> For the complete documentation index, see [llms.txt](https://0xb0b.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xb0b.gitbook.io/writeups/tryhackme/2024/nanocherryctf.md).

# NanoCherryCTF

Explore a double-sided site and escalate to root! - by dsneddon00

{% embed url="<https://tryhackme.com/r/room/nanocherryctf>" %}

The following post by 0xb0b is licensed under [CC BY 4.0<img src="https://mirrors.creativecommons.org/presskit/icons/cc.svg?ref=chooser-v1" alt="" data-size="line"><img src="https://mirrors.creativecommons.org/presskit/icons/by.svg?ref=chooser-v1" alt="" data-size="line">](http://creativecommons.org/licenses/by/4.0/?ref=chooser-v1)

***

## Recon

We start with a Nmap scan and find only two open ports. Port 22 with SSH and port 80 with a web server.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FDSnoORogSGaFmz0uroGG%2Fgrafik.png?alt=media&amp;token=976fa823-a7e1-46b3-8853-2696c1722b38" alt=""><figcaption></figcaption></figure>

We adapt our `/etc/hosts` file to the room description and find an ice cream online shop.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FRX78FEPw3TvnJDuk6gQ2%2Fgrafik.png?alt=media&amp;token=c43c1023-e95e-4716-893b-b42fd067c80d" alt=""><figcaption></figcaption></figure>

The first interesting page we discover is the content.php page. Here, we can retrieve facts for a specific user.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FeUZ3ewTxkbErAjaG4mPj%2Fgrafik.png?alt=media&amp;token=fb394697-9f64-4984-a05b-7a9fbe345604" alt=""><figcaption></figcaption></figure>

The subsequent directory scan yielded no further useful findings.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F0581AdbYYVTxhcDT3fu8%2Fgrafik.png?alt=media&amp;token=20a8f6a6-d4d0-46bd-b1a2-7034aa085543" alt=""><figcaption></figcaption></figure>

Since the room description requires a specific hostname, additional subdomains may be present. We scan for additional subdomains / vhost and find `nano.cherryontop.thm`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FCkjnhhb5seHoxEvObdRt%2Fgrafik.png?alt=media&amp;token=00495834-d768-45b6-9dae-b21d7132fed3" alt=""><figcaption></figcaption></figure>

We don't discover anything conspicuous here for the time being,...

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F5978mtbtp8BMYpOishSe%2Fgrafik.png?alt=media&amp;token=431be4d3-0e6f-4071-a634-4e5629679b62" alt=""><figcaption></figcaption></figure>

except for a login for the admin portal. \
Here, the question about the room description led me astray, as I was asked about molly's dashboard. I thought a certain user had to be related to molly. I used `cewl`, `cupp` and `usernameanarchy` to create word lists, but got no positive results. Let's continue for now.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FnBzpybLwrIVYpIu14z9T%2Fgrafik.png?alt=media&amp;token=f82bd40a-d081-45e5-867e-636b0425d3a7" alt=""><figcaption></figcaption></figure>

This time the directory scan returns something interesting, command.php, which is probably located behind the login. The first thought was command injection, but we can only check that later.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FDLjNpxNvOauuZxKDbBGU%2Fgrafik.png?alt=media&amp;token=8c105486-6d53-4b54-8273-e297c840bde0" alt=""><figcaption></figcaption></figure>

## Shell As notsus

According to the history of the room, there is already a backdoor that should be used as the start of the challenge. A user `notsus` exists, with which we can log in via ssh.<br>

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2Fo3GqMiZYGEiy2pq9pzOU%2Fgrafik.png?alt=media&amp;token=a6c508e6-4cb9-4f62-a297-730cac7147cf" alt=""><figcaption></figcaption></figure>

We use the credentials for login via SSH.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FwFb1bCP6MGwntIYM5jxj%2Fgrafik.png?alt=media&amp;token=797d2365-f8a4-4d70-bec4-86bbe033900c" alt=""><figcaption></figcaption></figure>

We get the hint that we can escalate via this user on `bob-boba`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FWjbWXrnWOD05Gt0ft8qp%2Fgrafik.png?alt=media&amp;token=8c53b5fb-d84e-4c49-8dca-b4d5958ccd99" alt=""><figcaption></figcaption></figure>

