTB: Reactor
Reactor is a Linux box running a nuclear reactor monitoring dashboard built on NextJS. I’ll pull the framework and React versions out of the JavaScript chunks served to the browser, and find that the site is vulnerable to React2Shell, a pre-authentication flaw where React Server Components unsafely deserialize data from server function requests, giving remote code execution and a shell. In the application directory I’ll find a SQLite database with password hashes that crack to give the next user. To escalate, I’ll find a monitoring script running as root with the NodeJS inspector listening on localhost, and tunnel to it to run code inside that root process using the Chrome DevTools Protocol. I’ll also show to do the root step using node from the command line, and how it can be done directly from the foothold skipping user.