Deskwell
Deskwell is a shared support helpdesk: agents triage tickets, attach files, and admins can export a support bundle of logs and attachments.
The Scenario
Deskwell is the internal helpdesk a few teams share. During an incident review, an
admin export job was seen running a command nobody added, right after some oddly named
files showed up as ticket attachments.
Come in as an outsider at the agent sign-in and work out how to become an admin without
a password, then how an attachment could end up running on the server.
Lab Intel
Synopsis
Login builds an XPath query by concatenation over an XML user store: //user[@name='<u>' and @pass='<p>']. Injecting username ' or @role='admin' or ' resolves the identity node to the admin entry (blind XPath injection auth bypass) with no password. As admin, 'generate support bundle' runs sh -c "cd /var/desk/att && tar czf bundle.tgz *" over the folder where ticket attachments land with their original names. Uploading attachments named --checkpoint=1 and --checkpoint-action=exec=sh f.sh (plus f.sh) feeds those names to GNU tar as options via the unquoted wildcard, so tar runs f.sh at the checkpoint -> RCE as the non-root desk user -> read /flag.txt.
Architecture
A hard, two-stage chain on two containers (nginx gateway + a Go net/http app). Stage one is XPath injection against an XML user store to bypass authentication straight to admin. Stage two is tar argument injection: the attachment filenames are preserved verbatim and later consumed by an unquoted tar wildcard, so tar's own --checkpoint-action=exec runs an attacker-supplied script. The flag (/flag.txt, 0600, owned by the desk user) is read by the command tar executes. First XPath-injection lab, first tar --checkpoint RCE, and the first Go lab.
Who It's For
Players who want two under-practised primitives in one chain: XPath injection for auth bypass (the XML sibling of SQLi/LDAP injection), and argument injection into GNU tar via attacker-controlled filenames in an unquoted wildcard.
Skills You'll Practice
- Spotting an XML-backed login and injecting XPath to select the admin node
- Understanding operator precedence in the injected predicate (and binds before or)
- Recognising an unquoted wildcard feeding filenames to a program as flags
- Weaponising GNU tar --checkpoint-action=exec via crafted attachment names
What You'll Gain
- XPath injection auth bypass technique and payload shape
- The tar --checkpoint-action=exec argument-injection-to-RCE primitive
- The instinct that filenames in an unquoted glob become program arguments