Target IP: 10.10.x.x (Requires /etc/hosts entry? Likely accessed via IP) Difficulty: Hard (CTF/Puzzle Heavy) Objective: User (M0nk3y_D_7uffy) & Root (root.txt) Flags

1. Executive Summary

“One Piece” is a Linux machine that relies heavily on Steganography, Cryptography, and OSINT. Initial access involves collecting four distinct “Poneglyphs” (encoded strings) hidden across FTP, web directories, and image metadata. These strings, when combined and decoded through a specific multi-stage pipeline, reveal SSH credentials. Privilege escalation involves exploiting a custom SUID binary via Python injection and leveraging misconfigured sudo rights on the less utility.

Key TTPs (MITRE ATT&CK):

  • T1027 (Obfuscated Files or Information): Multi-layer decoding (Base32/Morse/etc.).
  • T1566 (Phishing/OSINT): Leveraging GitHub repositories for wordlists.
  • T1110 (Brute Force): Cracking the login page with ffuf.
  • T1548.001 (Setuid and Setgid): Exploiting a custom SUID binary.
  • T1548.003 (Sudo and Sudo Caching): Exploiting sudo less.

2. Enumeration: “The Grand Line”

A. Network Scanning

Nmap revealed the standard entry points:

  • 21/tcp (FTP): Anonymous allowed.
  • 22/tcp (SSH): Open.
  • 80/tcp (HTTP): “New World” website.

B. The FTP Leak (Poneglyph 1)

  • welcome.txt: Context (Zou/Zunesha).
  • .notes.txt: Hinted at rockyou.txt and text editors.
  • .the_whale_tree/.road_poneglyph.jpg: Steganography.
  • Action: strings or steghide (likely strings or just cat/exiftool) revealed the first encoded string.
  • Decoding: The “CyberChef Recipe” (Base32 -> Morse -> Binary -> Hex -> Base58 -> Base64).

C. The Web Hunt (Poneglyph 2)

  • GitHub Hint: The repo 1FreyR/LogPose provided a wordlist.

  • Fuzzing: Using that wordlist found /dr3ssr0s4.html.

  • Image Forensics:

  • rabbit_hole.png: Hex analysis (Red Herring).

  • king_kong_gun.jpg: Source code comment “Doflamingo is /ko.jpg”.

  • ko.jpg: Strings revealed /wh0l3_c4k3.php.

  • Cookie Manipulation: Changing the cookie to CakeForYou granted access to the PHP page, revealing the Second Poneglyph.

D. The Login (Poneglyph 3)

  • Discovery: /r4nd0m.html -> Javascript source -> /0n1g4sh1m4.php (Login Page).
  • User Enumeration: Metadata of kaido.jpeg revealed user K1ng_0f_th3_B3@sts.
  • Brute Force: ffuf with rockyou.txt found password thebeast.
  • Result: Third Poneglyph.

E. The Final Piece (Poneglyph 4)

  • Discovery: A hidden endpoint /unspecified (often found via rigorous fuzzing or logic deduction).
  • Result: Fourth Poneglyph.

3. Initial Access: The Pirate King

A. The Master Decryption

You gathered all parts (or the final combined string from /unspecified sometimes contains the full key in these types of CTFs, but usually you concatenate them).

The Recipe:

  1. Base32
  2. Morse Code
  3. Binary
  4. Hex
  5. Base58
  6. Base64

Result: M0nk3y_D_7uffy:1_w1ll_b3_th3_p1r@t3_k1ng!

B. SSH Login

ssh M0nk3y_D_7uffy@10.10.x.x

Status: User Access.


4. Privilege Escalation: Level 1 (Luffy -> Teach)

A. SUID Enumeration

You found a suspicious binary:

find / -perm -u=s -type f 2>/dev/null
# /usr/bin/gomugomunooo_king_kobraaa

B. Analysis

Running strings suggested it runs Python commands. Since it is SUID and accepts an argument -c (common for “command”), we can inject python code.

C. Exploitation

/usr/bin/gomugomunooo_king_kobraaa -c 'import os; os.setresuid(1000, 1000, 1000); os.system("/bin/sh")'
  • Why setresuid? SUID binaries drop privileges to the real user ID if system() is called directly without setting the EUID to the real UID first. setresuid forces the shell to spawn with the owner’s privileges (Teach).

Status: User 7uffy_vs_T3@ch.


5. Privilege Escalation: Level 2 (Teach -> Root)

A. Sudo Rights

sudo -l
# (7uffy_vs_T3@ch) NOPASSWD: /usr/local/bin/less

B. Exploitation (GTFOBins)

less is a pager that can execute shell commands.

  1. Run less on any file:
sudo /usr/local/bin/less /etc/passwd
  1. Spawn shell inside less: Type !/bin/sh and hit Enter.

Result:

# whoami
root

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. Information Leakage:
  • Steganography: Remove encoded strings from public images.
  • Metadata: Scrub EXIF data from images (kaido.jpeg) to prevent username enumeration.
  • Source Code: Remove comments referencing hidden files (/ko.jpg) or logic logic.
  1. Authentication:
  • Cookies: Do not use predictable static cookies (CakeForYou) for authentication bypass.
  • Brute Force: Implement rate limiting on login forms (/0n1g4sh1m4.php).
  1. Privilege Escalation:
  • SUID: Remove the SUID bit from custom binaries that allow arbitrary command execution (gomugomunooo...).
  • Sudo: Do not grant NOPASSWD sudo rights to binaries with shell escapes (less, vi, man, more).