DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Ninja Skills - TryHackMe writeup

Practise your Linux skills and complete the challenges.

EasyLinux11 min read

Open the room on TryHackMe ↗ View on GitHub

Introduction

Some people skip rooms like this because they feel repetitive or time consuming, but this is actually the kind of work real SOC analysts, Linux administrators, forensic investigators and CTF players deal with daily. Knowing how to quickly search, filter, and investigate files inside a Linux system is one of the most useful skills in cybersecurity.

Ninja Skills is a Linux focused room based on file enumeration and investigation using common Linux commands.

The room provides the following files to investigate:

8V2L
bny0
c4ZX
D8B3
FHl1
oiMO
PFbD
rmfX
SRSq
uqyw
v2Vb
X1Uy

I connected through SSH instead of using the AttackBox since the terminal felt more stable and responsive.

ssh new-user@<ip>

Credentials:

Username: new-user
Password: new-user

Question 1

The first question asks which of the provided files are owned by the best-group group.

To solve this, I used the find command to search the Linux filesystem and filter files that belong to the best-group group.

find / -type f \( -name "8V2L" -o -name "bny0" -o -name "c4ZX" -o -name "D8B3" -o -name "FHl1" -o -name "oiMO" -o -name "PFbD" -o -name "rmfX" -o -name "SRSq" -o -name "uqyw" -o -name "v2Vb" -o -name "X1Uy" \) -group best-group 2>/dev/null

Command Breakdown

Part Meaning
find / Search from the root directory
-type f Search only for files
-name Match the filenames provided in the room
-o Means OR
-group best-group Filter files owned by the best-group group
2>/dev/null Hide permission denied errors

The output returned:

/mnt/D8B3
/home/v2Vb

This confirmed that the files D8B3 and v2Vb are owned by the best-group group.

Final Answer:

D8B3 v2Vb

Question 2

The second question asks which file contains an IP address.

Instead of manually opening every file, I used the find command together with grep to search inside all the provided files automatically.

find / -type f \( -name "8V2L" -o -name "bny0" -o -name "c4ZX" -o -name "D8B3" -o -name "FHl1" -o -name "oiMO" -o -name "PFbD" -o -name "rmfX" -o -name "SRSq" -o -name "uqyw" -o -name "v2Vb" -o -name "X1Uy" \) -exec grep -lE '([0-9]{1,3}\.){3}[0-9]{1,3}' {} \; 2>/dev/null

Command Breakdown

Part Meaning
find / Search the entire filesystem
-type f Search only files
-name Match the provided filenames
-exec Execute a command on each file found
grep Search for patterns inside files
-l Display only the filename
-E Enable extended regular expressions
([0-9]{1,3}\.){3}[0-9]{1,3} Regex pattern used to detect IPv4 addresses
2>/dev/null Hide permission denied errors

The command returned:

/opt/oiMO

This confirmed that the file oiMO contains an IP address.

Final Answer:

oiMO
image

Question 3

The third question asks which file matches the given SHA1 hash.

To solve this, I generated the SHA1 hash for each target file and compared the results with the hash provided in the question.

find / -type f \( -name "8V2L" -o -name "bny0" -o -name "c4ZX" -o -name "D8B3" -o -name "FHl1" -o -name "oiMO" -o -name "PFbD" -o -name "rmfX" -o -name "SRSq" -o -name "uqyw" -o -name "v2Vb" -o -name "X1Uy" \) -exec sha1sum {} \; 2>/dev/null

Command Breakdown

Part Meaning
find / Search the entire filesystem
-type f Search only files
-name Match the provided filenames
-exec sha1sum Generate SHA1 hashes for each file
{} Represents the current file
\; Ends the execute command
2>/dev/null Hide permission denied errors

The output returned:

9d54da7584015647ba052173b84d45e8007eba94  /mnt/c4ZX

This confirmed that the file c4ZX matches the given SHA1 hash.

