Target: Linux Strength Training (TryHackMe) Difficulty: Medium/Hard (Process Heavy) Objective: User (sarah, james) & Root (root.txt)

1. Executive Summary

This assessment focuses on internal system enumeration and privilege escalation. Starting with low-level access, we identify and crack multiple password hashes using both standard (rockyou) and custom-generated wordlists found on the target. We pivot through encrypted files (GPG) and analyze large datasets to locate hidden flags. Lateral movement to the user james is achieved by enumerating a local MySQL database. Root access is granted via sudo privileges after recovering the user’s password from the database.

Key TTPs (MITRE ATT&CK):

  • T1083 (File and Directory Discovery): Using find to locate specific hash files and hidden text.
  • T1110 (Brute Force): Cracking MD5, SHA, and GPG keys using John the Ripper and Hashcat.
  • T1027 (Obfuscated Files or Information): Decoding Base64 and decrypting GPG files.
  • T1552 (Unsecured Credentials): Recovering credentials from database tables.

2. Phase 1: Hash Cracking (Sarah)

A. Discovery

We access the machine as sarah. Our first task is to find specific hash files.

find / -type f -name "hash_file" 2>/dev/null

B. Identification & Cracking

We identify the hash types using hashid or example signatures.

1. Standard Hashes (Rockyou): The first two hashes were crackable using the standard rockyou.txt wordlist.

# Example MD5/SHA1 cracking
hashcat -a 0 -m 0 hash1.txt /usr/share/wordlists/rockyou.txt
hashcat -a 0 -m 900 hash2.txt /usr/share/wordlists/rockyou.txt

2. The Custom Wordlist: The final hash required a specific wordlist located on the target machine. Since we needed to crack it locally (for speed/GPU), we transferred it via SCP.

# Transfer wordlist from Target -> Attacker
scp sarah@10.10.x.x:"/home/sarah/system AB//db/ww.mnf" ./ww.mnf
  • Crack:
hashcat -a 0 -m 1400 hash3.txt ./ww.mnf

3. Phase 2: File Forensics (The Needle in the Haystack)

A. Base64 Decoding

We locate a file named encoded.txt.

find / -type f -name "encoded.txt" 2>/dev/null

The file contains massive amounts of Base64 data. The prompt hints at a keyword “special”. We use pipes to decode and search simultaneously.

cat encoded.txt | base64 -d | grep "special"
  • Output: “…the answer is in a file called ent.txt…”

B. Finding the Answer

We locate ent.txt:

find / -type f -name "ent.txt" 2>/dev/null
cat /home/sarah/logs/zhc/ent.txt
# Output: bfddc35c8f9c989545119988f79ccc77

C. Cracking the Result

This string looks like an MD4/MD5 hash.

john --format=Raw-MD4 --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
  • Result: horoscope (or similar).

4. Phase 3: Encryption (GPG)

We found an encrypted file personal.txt.gpg and a hint file data.txt. The hint suggests the password is in data.txt, but perhaps in reverse order.

1. Exfiltration:

scp sarah@10.10.x.x:~/oldLogs/units/personal.txt.gpg .
scp sarah@10.10.x.x:"~/logs/zmn/old stuff/-mvLp/data.txt" .

2. Wordlist Preparation (tac): The notes imply the password might be at the end of the file or require reversing the list. tac (cat backwards) is perfect for this.

tac data.txt > wordlist.txt

3. Cracking with John: We convert the GPG file to a format John can understand.

gpg2john personal.txt.gpg > personal.hash
john --wordlist=wordlist.txt personal.hash
  • Result: Password found.

4. Decryption:

gpg --import private.key # If a key was involved
gpg --decrypt personal.txt.gpg
# Enter the cracked password
  • Flag: Base64 encoded string inside the decrypted file.

5. Phase 4: MySQL & Lateral Movement

A. Configuration Enumeration

We explore /home/shared/sql/conf. A configuration file contains a Base64 string pointing to a wordlist directory.

Decoding the Path:

echo "aG9tZS..." | base64 -d
# Output: home/sameer/History LB/labmind/latestBuild/configBDB

B. Wordlist Filtering

We navigate to that directory. The instructions mention a password starting with ebq. We filter the files to create a targeted wordlist.

grep -h "^ebq" * > target_passwords.txt

C. Database Access

We found a SQL backup (or encrypted zip) that required this password. After unlocking it (or logging into MySQL directly if the credentials were for the DB), we query the database.

Enumerating Employees:

mysql -u root -p
# Password: (Recovered from previous step)
USE employees;
SELECT * FROM employees WHERE first_name='James';
  • Result: We find James’s entry, which contains his system password (or SSH password).

6. Phase 5: Privilege Escalation (Root)

A. Lateral Movement

We SSH as James using the password recovered from the database.

ssh james@10.10.x.x

B. Root Access

We check James’s privileges.

sudo -l
# (ALL : ALL) ALL

James has full sudo access.

sudo su
cd /root
cat root.txt

7. Key Learning Points

  1. find is powerful: When you don’t know where a file is, find / -name "name" 2>/dev/null is your best friend.
  2. tac vs cat: Reverse reading files is a niche but useful skill for logs or specific CTF challenges.
  3. GPG Cracking: GPG files aren’t dead ends; gpg2john allows you to brute-force the passphrase just like a standard hash.
  4. Data Filtering: You cannot brute force with a 50MB wordlist against a slow service. Using grep to filter for known patterns (starts with ebq) reduces the search space drastically.