DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Lo-Fi - TryHackMe writeup

Want to hear some lo-fi beats, to relax or study to? We've got you covered!

EasyLinuxLFI2 min read

View on GitHub

Task 1. Lo-Fi

Climb the filesystem to find the flag!

flag{e4478e0eab69bd642b8238765dcb7d18}

1. Reconnaissance

Nmap Scan

To begin, perform an initial reconnaissance scan using nmap to identify open ports and running services:

nmap -sV -sC <ip>

Nmap Scan Results

death@esther:~$ nmap -sV -sC 10.10.63.207
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-03-03 22:43 IST
Nmap scan report for 10.10.63.207
Host is up (0.16s latency).
Not shown: 998 closed tcp ports (conn-refused)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.4 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   3072 01:71:46:d9:02:03:cc:99:34:ef:a5:76:2f:0a:14:26 (RSA)
|   256 1d:17:a1:93:4f:ef:49:0e:3f:e3:01:23:0b:1a:45:d5 (ECDSA)
|_  256 60:b3:b1:1b:f0:f5:81:61:01:3f:ed:ab:37:5e:2c:ad (ED25519)
80/tcp open  http    Apache httpd 2.2.22 ((Ubuntu))
|_http-title: Lo-Fi Music
|_http-server-header: Apache/2.2.22 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Since HTTP (port 80) is open, we navigate to the website.


2. Website Analysis

Upon exploring the website, it appears to host five song videos. When clicking on a video, the URL structure includes a query and path parameter, suggesting a potential Local File Inclusion (LFI) vulnerability.


3. Exploitation: LFI Attack

To confirm the LFI vulnerability, we attempt to access the /etc/passwd file by modifying the URL:

../../../../etc/passwd

The inclusion of /etc/passwd confirms the vulnerability. Now, let's attempt to locate the flag.


4. Capturing the Flag

Since this worked, I attempted to retrieve the flag. After a few failed attempts, I finally found it. Initially, I thought it would be User flag.txt, but surprisingly, it was much simpler than I expected!

../../../../flag.txt