## Shell As bob-boba

We upgrade the shell and enumerate the machine. We find a cronjob that downloads and executes a script from `cherryontop.tld` as `bob-boba`. Nice, if we can edit the `/etc/hosts` we can provide the script ourselves, which for example executes a reverse shell and allows us to connect as `bob-boba`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FI0xDueiWtLgNekTjrGiS%2Fgrafik.png?alt=media&amp;token=d358788b-2a2b-4564-a36c-ec5979a3c1a7" alt=""><figcaption></figcaption></figure>

We may write in `/etc/hosts`, we add for one with our IP for `cherryontop.tld`.

```bash
echo '10.8.211.1 cherryontop.tld' >> /etc/hosts
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FpffZC5z5e1ijbOCih1jS%2Fgrafik.png?alt=media&amp;token=2c35827d-c8a5-4a13-b4c6-9ded4ac6d107" alt=""><figcaption></figcaption></figure>

Then we set up the folder structure and a script that executes a `nc mkfifo` rever shell, which we have generated on `revshells.com`. Then we start the `http server` on port `8000` and a `listener` on `4445` to catch the reverse shell.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FnPYQzX0LAO9uxwncF7Kq%2Fgrafik.png?alt=media&amp;token=d68c4f1e-56c2-433e-ad7b-5246006f8370" alt=""><figcaption></figcaption></figure>

We get a connection back as `bob-boba`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FeTewwXnHztXkObYDbj2r%2Fgrafik.png?alt=media&amp;token=05263cd6-de39-411e-a93a-169f4bb58996" alt=""><figcaption></figcaption></figure>

Here we find a message and `chads` third piece of his password.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2Fdx93A0SUQReoJS7CmcXq%2Fgrafik.png?alt=media&amp;token=aae010bd-f402-4806-a567-2cdec06c96b7" alt=""><figcaption></figcaption></figure>

From the `/etc/passwd` we can see that there are three other users, two of whom will probably have the remaining parts of `chad`'s password.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FABgPuMoVq0bMp948PPEa%2Fgrafik.png?alt=media&amp;token=5498626a-cb4b-497c-9e32-c50198d6f4c7" alt=""><figcaption></figcaption></figure>

As already described, we find the third part of the password here.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FX8mUPZtdBdF0zocODcYM%2Fgrafik.png?alt=media&amp;token=bceea9f6-b770-4e8b-832e-936b0d5057dc" alt=""><figcaption></figcaption></figure>

When enumerating the machine as user `bob-boba`, nothing else was found. I must have focused too much here and ignored the other findings from before. My focus was entirely on the lateral movement of `bob-boba`, which was not possible. It turns out that each user can be accessed individually. At least we now know the username of molly.

I should have noticed that `bob-boba` has the third password part, and the description explicitly states that the challenge can be solved independently.

## Shell As molly-milk

We go back to the login page of `nano.cherryontop.thm` and see that we can enumerate usernames. As mentioned at the beginning, I was initially too focused on generating and checking users in the context of the username `molly-milk`. Using the `xato username list` or `top-usernames-shortlist.txt` from `SecLists`, however, we can enumerate a user, since if we enter a wrong username, we get that message `"This user doesn't exist"`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FXFosChhwQ3cSEkuYZ7Lo%2Fgrafik.png?alt=media&amp;token=1a63632f-96dc-42e4-a478-64d0e6696f69" alt=""><figcaption></figcaption></figure>

We can either use `FuFF`, `hydra` or any other fuzzer to enumerate the user by matching for the message `"This user doesn't exist"`.

