{"id":72,"date":"2022-07-17T22:08:23","date_gmt":"2022-07-17T22:08:23","guid":{"rendered":"http:\/\/moveax.me\/?p=72"},"modified":"2022-08-31T19:01:09","modified_gmt":"2022-08-31T19:01:09","slug":"nebula-level18-a-newbies-approach","status":"publish","type":"post","link":"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level18-a-newbies-approach\/","title":{"rendered":"Nebula Level18: A Newbie\u2019s Approach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On the present challenge, level18, there are three ways of exploiting the program. I\u2019m going to take the easiest one<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What you\u2019ll need to know\u2026<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>\u2013rcfile option<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Level18<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After analyzing the&nbsp;<a href=\"\">code<\/a>&nbsp;presented, I was able to identify one vulnerability on login function. In this function, the program tries to open the password file, present in&nbsp;<code>\/home\/flag18<\/code>. If you can open it, you\u2019ll have a file pointer to the password file, but if it can\u2019t, it\u2019ll log you in without any password.<br>So, the trick here is to use up every file descriptor available in the system. To check the number of file descriptors in use and the maximum, one can use the command&nbsp;<code>sysctl fs.file-nr<\/code>.<br>My approach will be: create an SSH connection to the level18 account and start the flag18 program, before we exhaust the system. Then, I\u2019ll write a small program that creates many file descriptors and never destroy them (open a file without close it), and run it. After this I\u2019ll return to my SSH connection and type the login command. Because there are no more file descriptors available it\u2019ll log me in. Let\u2019s see if this worked.<\/p>\n\n\n\n<figure class=\"wp-block-image\" id=\"attachment_819\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/level18c.png\" alt=\"level18.c\" class=\"wp-image-819\"\/><figcaption>level18.c<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s run&nbsp;<code>for i in {1..200}; do .\/level18 &amp; done<\/code>&nbsp;in order to use every file descriptor.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/nomorefds.png\" alt=\"nomorefds\" class=\"wp-image-821\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Here you can see that the system can\u2019t create more file pointers.<\/p>\n\n\n\n<figure class=\"wp-block-image\" id=\"attachment_820\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/SSH.png\" alt=\"SSH connection\" class=\"wp-image-820\"\/><figcaption>SSH connection<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So we can start a shell, and because we are already logged in, we need to kill all the processes created before. For this, use&nbsp;<code>for i in {1..200};do kill \"%$i\"; done<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, start a shell.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/SSH_shell.png\" alt=\"SSH shell\" class=\"wp-image-822\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">From here we can get already the flag.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/SSH_getflag.png\" alt=\"getflag\" class=\"wp-image-823\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Or we can see the password (I tried to login with this password but I couldn\u2019t).<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/SSH_pass.png\" alt=\"Password\" class=\"wp-image-824\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">We can even compile a SUID program\u2026<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/SSH_suid.png\" alt=\"SUID\" class=\"wp-image-825\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Now we can exit this shell and run our SUID, so we don\u2019t have the trouble to do all the previous steps in order to get a shell.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"wp-content\/uploads\/2018\/07\/result_level18.png\" alt=\"Result level18\" class=\"wp-image-826\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Only one challenge left!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Challenges completed: 19\/20<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Delete the code that allows to login without password?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walkthrough<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/www.youtube.com\/watch?v=tC7e9jySIk4=03m57s\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Further Reading<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.kernel.org\/doc\/Documentation\/sysctl\/fs.txt\">sysctl<\/a><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>On the present challenge, level18, there are three ways of exploiting the program. I\u2019m going to take the easiest one What you\u2019ll need to know\u2026&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/giga-rapid.com\/esites\/moveaxme\/nebula-level18-a-newbies-approach\/\">Continue reading<span class=\"screen-reader-text\">Nebula Level18: A Newbie\u2019s Approach<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-72","post","type-post","status-publish","format-standard","hentry","category-nebula","category-uncategorized","entry"],"_links":{"self":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/72","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/comments?post=72"}],"version-history":[{"count":2,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/72\/revisions"}],"predecessor-version":[{"id":107,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/posts\/72\/revisions\/107"}],"wp:attachment":[{"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/media?parent=72"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/categories?post=72"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/giga-rapid.com\/esites\/moveaxme\/wp-json\/wp\/v2\/tags?post=72"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}