{"id":44,"date":"2012-07-19T23:11:24","date_gmt":"2012-07-20T06:11:24","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=44"},"modified":"2012-07-19T23:11:24","modified_gmt":"2012-07-20T06:11:24","slug":"blowfish-level2-where-to-start-looking","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=44","title":{"rendered":"Blowfish Level2 &#8211; Where to start looking"},"content":{"rendered":"<p>Welcome back to another post, another level. \u00a0Today we&#8217;re going to be solving level2 of the <a title=\"Blowfish\" href=\"http:\/\/blowfish.smashthestack.org:81\/\" target=\"_blank\">Blowfish<\/a> wargame from <a title=\"Smash The Stack\" href=\"http:\/\/www.smashthestack.org\" target=\"_blank\">Smash The Stack<\/a>. \u00a0As usual, the final password for level3 will be stripped out and replaced with Y&#8217;s. \u00a0Also, I assume you already have access to level2 on Blowfish. \u00a0Now let&#8217;s get started.<\/p>\n<p>As the end of level1 stated, level2 is accessed via ssh on port 2222 for blowfish.smashthestack.org, so let&#8217;s log in. \u00a0Upon login, a quick directory listing shows a README, so let&#8217;s check that for direction.<\/p>\n<blockquote><p>sh-3.2$ ls<br \/>\npublic_html README<br \/>\nsh-3.2$ more README<\/p>\n<p>There is a backdoor to the next level hidden somewhere on this system,\u00a0find it, and get the pass for level3 from \/pass\/level3<\/p>\n<p>&#8211; http:\/\/smashthestack.org\/viewtopic.php?id=436<\/p>\n<p>hint: `man find`<\/p><\/blockquote>\n<p>Alright, it looks like we&#8217;re looking for a hidden backdoor, and maybe this is the big point of the level. \u00a0What we need to look for is a program that runs as user level3, even when we execute it, and let&#8217;s us execute it because it has group for level2. \u00a0To do this, we will use the linux &#8220;find&#8221; command. \u00a0Our command and results are as follows:<\/p>\n<blockquote><p>sh-3.2$ find \/ -group level2 -user level3 2&gt;\/dev\/null<br \/>\n\/var\/tmp\/level4.c.swp<br \/>\n\/var\/tmp\/level3.swp<br \/>\n\/var\/tmp\/core.9788<br \/>\n\/var\/tmp\/level3.swo<br \/>\n\/var\/tmp\/.svz<br \/>\n\/var\/tmp\/hossam.swp<br \/>\n\/var\/tmp\/testme<br \/>\n\/var\/tmp\/.svy<br \/>\n\/var\/tmp\/apple<br \/>\n\/var\/tmp\/jnk.txt.swp<br \/>\n\/var\/tmp\/fdsa<br \/>\n\/usr\/bin\/false<\/p><\/blockquote>\n<p>Now, judging by the banner we got when logging in, we can assume all those files in \/var\/tmp aren&#8217;t for the game, they&#8217;re just left over from previous users. \u00a0So let&#8217;s look at \/usr\/bin\/false.<\/p>\n<blockquote><p>sh-3.2$ ls -la \/usr\/bin\/false<br \/>\n-r-sr-x&#8212; 1 level3 level2 607288 2007-12-02 17:13 \/usr\/bin\/false<\/p><\/blockquote>\n<p>Looking at the permissions, we can see the &#8220;s&#8221; is set for setuid, which enables the program to run with the permissions of the owner of the program, rather than those of the user who ran the program. \u00a0Additionally we can see from the group permissions columns, group has permission to execute the program. \u00a0This is just what we were looking for: a program owned by level3, SUID to run as level3, and set with group level2 with group execution permissions! \u00a0So let&#8217;s run it and see what happens:<\/p>\n<blockquote><p>sh-3.2$ \/usr\/bin\/false<br \/>\nStand-alone shell (version 3.7)<br \/>\n&gt; whoami<br \/>\nlevel3<br \/>\n&gt; more \/pass\/level3<br \/>\nYYYYYYYYYYYYY<\/p><\/blockquote>\n<p>There we have it, done with level2! \u00a0Point of the level was obviously searching, using the find command to find files which can be executed by you and used to gain higher privileges, through legitimate or illegitimate execute. \u00a0Finding programs such as this is often the first step in looking for vulnerabilities as one of the main goals in exploiting a vulnerability is often escalation of privileges.<\/p>\n<p>That wraps it up here for Blowfish Level2. \u00a0Check back often for more postings and wargame analysis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome back to another post, another level. \u00a0Today we&#8217;re going to be solving level2 of the Blowfish wargame from Smash The Stack. \u00a0As usual, the final password for level3 will be stripped out and replaced with Y&#8217;s. \u00a0Also, I assume &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=44\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[16,6,4],"tags":[51,22,21,13,49,47],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/44"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=44"}],"version-history":[{"count":3,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/44\/revisions"}],"predecessor-version":[{"id":47,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/44\/revisions\/47"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=44"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=44"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=44"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}