data:image/s3,"s3://crabby-images/efceb/efcebd9851eec3ae0bf5bba3c81cb0f1a423d910" alt=""
TryHackMe is an online platform that teaches Cybersecurity through hands-on virtual labs. Whether you are an expert or beginner, learn through a virtual room structure to understand theoretical and practical security elements.
data:image/s3,"s3://crabby-images/a8303/a8303c6e5f8d5ff79e877249891304c3cb9bfd72" alt=""
Lian_Yu is an easy CTF on TryHackMe for beginners to explore.
You have to first signup to join the room. There are few simple steps that you can follow in the Signup page. Next follow the steps in the Welcome room to configure the VPN connectivity.
I have connected to TryHackMe network using OpenVPN on Kali Linux. Once you connect, the access page will confirm the status by confirming your IP address and status.
data:image/s3,"s3://crabby-images/d9a6d/d9a6dcbdf3be88ec8f2fcb8d10c77433366bf9b0" alt=""
Once You have deployed the machine, you will get an IP address of the machine.
data:image/s3,"s3://crabby-images/4bfa7/4bfa70b909b04fc2aaebe4377e66672740157aaf" alt=""
The Machine's IP Address is displayed and the time remaining is also displayed, If you are unable to capture the flags within 1 hour, you may add 1 more hour.
We shall start enumeration using nmap. We can get the details of ports open and services running and their version by using -sV option along with nmap.
data:image/s3,"s3://crabby-images/37602/3760217be14e94670c61251cf032eb2c20ec2f11" alt=""
The nmap scan has revealed that port 80 is open and Apache service is running. We can explore it by browsing with IP.
data:image/s3,"s3://crabby-images/95625/95625953cc55c9a63b889abbec66a4cae807d37c" alt=""
We could see the web page has some details based on the famous series Arrow. Let us further enumerate using gobuster and try to find directories under the server.
data:image/s3,"s3://crabby-images/e4e3b/e4e3bb414f9dee5a438e2a49e687954f0ec439ff" alt=""
gobuster revealed /island page. Let us check what's there in it.
data:image/s3,"s3://crabby-images/da797/da7976d1efc8551c21719cab60f599e5ef56c8b6" alt=""
I could see that it is mentioned 'The code word is:' and there is nothing after that. So it as a good idea to check the source code of the page
data:image/s3,"s3://crabby-images/fef08/fef08ddb933a565537e06827f79c92f8249f8c77" alt=""
In the source I found that there is a word vigilante which is style encoded to be in white. The background is also white and the code word is also in white. So it wasn't visible in the page.
data:image/s3,"s3://crabby-images/851e2/851e296f79b4c12b83c46c9af262aae605998a3a" alt=""
For the next question, I could see a hint in the TryHackMe Room. There might be more hidden pages. Let us use another wordlist this time with only numbers of 4 digit.
data:image/s3,"s3://crabby-images/981e3/981e3047225a236de3ca9cc8c4a96d48eef60ea1" alt=""
So there is a page /2100 Let me explore it via browser. I can answer couple of questions on TryHackMe.
data:image/s3,"s3://crabby-images/b6c0b/b6c0b8eeeca6614b796fdee7ada7d1aa60fd7863" alt=""
data:image/s3,"s3://crabby-images/5f2d6/5f2d699e22b94190984d046a716d93d7b1c2d871" alt=""
I could see a video embedded on this page. It is a good idea to check the source of this page too.
data:image/s3,"s3://crabby-images/c7e43/c7e43190cfa7e1492c57a3feda96adfaf4f3bdc6" alt=""
This time the clue is .ticket
Also there is another Hint for us on TryHackMe so we now know that .ticket is an extension.
data:image/s3,"s3://crabby-images/14c67/14c673b4cb9c1a6f8a8339c142a23e842edcfbba" alt=""
We can use the tool ffuf to enumerate this time. I will use FUZZ.ticket as a placeholder.
data:image/s3,"s3://crabby-images/0ec2c/0ec2c9d56649f2b9b9fd33de34188592c0be244a" alt=""
And the ffuf tool reveal that the word green_arrow. We can explore the term green_arrow.ticket from the browser. Also we can answer a question on TryHackMe.
data:image/s3,"s3://crabby-images/17bcd/17bcd7197ffc968153981a4bd9ae438c052e9a45" alt=""
data:image/s3,"s3://crabby-images/93840/9384056c26ed967f1fda219ea7ee7eea769868bd" alt=""
So this might be a password but looks like it is encoded.
