Nodewell
mediumPro

Nodewell

Nodewell is a self-hosting dashboard that keeps all your homelab services on one pane of glass, including a diagnostic that checks whether the box can reach an endpoint.

argument-injectioncommand-injectioncurlrcefile-write
nodejsexpressnginx

The Scenario

Nodewell runs the homelab: a tidy dashboard over everything you self-host, plus a

"reach my endpoint" check for when a service looks down. The person who built it was

careful about the check, and stripped out the shell characters people use to break out

of commands.

Come at Nodewell from the dashboard, look closely at that reachability check, and work

out what it will still let you do even with the dangerous characters gone.

Lab Intel

Synopsis

The 'reach my endpoint' diagnostic (POST /diag) blocks shell metacharacters (; | & $ backticks <> (){} newlines) but then does url.split(' ') and hands the tokens straight to curl via execFile. That is argument injection: extra tokens are parsed by curl as flags. Using `-o /opt/nodewell/integrations/pwn.js` (with the file content sourced from the app's own /echo reflector, since egress is blocked) writes an attacker-controlled Node module into the folder the /integrations page require()s and renders. Loading /integrations executes the module -> RCE as the node user -> read /flag.txt. curl itself is a capable interpreter of its own flags; sanitising only for shell injection misses it.

Architecture

A medium lab on two containers (nginx gateway + Node/Express app). The dashboard's only interesting surface is the reachability check, which runs curl against a user URL. Shell-injection is correctly blocked, so ; and backticks are dead ends. But the URL is space-split into argv, so `http://127.0.0.1:3000/echo?body=<module> -o /opt/nodewell/integrations/pwn.js` makes curl fetch the app's echo reflector and write the response as a .js module into the integrations folder. The Integrations page require()s every .js there and renders it, executing the dropped module for RCE and reading /flag.txt (owned by the non-root node user).

Who It's For

Players who know command injection and need to meet ARGUMENT injection: when input is split into argv and passed to a real program, the program's own flags (here curl's -o/-d/-K) are the attack surface even with shell metacharacters removed.

Skills You'll Practice

  • Telling argument injection apart from shell command injection
  • Abusing curl's -o to write an attacker-controlled file without a shell
  • Sourcing file content from an on-box reflector when egress is blocked
  • Turning a file write into the right directory into code execution (Node require)

What You'll Gain

  • The instinct that a split-into-argv URL exposes the target program's own flags
  • A reusable curl -o file-write-to-RCE argument-injection technique
  • Why 'we sanitised for shell injection' is not the same as safe

Ready to hack Nodewell?

Upgrade to Pro to unlock this lab and the full library.

Nodewell | WebVerse Pro Lab