
Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.
Target: HackSudo Thor from VulnHub
Objective: Gain root access and read/root/proof.txt
Environment: Isolated VirtualBox lab segmented by a pfSense firewall
This repository documents a partial black-box penetration test conducted on HackSudo Thor, an intentionally vulnerable virtual machine published on VulnHub by Vishal Waghmare. The goal was to simulate a real-world attack where an outside attacker attempts to compromise an isolated internal system with the primary objective being to gain root access and read the contents of /root/proof.txt.
The assessment follows the full penetration testing lifecycle: passive reconnaissance, network discovery, enumeration, vulnerability assessment, exploitation, privilege escalation, post-exploitation, and track covering.
The primary tools used were Nmap for network scanning, Nessus for vulnerability assessment, and the Metasploit Framework as the main exploitation and post-exploitation platform. John the Ripper, Hashcat, and online Rainbow Tables were used during the password cracking stage, though all attempts were ultimately unsuccessful due to the strength of the hashing algorithm in use.
The virtual lab was built entirely in VirtualBox and designed to simulate a realistic enterprise network with three distinct security zones, all managed by a pfSense 2.7.2 firewall. The three NAT networks were configured as follows: a WAN zone simulating the public internet where the Kali attacker machine lives, a DMZ zone hosting the target machine, and an internal LAN zone containing out-of-scope machines.
Internet Zone — NatNetwork (10.0.2.0/24)
│
│ Kali Linux 2025.4 [attacker] — 10.0.2.9
│ pfSense WAN interface — 10.0.2.8
│
├── pfSense Firewall (boundary device)
│
├── DMZ Zone — DMZnat (10.0.4.0/24)
│ ├── HackSudo Thor [TARGET] — 10.0.4.3
│ └── DVWA — 10.0.4.4 (out of scope)
│
└── LAN Zone — LANnat (10.0.3.0/24)
├── Metasploitable 2 — 10.0.3.5 (out of scope)
└── Windows XP Cyberlab — 10.0.3.4 (out of scope)
Logical network topology security zones managed by pfSense
The WAN interface was assigned 10.0.2.8/24 by DHCP, the LAN interface was set to 10.0.3.1/24, and the OPT1 (DMZ) interface was set to 10.0.4.1/24. To introduce a deliberate misconfiguration into the lab, port 80 was intentionally left exposed on the pfSense WAN interface, simulating a common real-world admin panel exposure that served as the primary entry point into the internal network.
[Kali Linux — 10.0.2.9]
│
│ CSRF-aware Python brute force → admin / pfsense
▼
[pfSense webConfigurator — 10.0.2.8:80]
│
│ Firewall rules disabled → DMZ and LAN now reachable
▼
[HackSudo Thor — 10.0.4.3]
│
│ Shellshock RCE (CVE-2014-6271)
│ Apache mod_cgi → /cgi-bin/shell.sh
▼
[Meterpreter shell — www-data]
│
│ sudo -u thor /home/thor/hammer.sh
│ Command injection via eval → bash -i payload
▼
[Interactive shell — thor]
│
│ GTFOBins: sudo service ../../bin/bash
▼
[Root shell]
│
├── /root/proof.txt captured ✅
├── /etc/shadow + /etc/passwd exfiltrated
└── SSH RSA backdoor planted
Before making any contact with the target environment, information was gathered exclusively from public sources. The two primary sources were the official VulnHub entry page for HackSudo Thor and the author's public GitHub profile.
The VulnHub page confirmed the target was a Linux-based system, rated easy to medium difficulty, with the objective of finding the proof.txt flag. Reviewing the author's GitHub profile gave additional insight. Vishal Waghmare consistently designs Linux boot-to-root machines with privilege escalation as the core challenge across the entire HackSudo series. This shaped the threat model going into the active phases: HTTP and SSH services were the most likely attack surface, and the escalation path was predicted to involve sudo misconfiguration, SUID binary abuse, or exploitation of a custom service.
This kind of author pattern analysis matters in a real engagement too. Understanding how a system was likely designed and what categories of weakness its administrator is likely to repeat gives direction before a single packet is sent.
| Field | Detail |
|---|---|
| Target | HackSudo Thor |
| Author | Vishal Waghmare (@hacksudo) |
| Release | 3 August 2021 |
| Difficulty | Easy to Medium |
| OS | Linux (Debian) |
| Format | VirtualBox OVA |
| DHCP | Enabled |
| Predicted Attack Surface | HTTP, SSH, sudo misconfiguration likely |
This phase involved making direct active contact with the environment. The objective was to identify all live hosts, understand the network boundary, and build a picture of the full attack surface before narrowing focus to the primary target.
A lightweight Nmap ping sweep (-sn) was first run against the WAN subnet (10.0.2.0/24) to discover live hosts with minimal noise. Three hosts were identified: 10.0.2.1 and 10.0.2.2 were standard VirtualBox infrastructure addresses, which left 10.0.2.8 as the only non-infrastructure host. That machine became the immediate focus.
A full SYN stealth scan against 10.0.2.8 returned no results at all. This was expected behaviour rather than an error. Enterprise firewalls are designed to be unresponsive to port scanning, silently dropping packets rather than replying. The absence of results was itself confirmation that this was a network boundary device actively filtering traffic.
To confirm what services were actually running without relying on packet scanning, a direct HTTP request was issued using curl. This approach was taken because a standard web request is far less likely to be filtered than a scanning tool. The response came back as HTTP/1.1 200 OK with Server: nginx and a page title of pfSense, confirming that the webConfigurator was directly accessible on port 80 from the WAN interface.