Target IP: anthem.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Anthem” is a Windows Server 2019 box that demonstrates the risks of Information Disclosure and Misconfigured File Permissions. We gain initial access by combining a password leaked in robots.txt with a username harvested from a public blog post (sg). Remote Desktop Protocol (RDP) is used for entry. Privilege escalation is achieved by exploiting weak Access Control Lists (ACLs) on a hidden backup folder, allowing a standard user to grant themselves “Full Control” over a file containing the Administrator’s password.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port/service enumeration.
- T1592 (Gather Victim Host Information): Harvesting email/usernames from blog posts.
- T1078 (Valid Accounts): Leveraging leaked credentials for RDP access.
- T1222 (File and Directory Permissions Modification): Modifying NTFS ACLs to access a locked file.
- T1552 (Unsecured Credentials): Recovering plaintext passwords from backup files.
2. Operational Setup
OpSec Note: “No tricks, just reality.” Set up your environment correctly first.
Host Configuration
# Verify connection
ping -c 1 10.10.x.x
# Add to hosts file
echo "10.10.x.x anthem.thm" | sudo tee -a /etc/hostsWorkspace
- Pane 1 (Recon):
nmap, browser. - Pane 2 (Access):
xfreerdp. - Pane 3 (Notes): Documentation.
3. Enumeration: “What do we see?”
A. Network Scanning
We start with a service scan to identify the landscape.
nmap -sC -sV -oA nmap/anthem anthem.thmResults:
- 80/tcp (HTTP): Microsoft HTTPAPI 2.0. Hosting a web app.
- 3389/tcp (RDP): Windows Terminal Services.
- Info Leaked: Hostname
WIN-LU09299160F, DomainWORKGROUP(Standalone).
B. Web Enumeration
We browse to port 80. It looks like a corporate blog.
1. Robots.txt Disclosure:
Checking standard files is mandatory.
http://anthem.thm/robots.txt
User-agent: *
Disallow: /umbraco/
UmbracoIsTheBest!- Observation: The string
UmbracoIsTheBest!is incredibly suspicious. It doesn’t fit the syntax of a robot rule. - Hypothesis: This is likely a password or a hint left by a careless admin.
- Context: “Umbraco” is a .NET-based CMS.
2. Username Harvesting: We browse the blog posts to find potential users.
- Post 1: Author “Jane Doe”, Email
JD@anthem.com. - Post 2: Mentions “Solomon Grundy”.
- Logic: Corporate username policies are usually standard.
JDmatches “Jane Doe”. Therefore, “Solomon Grundy” is likelysgorsgrundy. given theJDpattern,sgis the stronger hypothesis.
3. Hidden Flags (The “CTF” Element):
You noted flags hidden in the source code (Ctrl+U).
THM{L0L_WH0_US3S_M3T4}(Meta tags)THM{G!T_G00D}- Analysis: While these are points for the game, in a real pentest, comments in source code often leak dev notes or versions. Always check sources.
4. Initial Access: Credential Stuffing
The Chain
We have a username candidate (sg) and a password candidate (UmbracoIsTheBest!). Since RDP (Port 3389) is open, we attempt to log in directly.
Execution
We use xfreerdp, the standard Linux client for RDP.
# /v:Target /u:User /p:Password /dynamic-resolution +clipboard /cert:ignore
xfreerdp /v:anthem.thm /u:sg /p:'UmbracoIsTheBest!' /cert:ignore /dynamic-resolutionResult:
Authentication succeeds. We land on the desktop of sg.
User Flag: Located at C:\Users\sg\Desktop\user.txt.
5. Privilege Escalation: ACL Exploitation
Enumeration
Once inside, we check whoami (standard user) and systeminfo (Server 2019).
Running scripts like winPEAS is good practice, but sometimes manual browsing beats automation.
Discovery:
Navigating the C:\ drive, we check for hidden files (View -> Check “Hidden items”).
- Target:
C:\backupfolder. - File:
restore.txt.
The Problem
When trying to open restore.txt, Windows denies access.
The Vulnerability (The “Why”)
In Windows, access is controlled by ACLs (Access Control Lists).
Even if you cannot read a file, you might have the permission to change permissions on it. This is known as WRITE_DAC (Discretionary Access Control) permission.
In this specific box, the user sg (or the Users group) has been improperly granted the ability to modify the security descriptor of this file.
The Exploit (GUI Method)
- Right-Click
restore.txt-> Properties. - Go to the Security tab.
- Click Edit (to change permissions).
- Click Add -> Type
sg-> Check Names -> OK. - Select
sgin the list and check Full Control (Allow). - Click Apply.
Outcome: We have effectively rewritten the ACL to say “sg is allowed to do anything.” Open the file:
Administrator:ChangeMeBaby1MoreTimeThe Pivot
We have Administrator credentials. Log out of the sg RDP session (or open a new window) and log in as Administrator.
xfreerdp /v:anthem.thm /u:Administrator /p:'ChangeMeBaby1MoreTime' /cert:ignoreRoot Flag: C:\Users\Administrator\Desktop\root.txt -> THM{Y0U_4R3_1337}
6. Remediation (Blue Team)
As a security professional, here is how we fix this:
- Sanitize Robots.txt:
- Never put passwords, internal logic, or specific software versions in
robots.txt. It is a public file.
- Strict ACL Management:
- Backup files (
C:\backup) should be restricted to SYSTEM and Administrators only. - Audit file permissions using tools like
AccessChkoricaclsto ensure standard users do not haveWRITE_DACorFull Controlon sensitive directories.
- Username Disclosure:
- Avoid displaying direct author usernames or emails on public blogs. Use display names (e.g., “Editorial Team”) to make username guessing harder.