[THM] Year of the Rabbit - Web Enumeration and Privilege Escalation

Summary

This easy-level machine requires basic knowledge of JavaScript, Web request analysis, file forensics, brute force attacks, and privilege escalation.

Reconnaissance

The first recon step was a port scan against the host using Nmap. Nmap

Web page

After that, we visited the Web page and landed on the default Apache Server splash screen. A directory brute force attack revealed a few directories and pages. Fuzzing

Browsing the /assets directory on the application, we found the following file listing: assets

The first one is a video containing the classic Rickroll meme, while the second - style.css - is a stylesheet whose code has a comment pointing to a secret PHP page. CSS code

Accessing the page, we noticed a chain of redirects that eventually land on the Rickroll. Among them was an alert stating the browser's JavaScript needed to be disabled to avoid the window.location call. JS alert

However, that wasn't actually necessary. Using the browser's network console, we spotted an interesting call to an intermediate page with a parameter pointing to a hidden directory. Redirects

Following it, we found another file listing. Hidden directory

Opening Hot_Babe.png gives us the image below. Hot babe

I saved it locally and, to inspect it, opened its contents as plain text — VSCode, VIM, VI, or even cat on Linux / type on Windows all work. At the end of the file there's a message with an FTP username and a few candidate passwords.

Exploitation

Brute force attack

Exporting all the passwords to a text file lets us brute force the credentials for the file transfer service. I used THC Hydra with the following command:

hydra -l ftpuser -P .exploit/passwords.txt ftp://<IP>:21

After logging into FTP we only see a file named Eli's_Creds.txt. FTP

Remote access

Downloading the file above shows what looks like a strange piece of code, but on a closer look it's easy to recognize the pattern used by the Brainfuck programming language. Running it through an online compiler reveals Eli's credentials for remote access.

Connecting remotely to the server over SSH, we get a banner with a message left by root for the user Gwendoline. SSH banner

Searching for that secret message we manage to find it and obtain the login credentials for that user. Hidden message

Logging in as Gwendoline and going to her home directory gets us the user flag.

Privilege escalation

To enumerate privilege escalation vectors I basically used two commands:

  • sudo -l - to enumerate files that can be executed with root permissions.
  • sudo -v - to enumerate the SUDO version and check for known CVEs.

Privesc

The output shows we can run the following command as root:

/usr/bin/vi /home/gwendoline/user.txt

And from the version we identify it's vulnerable to CVE-2019-14287, which can be exploited with the following command:

sudo -u#-1

Combining these findings gives us the following privilege escalation vector:

sudo -u#-1 /usr/bin/vi /home/gwendoline/user.txt

On the text editor screen, just type :!sh and hit Enter. Privesc

The final flag can be found in the /root folder.

TryHackMeWebPrivilege Escalation