Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Penetration-Testing-Walkthrough-Hacksudo-Thor — Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation. | Kitploit
Tools/GitHubGitHub/heventafese/penetration-testing-walkthrough-hacksudo-thor
Privilege EscalationReconnaissancePassword AttacksVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationCTFPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Learning & Education
Labs & Practice
GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Penetration-Testing-Walkthrough-Hacksudo-Thor

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.

View Repository
135 months agoNot yet reviewed

HackSudo Thor Full Penetration Testing Walkthrough

Target: HackSudo Thor from VulnHub
Objective: Gain root access and read /root/proof.txt
Environment: Isolated VirtualBox lab segmented by a pfSense firewall

Table of Contents

  • Overview
  • Network Topology
  • Attack Chain Summary
  • Phase 1: Passive Reconnaissance
  • Phase 2: Network Discovery and pfSense
  • Phase 3: Target Scanning and Enumeration
  • Phase 4: Vulnerability Assessment
  • Phase 5: Gaining Access
  • Phase 6: Privilege Escalation
  • Phase 7: Post-Exploitation
  • Phase 8: Tracks Covering
  • Vulnerabilities Exploited
  • Tools Used
  • Recommendations
  • Repository Structure
  • Ethical Disclaimer

Overview

This repository documents a partial black-box penetration test conducted on HackSudo Thor, an intentionally vulnerable virtual machine published on VulnHub by Vishal Waghmare. The goal was to simulate a real-world attack where an outside attacker attempts to compromise an isolated internal system with the primary objective being to gain root access and read the contents of /root/proof.txt.

The assessment follows the full penetration testing lifecycle: passive reconnaissance, network discovery, enumeration, vulnerability assessment, exploitation, privilege escalation, post-exploitation, and track covering.

The primary tools used were Nmap for network scanning, Nessus for vulnerability assessment, and the Metasploit Framework as the main exploitation and post-exploitation platform. John the Ripper, Hashcat, and online Rainbow Tables were used during the password cracking stage, though all attempts were ultimately unsuccessful due to the strength of the hashing algorithm in use.

Network Topology

The virtual lab was built entirely in VirtualBox and designed to simulate a realistic enterprise network with three distinct security zones, all managed by a pfSense 2.7.2 firewall. The three NAT networks were configured as follows: a WAN zone simulating the public internet where the Kali attacker machine lives, a DMZ zone hosting the target machine, and an internal LAN zone containing out-of-scope machines.

Internet Zone — NatNetwork (10.0.2.0/24)
│
│   Kali Linux 2025.4 [attacker]    — 10.0.2.9
│   pfSense WAN interface           — 10.0.2.8
│
├── pfSense Firewall (boundary device)
│
├── DMZ Zone — DMZnat (10.0.4.0/24)
│   ├── HackSudo Thor [TARGET]      — 10.0.4.3
│   └── DVWA                        — 10.0.4.4   (out of scope)
│
└── LAN Zone — LANnat (10.0.3.0/24)
    ├── Metasploitable 2             — 10.0.3.5   (out of scope)
    └── Windows XP Cyberlab          — 10.0.3.4   (out of scope)

Logical network topology diagram Logical network topology security zones managed by pfSense

The WAN interface was assigned 10.0.2.8/24 by DHCP, the LAN interface was set to 10.0.3.1/24, and the OPT1 (DMZ) interface was set to 10.0.4.1/24. To introduce a deliberate misconfiguration into the lab, port 80 was intentionally left exposed on the pfSense WAN interface, simulating a common real-world admin panel exposure that served as the primary entry point into the internal network.


Attack Chain Summary

[Kali Linux — 10.0.2.9]
        │
        │  CSRF-aware Python brute force → admin / pfsense
        ▼
[pfSense webConfigurator — 10.0.2.8:80]
        │
        │  Firewall rules disabled → DMZ and LAN now reachable
        ▼
[HackSudo Thor — 10.0.4.3]
        │
        │  Shellshock RCE (CVE-2014-6271)
        │  Apache mod_cgi → /cgi-bin/shell.sh
        ▼
[Meterpreter shell — www-data]
        │
        │  sudo -u thor /home/thor/hammer.sh
        │  Command injection via eval → bash -i payload
        ▼
[Interactive shell — thor]
        │
        │  GTFOBins: sudo service ../../bin/bash
        ▼
[Root shell]
        │
        ├── /root/proof.txt captured        ✅
        ├── /etc/shadow + /etc/passwd exfiltrated
        └── SSH RSA backdoor planted

Phase 1: Passive Reconnaissance

Before making any contact with the target environment, information was gathered exclusively from public sources. The two primary sources were the official VulnHub entry page for HackSudo Thor and the author's public GitHub profile.

The VulnHub page confirmed the target was a Linux-based system, rated easy to medium difficulty, with the objective of finding the proof.txt flag. Reviewing the author's GitHub profile gave additional insight. Vishal Waghmare consistently designs Linux boot-to-root machines with privilege escalation as the core challenge across the entire HackSudo series. This shaped the threat model going into the active phases: HTTP and SSH services were the most likely attack surface, and the escalation path was predicted to involve sudo misconfiguration, SUID binary abuse, or exploitation of a custom service.

This kind of author pattern analysis matters in a real engagement too. Understanding how a system was likely designed and what categories of weakness its administrator is likely to repeat gives direction before a single packet is sent.

FieldDetail
TargetHackSudo Thor
AuthorVishal Waghmare (@hacksudo)
Release3 August 2021
DifficultyEasy to Medium
OSLinux (Debian)
FormatVirtualBox OVA
DHCPEnabled
Predicted Attack SurfaceHTTP, SSH, sudo misconfiguration likely

Phase 2: Network Discovery and pfSense

This phase involved making direct active contact with the environment. The objective was to identify all live hosts, understand the network boundary, and build a picture of the full attack surface before narrowing focus to the primary target.

Finding the Boundary Device

A lightweight Nmap ping sweep (-sn) was first run against the WAN subnet (10.0.2.0/24) to discover live hosts with minimal noise. Three hosts were identified: 10.0.2.1 and 10.0.2.2 were standard VirtualBox infrastructure addresses, which left 10.0.2.8 as the only non-infrastructure host. That machine became the immediate focus.

A full SYN stealth scan against 10.0.2.8 returned no results at all. This was expected behaviour rather than an error. Enterprise firewalls are designed to be unresponsive to port scanning, silently dropping packets rather than replying. The absence of results was itself confirmation that this was a network boundary device actively filtering traffic.

To confirm what services were actually running without relying on packet scanning, a direct HTTP request was issued using curl. This approach was taken because a standard web request is far less likely to be filtered than a scanning tool. The response came back as HTTP/1.1 200 OK with Server: nginx and a page title of pfSense, confirming that the webConfigurator was directly accessible on port 80 from the WAN interface.

Bypassing CSRF to Brute Force pfSense

Download Tool