Target: Linux Strength Training (TryHackMe)
Difficulty: Medium/Hard (Process Heavy)
Objective: User (sarah, james) & Root (root.txt)
1. Executive Summary
This assessment focuses on internal system enumeration and privilege escalation. Starting with low-level access, we identify and crack multiple password hashes using both standard (rockyou) and custom-generated wordlists found on the target. We pivot through encrypted files (GPG) and analyze large datasets to locate hidden flags. Lateral movement to the user james is achieved by enumerating a local MySQL database. Root access is granted via sudo privileges after recovering the user’s password from the database.
Key TTPs (MITRE ATT&CK):
- T1083 (File and Directory Discovery): Using
findto locate specific hash files and hidden text. - T1110 (Brute Force): Cracking MD5, SHA, and GPG keys using John the Ripper and Hashcat.
- T1027 (Obfuscated Files or Information): Decoding Base64 and decrypting GPG files.
- T1552 (Unsecured Credentials): Recovering credentials from database tables.
2. Phase 1: Hash Cracking (Sarah)
A. Discovery
We access the machine as sarah. Our first task is to find specific hash files.
find / -type f -name "hash_file" 2>/dev/nullB. Identification & Cracking
We identify the hash types using hashid or example signatures.
1. Standard Hashes (Rockyou):
The first two hashes were crackable using the standard rockyou.txt wordlist.
# Example MD5/SHA1 cracking
hashcat -a 0 -m 0 hash1.txt /usr/share/wordlists/rockyou.txt
hashcat -a 0 -m 900 hash2.txt /usr/share/wordlists/rockyou.txt2. The Custom Wordlist: The final hash required a specific wordlist located on the target machine. Since we needed to crack it locally (for speed/GPU), we transferred it via SCP.
# Transfer wordlist from Target -> Attacker
scp sarah@10.10.x.x:"/home/sarah/system AB//db/ww.mnf" ./ww.mnf- Crack:
hashcat -a 0 -m 1400 hash3.txt ./ww.mnf3. Phase 2: File Forensics (The Needle in the Haystack)
A. Base64 Decoding
We locate a file named encoded.txt.
find / -type f -name "encoded.txt" 2>/dev/nullThe file contains massive amounts of Base64 data. The prompt hints at a keyword “special”. We use pipes to decode and search simultaneously.
cat encoded.txt | base64 -d | grep "special"- Output: “…the answer is in a file called ent.txt…”
B. Finding the Answer
We locate ent.txt:
find / -type f -name "ent.txt" 2>/dev/null
cat /home/sarah/logs/zhc/ent.txt
# Output: bfddc35c8f9c989545119988f79ccc77C. Cracking the Result
This string looks like an MD4/MD5 hash.
john --format=Raw-MD4 --wordlist=/usr/share/wordlists/rockyou.txt hash.txt- Result:
horoscope(or similar).
4. Phase 3: Encryption (GPG)
We found an encrypted file personal.txt.gpg and a hint file data.txt. The hint suggests the password is in data.txt, but perhaps in reverse order.
1. Exfiltration:
scp sarah@10.10.x.x:~/oldLogs/units/personal.txt.gpg .
scp sarah@10.10.x.x:"~/logs/zmn/old stuff/-mvLp/data.txt" .2. Wordlist Preparation (tac):
The notes imply the password might be at the end of the file or require reversing the list. tac (cat backwards) is perfect for this.
tac data.txt > wordlist.txt3. Cracking with John: We convert the GPG file to a format John can understand.
gpg2john personal.txt.gpg > personal.hash
john --wordlist=wordlist.txt personal.hash- Result: Password found.
4. Decryption:
gpg --import private.key # If a key was involved
gpg --decrypt personal.txt.gpg
# Enter the cracked password- Flag: Base64 encoded string inside the decrypted file.
5. Phase 4: MySQL & Lateral Movement
A. Configuration Enumeration
We explore /home/shared/sql/conf. A configuration file contains a Base64 string pointing to a wordlist directory.
Decoding the Path:
echo "aG9tZS..." | base64 -d
# Output: home/sameer/History LB/labmind/latestBuild/configBDBB. Wordlist Filtering
We navigate to that directory. The instructions mention a password starting with ebq. We filter the files to create a targeted wordlist.
grep -h "^ebq" * > target_passwords.txtC. Database Access
We found a SQL backup (or encrypted zip) that required this password. After unlocking it (or logging into MySQL directly if the credentials were for the DB), we query the database.
Enumerating Employees:
mysql -u root -p
# Password: (Recovered from previous step)
USE employees;
SELECT * FROM employees WHERE first_name='James';- Result: We find James’s entry, which contains his system password (or SSH password).
6. Phase 5: Privilege Escalation (Root)
A. Lateral Movement
We SSH as James using the password recovered from the database.
ssh james@10.10.x.xB. Root Access
We check James’s privileges.
sudo -l
# (ALL : ALL) ALLJames has full sudo access.
sudo su
cd /root
cat root.txt7. Key Learning Points
findis powerful: When you don’t know where a file is,find / -name "name" 2>/dev/nullis your best friend.tacvscat: Reverse reading files is a niche but useful skill for logs or specific CTF challenges.- GPG Cracking: GPG files aren’t dead ends;
gpg2johnallows you to brute-force the passphrase just like a standard hash. - Data Filtering: You cannot brute force with a 50MB wordlist against a slow service. Using
grepto filter for known patterns (starts withebq) reduces the search space drastically.