Recommended Free Tools
To solve HTB Busqueda without Metasploit, follow the machine’s documented chain: identify the web application, investigate its command-injection surface, use discovered credentials to reach local Gitea, inspect Docker-related clues, then analyze the privileged system-checkup script for a relative-path weakness. Hack The Box classifies Busqueda as an Easy Linux machine and marks it retired. This is a reasoning-focused walkthrough of that route, not a claim that a particular payload or command sequence has been tested.
What the documented Busqueda route involves
Hack The Box’s machine synopsis describes Busqueda as an Easy Linux machine involving “a command injection vulnerability present in a Python module.” The synopsis then outlines credential discovery in a Git configuration file, access to local Gitea, Docker-container enumeration to find Gitea administrator credentials, and a root-level weakness in a system-checkup script. The machine page lists its release date as 08/04/2023; its displayed date format does not establish the locale, so it is best left as shown. Hack The Box: Busqueda
A third-party result associates the application with Searchor 2.4.0, but that is secondary information, not a detail established by the official synopsis. Confirm the application and version from the target’s own evidence before treating that identification as decisive. 0xdf: Busqueda write-up
1. Identify the exposed application and its input flow
Start with ordinary host and web-service enumeration, then inspect the site as a user would: note its purpose, visible inputs, responses, and any identifying version or framework information. The objective is not simply to find a product name; it is to understand which user-controlled value the application may pass into a command.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- Record the services and application details you actually observe rather than assuming a service or version from a write-up.
- Test how the application responds to normal input, unusual characters, and invalid values, keeping a record of the request and response.
- When a Python-backed feature appears to invoke a system utility, trace whether the input is treated as data or incorporated into a command string.
Command injection occurs when untrusted input changes the command that an application executes. The key reasoning step is to establish a connection between a particular input and command execution; a product name or version alone does not prove the behavior. The official synopsis confirms command injection in a Python module on this machine, but it does not publish the vulnerable line, exact request, or reliable payload. Do not assume one without evidence from the application or an authoritative vulnerability reference.
2. Turn the foothold into a usable user session
Once the injection point is understood, the practical goal is to obtain a stable, user-level shell rather than stop at a one-off command result. Keep the transition deliberate: distinguish proof that a command ran from proof that you have an interactive session, and use only a connection method available in the lab environment. The official synopsis establishes user-level access as the result of the foothold, but does not specify a tested payload or shell procedure.
After gaining access, establish the current user and host context, then inspect accessible files and configuration. This keeps later findings attributable to their source and prevents a credential or privilege assumption from being mistaken for a confirmed fact.
3. Find and track the Git configuration credentials
HTB’s synopsis says credentials are discovered in a Git configuration file. Inspect relevant Git configuration and repository metadata that the compromised account can read. Configuration can retain authentication details used for remote repository access; if credentials appear, record where they came from and what service or account they plausibly apply to.
- Separate confirmed credentials from guesses about where they work.
- Try a discovered credential only against services or accounts supported by the evidence.
- Do not publish machine-specific passwords, tokens, or flag values.
This is a pivot in the documented chain, not an invitation to assume that every Git setting contains a password. The clue matters because it leads to the local Gitea service identified by HTB, where the credentials can be tested in context.
4. Use the local Gitea service as the next evidence point
With the Git-derived credentials in hand, inspect the target’s local services and determine whether Gitea is reachable from the machine. The official route connects credential discovery to access to local Gitea. Treat that access as a way to understand the host’s repositories and the privileged helper mentioned later, rather than as proof that a particular repository or file is present until you find it.
Rank #4
- Used Book in Good Condition
Repositories can expose source code, configuration, and the conventions used by local administrative scripts. Follow the evidence from the account and repository you can actually access. In particular, keep a copy of the system-checkup script’s source for review and note its repository location and execution context.
5. Relate Docker enumeration to the Gitea administrator account
HTB describes running a system-checkup script with root privileges for a specific user, then enumerating Docker containers to discover credentials for Gitea’s administrator account. Keep those steps distinct: the script’s permitted execution is one fact; container inspection is a separate route to additional credentials. Look for container metadata and configuration that the current permissions allow you to inspect, and determine whether any discovered secret is explicitly associated with Gitea administration.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Do not treat the mere presence of Docker as an escalation. The useful finding in this machine’s documented chain is credential disclosure tied to a specific service account. Validate the account context, then use the credential in Gitea only if the target evidence supports that connection. The official synopsis does not provide the credential values or the exact container command sequence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Inspect system-checkup for the root-level relative-path weakness
The final documented step is source analysis: HTB says a relative-path reference in the system-checkup script can be abused for root-level remote code execution. A relative path is resolved in relation to the process’s working directory or environment rather than naming a fixed absolute location. If a privileged script invokes a program by a relative name, and an attacker can influence which matching program is found, the privileged process may execute attacker-controlled code instead of the intended utility.
For this machine, establish the exact conditions from the script and its execution context before drawing the conclusion. Inspect which name is resolved relatively, how the script is launched, which directory it runs from, what environment and permissions apply, and whether the user can influence the resolution location. The official synopsis does not expose the vulnerable line, required directory, or exact command, so a generic relative-path explanation should not be mistaken for a verified command recipe.
This is a privilege-boundary failure: a script permitted to run with root privileges trusts a name whose resolution may be influenced by a less-privileged user. The lesson is to reason about both the script’s source and the context in which the privileged process executes it.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhy a manual approach is useful here
Metasploit is not required to understand the route. Manual service and application inspection, careful request observation, shell interaction, credential tracking, and source review make the cause-and-effect chain visible. For learning, choose methods that show what input is sent, what command flow is being tested, and what evidence supports each transition; that is a practical teaching choice, not an official ranking of tools.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