data:image/s3,"s3://crabby-images/f9f85/f9f85823b744b091d964fb4c425ae0004abb0267" alt=""
Let me go to the github link https://gchq.github.io/CyberChef given in the hint and try decoding it.
data:image/s3,"s3://crabby-images/12497/124976db6e661e94c2850c8df7ffdce8eee38611" alt=""
It was a base58 encryption. The decrypted word !#th3h00d looks like a password
Looks like I have found another answer.
data:image/s3,"s3://crabby-images/f6109/f61098d9b1adf6f54f13e402a685274a88d00e84" alt=""
Let me connect to the machine using ftp and check Username is vigilante and the password we just found.
data:image/s3,"s3://crabby-images/fb640/fb640fc4f3bbbc2b367970fbde6789d82854ba92" alt=""
Remember to login using passive mode.
data:image/s3,"s3://crabby-images/81ec7/81ec7be273021ee9650d249a657cf27f9044cc78" alt=""
I could see a lot of images are stored on the machine. Let me download them to check if there are any clues in it.
data:image/s3,"s3://crabby-images/3e9bb/3e9bb764528172abc48ce757913d01d8cbc8ec4d" alt=""
steghide tool can be used to extract information from the images.
data:image/s3,"s3://crabby-images/74183/74183c5e83f242dbc0d85a329573f911a307fcc5" alt=""
It is asking for a passphrase. First we have to find the passphrase. For that I will use another tool stegcracker
data:image/s3,"s3://crabby-images/50a38/50a389889ab4c89d0b6cb8b1d1fe59d30addd84a" alt=""
The tool found the password and it is password
Run the steghide again to extract the data from the image. The extracted data is saved with .zip file extension. use unzip to extract the files from it.
data:image/s3,"s3://crabby-images/eec3e/eec3e2f68ffd19c829ccac1937d25d61697e1aad" alt=""
I could see two files, passwd.txt and shado.
data:image/s3,"s3://crabby-images/fd9c1/fd9c11e037aa3ef0e95b89b76b1ab4456d8fb1c8" alt=""
The shado file revealed the password. It is M3tahuman but the passwd.txt is a booby trap. We had downloaded few other files from ftp, that is .profile, .other_user We can look in to those files as well if we can find username or any clue. We now have answer for one more question.
data:image/s3,"s3://crabby-images/de8e8/de8e89d0a0adb8837807bf23a2b862833d6031cd" alt=""
data:image/s3,"s3://crabby-images/4a1f1/4a1f1c8af3f40ec3b0e8296ea980c90c63143249" alt=""
The .other_user file has lot of names, I may have to try each of them starting with slade
data:image/s3,"s3://crabby-images/eadd8/eadd819a36ad2c10ac4093b3db015fb88f9598f6" alt=""
So the username is slade and the password is M3tahuman
data:image/s3,"s3://crabby-images/a7954/a7954f297d23aa00132fb92d18eb42cbb89d31f5" alt=""
Listing the directory contents, we have found the user.txt and a flag in it. Copy the flag and paste it on TryHackMe to verify.
data:image/s3,"s3://crabby-images/28b91/28b91b3a20013258b921ffb02341568a9a5c328d" alt=""
To be able to see root.txt we should have root access. Let me check if slade user has sudo access.
data:image/s3,"s3://crabby-images/42da8/42da8e6be5ed75ef7ea019e3bb5e2ff66137b58b" alt=""
The command sudo -l revealed that slade can run pkexec with root privilege. I can use the same to get the root prompt.
data:image/s3,"s3://crabby-images/d3f91/d3f917b7db555ccb43775d579b67da0f2efdfd3b" alt=""
I was able to escalate the privilege of user slade and get the root access. And I can see the root.txt and a flag in it. I can paste the flag on TryHackMe.
data:image/s3,"s3://crabby-images/7221e/7221e7c64225635404738d0534dc27e618f64fb1" alt=""
data:image/s3,"s3://crabby-images/4ee67/4ee677d870a205c4cc3fa1e8be3344aecabfcbaf" alt=""
I hope this write-up was informative for you. Please leave a feedback. Thank you
-Srivathsa Dhanvantri
The World Best Exam Dumps Webiste is Dumpsedu. One of the top site for AZ-900 Exam Dumps. DAS-C01 Exam Questions
DBS-C01 Exam Questions
SOA-C02 Exam Questions
PAS-C01 Exam Questions
ANS-C01 Exam Questions
DOP-001 Exam Questions
SAA-C03 Exam Questions