{"id":58,"date":"2022-07-17T22:04:51","date_gmt":"2022-07-17T22:04:51","guid":{"rendered":"http:\/\/moveax.me\/?p=58"},"modified":"2022-08-31T19:01:33","modified_gmt":"2022-08-31T19:01:33","slug":"nebula-level04-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level04-a-newbies-approach\/","title":{"rendered":"Nebula Level04: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">With level04 challenge we are supposed to exploit the weak permissions of flag04\u2019s file. As always, my main objective is to get a shell under the flag04 account.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Symbolic links<\/li><li>Basic Unix commands<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level04<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For this challenge, we have some&nbsp;<a href=\"\">code<\/a>&nbsp;to analyze. By reading this code, it\u2019s possible to understand that flag04 takes one argument by looking at the first if condition. From the analysis of the second condition, we can conclude that if our file\u2019s name contain the word \u201ctoken\u201d (due to the&nbsp;<a href=\"https:\/\/linux.die.net\/man\/3\/strstr\">strstr<\/a>), it won\u2019t be read.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From here on, you just need to feed flag04 some program that you actually have permissions\u2026or not! Let\u2019s hold this thought.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/ls.png\" alt=\"ls\" class=\"wp-image-588\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Once more, flag04 is a SUID program, owned by the user flag04. We\u2019ve seen this kind of file, for example, in&nbsp;<a href=\"nebula-level01\/\">level 1<\/a>. This means that when we are running flag04 program, we are doing it as if we were flag04 user. But because token is also owned by flag04 user, we can\u2019t read it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what if\u2026 we could make a file owned by us point to this token and feed that same file to flag04 program? Of course I\u2019m talking about symbolic links, so let\u2019s try it. We need a folder where we can actually write, which will be level04 folder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The option \u201c-T\u201d makes the symbolic link target the token file. So, basically, this will create the moveaxme symbolic link and make it point to token.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/solving_level04-1.png\" alt=\"Solving level04\" class=\"wp-image-591\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now we have our symbolic link. Let\u2019s feed it to flag04 and see what happens.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/solution_level04.png\" alt=\"Level04's solution\" class=\"wp-image-592\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Neither the token file belongs to us, nor we have permissions to read it, but even that way we were able to see the content of this file. But wait, how does this help me getting a shell?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Maybe it\u2019s the password of flag04 account\u2026<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/05\/flag04_user.png\" alt=\"Result\" class=\"wp-image-593\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Bingo!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 5\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Same advice as&nbsp;<a href=\"nebula-level00\/\">level00<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>With level04 challenge we are supposed to exploit the weak permissions of flag04\u2019s file. As always, my main objective is to get a shell under&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level04-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level04: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-58","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/58","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=58"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/58\/revisions"}],"predecessor-version":[{"id":113,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/58\/revisions\/113"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=58"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=58"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=58"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}