TryHackMe is an online platform that teaches Cybersecurity through hands-on virtual labs. Whether you are an expert or beginner, learn through a virtual room structure to understand theoretical and practical security elements.
data:image/s3,"s3://crabby-images/e16b2/e16b29007073296f5fb10f67842cbf6c11aeea64" alt=""
Fowsniff CTF is an easy room on TryHackMe for beginners to explore.
You have to first signup to join the room. There are few simple steps that you can follow in the Signup page. Next follow the steps in the Welcome room to configure the VPN connectivity.
I have connected to TryHackMe network using OpenVPN on Kali Linux. Once you connect, the access page will confirm the status by confirming your IP address and status.
data:image/s3,"s3://crabby-images/6a75a/6a75a13b4bb35ee6d3f9bf447a10d696fa39d256" alt=""
Click on Deploy to start the target machine.
data:image/s3,"s3://crabby-images/87299/87299529cea8a3d700fbf74645fde0e2ea82dff7" alt=""
The IP address of the target is displayed.
Start Enumeration using nmap. The -sV option will do a service fingerprinting. - A is for aggressive scan. -p- will check all the ports.
data:image/s3,"s3://crabby-images/e15c6/e15c64df3173587e42ca753d42e93b9e2f0cfbab" alt=""
From the scan result, it can be seen that port 80 is open and Apache server is running. Let us start checking each of these services listed in nmap scan result. Explore http service using a web browser.
data:image/s3,"s3://crabby-images/7910a/7910ae6cb5aceb088e007064b73f9997bd541382" alt=""
There is a message on the web page that the website is down temporarily. It is always a good idea to check page source.
data:image/s3,"s3://crabby-images/d446a/d446a22798655fc7bc630982f2d1524d9d38ce62" alt=""
Looks like blackhat hackers have attacked the website and also taken over their twitter account. And the attackers may have uploaded sensitive information on twitter account. Please check the twitter account.
data:image/s3,"s3://crabby-images/023a9/023a9b640bc27daf9a754b4ee715c250fcd84808" alt=""
There is a post on twitter account by attackers that passwords have been posted on pastebin site. Check the pastebin site by following the link posted on twitter.
data:image/s3,"s3://crabby-images/f7eb1/f7eb1a90fc8910b2931a0b4e69e74ce26322c1c5" alt=""
Note down all the credentials leaked on pastebin. From the nmap scan results we had seen that port 110 is also open and it is running pop3 service. Explore the pop3 service using netcat.
data:image/s3,"s3://crabby-images/41299/41299d583143cf9ffea474901ec60f94e58dd617" alt=""
User seina's credentials worked and we are able to see the messages in the inbox. Check all the messages to find more information.
data:image/s3,"s3://crabby-images/2b0d3/2b0d37a49d674838b0fd055c28273451bec88197" alt=""
From the first email in the inbox, we can see a temporary password for SSH. Note it down. The SSH for siena or stone didn't work. Check the second message.
data:image/s3,"s3://crabby-images/a81d8/a81d812bff47115699e0c1251e4970f9b63afb41" alt=""
The second email is from baksteen. Probably another user. Try doing ssh using baksteen and the password from first email.
data:image/s3,"s3://crabby-images/ebee6/ebee6f53ca6242b7ff3eee1053a59dbdb2015f31" alt=""
You are able to login as baksteen. Now run sudo -l command to check if the user has sudo permissions on this machine.
The sudo -l revealed that baksteen is not a sudo user. Get more information about the target machine using uname.
data:image/s3,"s3://crabby-images/42fd7/42fd7a51544a0de958f301f11f66118f0b4f1bd4" alt=""
uname revealed the kernel version. Check if there are any exploits available on exploit-db for this kernel version to escalate privilege.
data:image/s3,"s3://crabby-images/f945a/f945a31546ed325a32a0b0dda7255262d980c05f" alt=""
The google search result revealed there seems to be an exploit.
data:image/s3,"s3://crabby-images/709f6/709f64ac1e2c61ec63d2f5fcfa7420e6df0cace1" alt=""
Download the exploit from the exploit db. Use gcc to compile the c program.
data:image/s3,"s3://crabby-images/5e5fe/5e5fe9ec29a07d0259033cd326a094c4877a6073" alt=""
Start a python server on your Kali or whichever machine you are using for attacking.
data:image/s3,"s3://crabby-images/121b8/121b84b8aad8d8af84553ad60b23feafa2d5304b" alt=""
Using wget command, download the complied code on the target machine. Give execution permissions to the downloaded exploit file using chmod command. Execute the exploit.
data:image/s3,"s3://crabby-images/6dfb3/6dfb395318f3389c4d9ef3f9d80df215c7fa3688" alt=""
Note the root shell has been obtained. Check what's in root's home directory. By now you would have got all the answers for the questions in the TryHackMe room.
Congratulations!! you solved this room.
data:image/s3,"s3://crabby-images/cd27c/cd27c4e747b861afe5af1081fc35fc33859d520d" alt=""
I hope this write-up was informative for you. Please leave a feedback. Thank you
-Srivathsa Dhanvantri
Comments