<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Arbitrary File Upload on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/arbitrary-file-upload/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 11 Oct 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/arbitrary-file-upload/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Ten</title><link>https://wearethebug.dev/posts/vl-ten/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ten/</guid><description>Ten is a Hard difficulty Linux machine that simulates a misconfigured shared-hosting environment. Players enumerate a public sign-up portal that provisions FTP accounts, abuse weak MySQL/FTP integration to pivot into a real local user, and finally achieve root by poisoning an etcd-driven Apache configuration reload.</description></item><item><title>VULNLAB: Race</title><link>https://wearethebug.dev/posts/vl-race/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-race/</guid><description>Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, but its password is weak. The endpoint leaks credentials for the Grav CMS admin panel, which is accessible to a low-privilege user with permission to create web server backups. The attacker exploits the backup functionality to retrieve the rest token for a user with privileges to add a proxy and install themes. The attacker adds a proxy to intercept the response, uploads a custom theme, and gets a reverse shell. After gaining a reverse shell, the attacker is able to read sensitive files using a hardcoded password for the max user account. The max user account is a racers group member, which has write permission over a file vulnerable to a time-of-check / time-of-use vulnerability in a cron script. As an attacker, we will create named pipes to suspend execution and replace the file, thereby gaining command execution as root.</description></item></channel></rss>