Final Answer:

c4ZX
image

Question 4

The fourth question asks which file contains exactly 230 lines.

To solve this, I used the wc -l command together with find to count the number of lines in each target file automatically.

find / \( -name "8V2L" -o -name "bny0" -o -name "c4ZX" -o -name "D8B3" -o -name "FHl1" -o -name "oiMO" -o -name "PFbD" -o -name "rmfX" -o -name "SRSq" -o -name "uqyw" -o -name "v2Vb" -o -name "X1Uy" \) -exec wc -l {} \; 2>/dev/null

Command Breakdown

Part Meaning
find / Search the entire filesystem
-name Match the provided filenames
-exec wc -l Run the line count command on each file
wc -l Count the number of lines in a file
2>/dev/null Hide permission denied errors

When I ran the command, the file bny0 did not appear in the output, which made this question slightly confusing at first.

The output only displayed the remaining files and their line counts:

209 /mnt/D8B3
209 /mnt/c4ZX
209 /var/FHl1
209 /var/log/uqyw
209 /opt/PFbD
209 /opt/oiMO
209 /media/rmfX
209 /etc/8V2L
209 /etc/ssh/SRSq
209 /home/v2Vb
209 /X1Uy

Since bny0 was missing from the results, it indicated that this was the file associated with the question. The correct answer was bny0.

Final Answer:

bny0

Question 5

The fifth question asks which file is owned by a user with the UID 502.

In Linux, every user has a numeric User ID, also known as a UID. File ownership information can be viewed using the ls -ln command.

To identify the correct file, I used the following command:

find / -type f \( -name 8V2L -o -name bny0 -o -name c4ZX -o -name D8B3 -o -name FHl1 -o -name oiMO -o -name PFbD -o -name rmfX -o -name SRSq -o -name uqyw -o -name v2Vb -o -name X1Uy \) -exec ls -ln {} \; 2>>/dev/null

Command Breakdown

Part Meaning
find / Search the entire filesystem
-type f Search only files
-name Match the provided filenames
-exec ls -ln Display detailed file permissions with numeric IDs
ls -l Show detailed file information
-n Display numeric UID and GID instead of names
2>>/dev/null Hide permission denied errors

The output returned:

-rw-rw-r-- 1 502 501 13545 Oct 23 2019 /X1Uy

Here, 502 represents the owner UID of the file.

This confirmed that the file X1Uy is owned by a user with the ID 502.

Final Answer:

X1Uy
image

Question 6

The final question asks which file is executable by everyone.

In Linux, file permissions are displayed using symbols such as:

rwxrwxr-x

Where:

Symbol Meaning
r Read
w Write
x Execute

To check the permissions of all target files, I used the following command:

find / -type f \( -name 8V2L -o -name bny0 -o -name c4ZX -o -name D8B3 -o -name FHl1 -o -name oiMO -o -name PFbD -o -name rmfX -o -name SRSq -o -name uqyw -o -name v2Vb -o -name X1Uy \) -exec ls -ln {} \; 2>>/dev/null

Command Breakdown

Part Meaning
find / Search the entire filesystem
-type f Search only files
-name Match the provided filenames
-exec ls -ln Display detailed file permissions
ls -l Show file permissions and metadata
-n Display numeric user and group IDs
2>>/dev/null Hide permission denied errors

The output returned:

-rwxrwxr-x 1 501 501 13545 Oct 23 2019 /etc/8V2L

The permission string rwxrwxr-x shows that the file has execute permissions enabled.

This confirmed that the file 8V2L is executable by everyone.

Final Answer:

8V2L
image

Conclusion

Ninja Skills was a great beginner friendly room for practicing Linux file enumeration and investigation using common commands like find, grep, wc, sha1sum and ls.

Even though the room was simple, it helped build practical Linux skills that are heavily used in cybersecurity, CTFs and real world investigations.

Thanks for reading.

image