Deskwell
hardPro

Deskwell

Deskwell is a shared support helpdesk: agents triage tickets, attach files, and admins can export a support bundle of logs and attachments.

xpath-injectionauthentication-bypassargument-injectiontarrce
gonginx

The Scenario

Deskwell is the internal helpdesk a few teams share. During an incident review, an

admin export job was seen running a command nobody added, right after some oddly named

files showed up as ticket attachments.

Come in as an outsider at the agent sign-in and work out how to become an admin without

a password, then how an attachment could end up running on the server.

Lab Intel

Synopsis

Login builds an XPath query by concatenation over an XML user store: //user[@name='<u>' and @pass='<p>']. Injecting username ' or @role='admin' or ' resolves the identity node to the admin entry (blind XPath injection auth bypass) with no password. As admin, 'generate support bundle' runs sh -c "cd /var/desk/att && tar czf bundle.tgz *" over the folder where ticket attachments land with their original names. Uploading attachments named --checkpoint=1 and --checkpoint-action=exec=sh f.sh (plus f.sh) feeds those names to GNU tar as options via the unquoted wildcard, so tar runs f.sh at the checkpoint -> RCE as the non-root desk user -> read /flag.txt.

Architecture

A hard, two-stage chain on two containers (nginx gateway + a Go net/http app). Stage one is XPath injection against an XML user store to bypass authentication straight to admin. Stage two is tar argument injection: the attachment filenames are preserved verbatim and later consumed by an unquoted tar wildcard, so tar's own --checkpoint-action=exec runs an attacker-supplied script. The flag (/flag.txt, 0600, owned by the desk user) is read by the command tar executes. First XPath-injection lab, first tar --checkpoint RCE, and the first Go lab.

Who It's For

Players who want two under-practised primitives in one chain: XPath injection for auth bypass (the XML sibling of SQLi/LDAP injection), and argument injection into GNU tar via attacker-controlled filenames in an unquoted wildcard.

Skills You'll Practice

  • Spotting an XML-backed login and injecting XPath to select the admin node
  • Understanding operator precedence in the injected predicate (and binds before or)
  • Recognising an unquoted wildcard feeding filenames to a program as flags
  • Weaponising GNU tar --checkpoint-action=exec via crafted attachment names

What You'll Gain

  • XPath injection auth bypass technique and payload shape
  • The tar --checkpoint-action=exec argument-injection-to-RCE primitive
  • The instinct that filenames in an unquoted glob become program arguments

Ready to hack Deskwell?

Upgrade to Pro to unlock this lab and the full library.

Deskwell | WebVerse Pro Lab