<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Motd on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/motd/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Mon, 13 Mar 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/motd/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Dump</title><link>https://wearethebug.dev/posts/vl-dump/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-dump/</guid><description>Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download functionality of pcap files. The machine demonstrates command argument injection through file naming to obtain initial remote code execution as www-data. Enumeration of the system reveals a sudo rule with tcpdump that can be abused for arbitrary file writes to the system and bypassing AppArmor security policy restrictions. With arbitrary file writes players can write malicious Message of The Day configurations that execute as root during system login.</description></item></channel></rss>