RedCross
Overview Machine author: ompamo. Debian. A maze box with multiple paths at every stage. Key concepts: cookie reuse between subdomains, NSS + PostgreSQL as the backend for system accounts, command injection in a setuid wrapper, and a x64 ROP buffer overflow. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 +- XSS (contact form) --------------+ admin.redcross.htb +- SQLi -> crack charles -----------+-> reuse PHPSESSID +- guest account -> cookie ---------+ | v +- Haraka SMTP RCE ---------------+ shell as penelope + +-> user.txt +- cmd injection (iptctl) -> www-data -> PostgreSQL creds -> add a user gid=1000 | v +- gid=27 (sudo) -> sudo su ------+ (unintended) root +- unixnssroot -> uid=0 -> su ----+ (intended) +- BOF in iptctl (setuid) -> ROP -+ (BOF path) | v root.txt Reconnaissance 1 2 3 22/tcp ssh OpenSSH 7.4p1 Debian 10+deb9u3 (Debian 9 Stretch) 80/tcp http Apache 2.4.25 443/tcp ssl/http Apache 2.4.25 Script scans (-sC) hang, so there is a WAF. Run only -sV. HTTP GET / redirects (301) to https://intra.redcross.htb. Add it to /etc/hosts. Domain and directory enumeration: ...