ojoguardian:~/writeups$
writeups / masterschool-ctf-4

Capture the Flag: Linux, web, hidden flags, hash cracking and Nmap

A seven-part TryHackMe CTF worked end to end: Linux user management, file system and web flags, steganography-style hidden flags, hash cracking, and an Nmap scan report with remediation.

Case
OG-2023-01
Date
Category
CTF
Tools
Linux, SSH, Nmap, John the Ripper, Hashcat, Browser DevTools

context: written for the Masterschool cybersecurity program, against an isolated lab target. Published as written at the time.

Introduction

This report provides an overview and analysis of the Cybersecurity Capture The Flag (CTF) project. The project focuses on testing and enhancing cybersecurity skills through a series of challenges and scenarios. Participants are tasked with identifying vulnerabilities, exploiting systems, and uncovering hidden flags within a controlled environment.

The objective of the CTF project is to simulate real-world cyber threats and provide hands-on experience in securing systems and networks.

Linux Basics: User and File Management

  1. User Creation: In my attack machine, I used SSH to get in the Masterschool CTF machine. The CTF login and username were given, command on attack box to get in ctf machine is *ssh ctf@<machine_IP> *

Screenshot from the original report

User ctf is not a root, therefore he is unable to create the user. Checked .bash_history and found user executed user add. The action is still recorded under sudo, so we can add this user with *sudo adduser a. *Gave the new user password.

Screenshot from the original report

  1. User switch: I used command *su-l *(Username in this case is “a”) to login with shell so we can get full access to the environment.
  2. Folder and File Creation: I used mkdir <directory_name> to make directory, cd to move into the directory just created, and *nano *to make file inside the directory. I wrote in nano mode “Hello from a” and used CTRL+S to save the nano and CTRL+X to exit nano mode
  3. Switch Back to Original User: I used command *exit *to switch back to user ctf (original user)

Screenshot from the original report

File System Flags

  1. First flag: {flag redacted}

Found flag when you first ssh into ctf account on machine.

Screenshot from the original report

  1. Second flag: {flag redacted}

Found flag inside hidden file .f.txt on ctf account. I used ls -a command to show hidden files.

Screenshot from the original report

  1. Third flag: {flag redacted}

Used deductive reasoning. The flags are usually hidden in a .txt file. I used cd flag to get in flag directory. Then ran find command on any file that is a text file: find -name “.*.txt”* *I got two output. I found a directory inside multiple directories that leads to *f_l_a_g.txt *

I went into the multiple directories using *cd 6/m/a/s/t/e/r/s/c/h/o/o/l *

Screenshot from the original report

  1. Fourth flag: {flag redacted}

Remember that I got two text file when we did the find. Now I go inside the *./story/txt * I read the story, and inside the story, the flag was hidden in it.

Screenshot from the original report

Webpage Flags

I hopped back on my attack machine and ran an nmap scan to see which web port was open using *nmap <ctf_machineIP> | grep open Screenshot from the original report

Now that we see that http port 80 is open, I open a web page usinghttp://<ctf_machineIP>*

  1. First flag: {flag redacted}

This was the welcome page when you go on the website.

  1. Second flag: {flag redacted}
  2. Third flag: {flag redacted}
  3. Fourth flag: {flag redacted}
  4. Fifth flag: {flag redacted}
  5. Sixth flag: {flag redacted}

Found some of the flags on the webpage, I right clicked and chose “View page source”

Screenshot from the original report

Hidden Flags Challenge

Since I already ransacked the whole file, it is not bound to be in files anymore. Now I am looking into vulnerabilities and other logs.

I ran a detailed nmap scan on my attack machine to find vulnerabilities/open ports on the ctf machine using nmap -A -O

Screenshot from the original report

  1. First flag: {flag redacted}

This was found from ftp login. With the scan above, I saw that ftp allows anonymous login. On attack machine, I logged in with command ftp

Checked for files on it using ls -a and found two named “flag.txt” and “files.zip”

Screenshot from the original report

I used get command to download text file and zip file to my attack box. On my attack box, I opened up the flag.txt and got the first hidden flag.

Screenshot from the original report

  1. Second Flag: {flag redacted}

Next is to open the zip file. The zip file is password protected but we got a hint from flag.txt that we should know the password. After multiple combinations, “Masterschool” password worked. I opened the files.zip and found another zip file in it. This time, we have a wordlist with it.

I used zip2john to convert the secret.zip to secret.txt

Screenshot from the original report

zip2john files.zip > secret.txt

I ran john against the hash I got with the downloaded wordlist.

Screenshot from the original report

Now I will begin to look inside of important directories such as /etc, /var, /usr, /proc, /bin, /sbin, /tmp, /mnt, /lib, /home, /root, /srv

In Var directory, I used find -name “*.txt” and got a list of text files in the directory.

