<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Arbitrary File Read on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/arbitrary-file-read/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 20 Sep 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/arbitrary-file-read/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Down</title><link>https://wearethebug.dev/posts/vl-down/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-down/</guid><description>Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.</description></item><item><title>VULNLAB: Race</title><link>https://wearethebug.dev/posts/vl-race/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-race/</guid><description>Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, but its password is weak. The endpoint leaks credentials for the Grav CMS admin panel, which is accessible to a low-privilege user with permission to create web server backups. The attacker exploits the backup functionality to retrieve the rest token for a user with privileges to add a proxy and install themes. The attacker adds a proxy to intercept the response, uploads a custom theme, and gets a reverse shell. After gaining a reverse shell, the attacker is able to read sensitive files using a hardcoded password for the max user account. The max user account is a racers group member, which has write permission over a file vulnerable to a time-of-check / time-of-use vulnerability in a cron script. As an attacker, we will create named pipes to suspend execution and replace the file, thereby gaining command execution as root.</description></item></channel></rss>