Offsec Proving Grounds Walkthrough – SpringAuth_Attack

Walkthrough of the machine called “SpringAuth_Attack” in the Offsec Proving Grounds…this is a Linux machine rated as Intermediate. In this video we take advantage of anonymous FTP as well as a directory traversal/auth bypass bug in the SpringAuth Framework to gain an initial foothold. We then exploit a regularly schedule shell script (visible using pspy64) running as root with erroneous permissions to the set the SUID on /bin/bash and obtain root access.