  1. Third Flag: {flag redacted}

Found in /var/backups/find_flag.txt

Screenshot from the original report

  1. Fourth Flag: {flag redacted}

Found in /var/www/html/secret.txt

Screenshot from the original report

  1. Fifth Flag: {flag redacted}

Found in /var/www/html/robots.txt

Screenshot from the original report

  1. Sixth Flag: {flag redacted}

Found in /var/www/html/flag/flag/flag.txt

Screenshot from the original report

Hash Cracking

In the ctf machine, from previous exploitations that I did, I know that the hashes are inside a directory called “hash_to_crack” In order to be able to crack the hash, I need to get it inside my attack box by using source and destination command *scp -r @<ctf_machineip>:/home/ctf/hash_to_crack hashes.txtScreenshot from the original report

I then installed hashid usingsudo apt-get install hashid -y *

*cd *into “hashes.txt” and ran hashid hash1.txt to get the hash format for john.

Ran *john --format=raw-md5 -wordlist=wordlist.txt hash1.txt *to crack the first hash.

Screenshot from the original report

  1. First Flag: {flag redacted}
  2. Second Flag: {flag redacted}

Found by running hash id to find the hash format and then john against the second hash. Follow the same process to crack hashe3, 4, and 5.

Screenshot from the original report

  1. Third Flag: {flag redacted}

Screenshot from the original report

  1. Fourth Flag: {flag redacted}

Screenshot from the original report

  1. Fifth Flag: {flag redacted}

Screenshot from the original report

NMAP Scan Report

I ran a detailed nmap scan with *nmap -A -O <ctf_machineip> *

Nmap performs a scan with aggressive options such as OS detection, against the ctf machine. It gathered information about the target’s open ports, services, and operating system.

Screenshot from the original report

  1. Host information:

IP Address: 10.10.252.68

Hostname: ip-10-10-252-68.eu-west-1.compute.internal

MAC Address: 02:7E:30:2D:FD:2B

Host: Masterschool.Masterschool.com

  1. Open Ports and Services:
  • Port 21/tcp: Open FTP port running vsftpd 3.0.3
  • Anonymous FTP login is allowed, indicating potential data exposure
  • Files identified on the FTP server: “files.zip” (size: 11,156 bytes) and “flag.txt” (size: 63 bytes)
  • Port 22/tcp: Open SSH port running OpenSSH 8.2p1 Ubuntu 4ubuntu0.5
  • Port 25/tcp: Open SMTP port running Postfix smtpd
  • Supports various SMTP commands including PIPELINING, STARTTLS, and CHUNKING
  • Port 53/tcp: Open DNS port running ISC BIND 9.16.1-Ubuntu
  • DNS server version identified as 9.16.1-Ubuntu
  • Port 80/tcp: Open HTTP port running Apache httpd 2.4.41 (Ubuntu)
  • Port 110/tcp: Open POP3 port running Dovecot pop3d
  • Supports various POP3 capabilities including TOP, UIDL, and SASL.
  • Port 143/tcp: Open IMAP port running Dovecot imapd (Ubuntu).
  • Supports various IMAP capabilities including STARTTLS and IDLE.
  • Port 993/tcp: Open port, possibly running a service that is wrapped in a secure layer (e.g., SSL/TLS).
  • Port 995/tcp: Open port, possibly running a service that is wrapped in a secure layer (e.g., SSL/TLS).

Potential vulnerabilities and solutions

  • Anonymous FTP Access (Port 21/tcp): The FTP server allows anonymous logins, which could potentially lead to unauthorized access or data leakage. The files “files.zip” and “flag.txt” are accessible, indicating the need for securing FTP access and evaluating the contents of these files for sensitive information. FTP sends data in plaintext; it is best not to be used.
  • OpenSSH (Port 22/tcp): The OpenSSH version 8.2p1 Ubuntu 4ubuntu0.5 is running. Ensure that the SSH service is properly configured with strong authentication and encryption settings to prevent unauthorized access.
  • Postfix SMTP Service (Port 25/tcp): The Postfix SMTP service is running, supporting several SMTP commands and extensions. Regularly apply security updates and follow best practices to protect the SMTP service from potential vulnerabilities and abuse.
  • I was able to get on SMTP and send out email. Check screenshot below:

Screenshot from the original report

  • ISC BIND DNS Server (Port 53/tcp): Best security practice on this is to keep DNS software up to date and follow best practices.
  • Apache HTTP Server (Port 80/tcp): Regularly apply security patches, It is best to stay up to date and use HTTPS as HTTP is more susceptible to attacks such as response splitting, and injection attacks
  • Dovecot POP3 (Port 110/tcp) and IMAP (Port 143/tcp) Services: The Dovecot POP3 and IMAP services are open. Ensure that proper authentication mechanisms are in place and SSL/TLS is correctly configured to secure email communications. I am unable to exploit these services because plaintext authentication is disallowed. This is good practice.

Screenshot from the original report

← all writeups