```bash
hydra -L /usr/share/wordlists/SecLists/Usernames/xato-net-10-million-usernames.txt -p asdf nano.cherryontop.thm http-post-form "/login.php:username=^USER^&password=^PASS^&submit=:F=This user doesn't exist"
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FUT5WrgkKcf0WYXpiYKym%2Fimage.png?alt=media&amp;token=605ea4d6-e874-49c7-9192-e111cc94359d" alt=""><figcaption></figcaption></figure>

We find the user puppet, now we just need to brute force the password. If the password is entered incorrectly, we receive the message `"Bad password"` to which we only have to match.

```bash
hydra -l puppet -P /usr/share/wordlists/rockyou.txt nano.cherryontop.thm http-post-form "/login.php:username=^USER^&password=^PASS^&submit=:Bad password"
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FmS6Rf3wgpiWmyUvwJB5z%2Fgrafik.png?alt=media&amp;token=0c5ec5f1-de00-4765-8f63-44fe0cdb20ab" alt=""><figcaption></figcaption></figure>

With the credentials found `puppet:<REDACTED>`, we can log in to the dashboard and find the molly dashboard flag.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FgB0kpwvFlsawywOXjvqi%2Fgrafik.png?alt=media&amp;token=07a08cf5-0b06-4906-89fb-901a747c642d" alt=""><figcaption></figcaption></figure>

If we scroll down a little further, we find the password for `molly`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F3IWgoqn8ZtfuBxCfqacf%2Fgrafik.png?alt=media&amp;token=344d0c96-5a7a-4c27-ab5a-c3f8fb051082" alt=""><figcaption></figcaption></figure>

Since we already know the username of molly through `notsus`/ `bob-boba`, we can log in to the machine via SSH as `molly-milk`. Here we find the first part of chad-cherrys password.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FObPoKohGnCA3ldsjJI2F%2Fgrafik.png?alt=media&amp;token=19a4f5f9-0fc1-4651-8aba-e25e5039d0ca" alt=""><figcaption></figcaption></figure>

## Shell As sam-sprinkles

At `molly-milk`, too, we can't find a way to extend our rights, so we go back and take a look at what we've found so far. We still have the `content.php` page on `cherryontop.thm`. Here we can see that facts can be viewed for a specific user and ID. The username is Base32 encoded. Using CyberChef we can see that it is the user `guest`. We can see four facts, but maybe there are more!

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F4SsfWWZNidGkCPzQyFKh%2Fgrafik.png?alt=media&amp;token=e8a87c84-396f-41e9-ae13-9377b8cc8fb0" alt=""><figcaption></figcaption></figure>

We create a list of 10000 IDs.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FAhxOgpOXhif2kum3DLQz%2Fgrafik.png?alt=media&amp;token=d4282976-942c-446b-9682-202ac9b5aa84" alt=""><figcaption></figcaption></figure>

Next, we use FFuF to enumerate all possible IDs for the user `guest`.

```bash
ffuf -u "http://cherryontop.thm/content.php?facts=FUZZ&user=I52WK43U" -w ids.txt -mc all -fr "Error"
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FIXuNqCrs1qRGCJgtLiJb%2Fgrafik.png?alt=media&amp;token=396b090f-fa2c-4856-88a9-54d6ff014337" alt=""><figcaption></figcaption></figure>

We find more valid IDs outside the selectable, but none of them give us a hint to extend our privileges. We may have to change the user. Since we have already escalated to `molly-milk` and `bob-boba`, we are left with `chad-cherry` and `sam-sprinkles`. We encode the username `sam-sprinkles` to `Base32` and use it this time to query the 10000 IDs.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F7VNFLCvpzCjCGMcnsPWn%2Fgrafik.png?alt=media&amp;token=f2671f1a-5678-49ab-ba90-9cdf083de963" alt=""><figcaption></figcaption></figure>

We find the same IDs again, but maybe they have a different entry this time.

```bash
ffuf -u "http://cherryontop.thm/content.php?facts=FUZZ&user=ONQW2LLTOBZGS3TLNRSXG===" -w ids.txt -mc all -fr "Error"
```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FqTk7VNZkKEoF0wVvPNL9%2Fgrafik.png?alt=media&amp;token=1124c1f7-cdc5-46df-ab37-be75ff647707" alt=""><figcaption></figcaption></figure>

For the ID `43` we find the credentials for `sam-sprinkles`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FNVcOm8u3m90iQHdZLh2o%2Fgrafik.png?alt=media&amp;token=c75ae987-374d-4927-8631-50945d4db07e" alt=""><figcaption></figcaption></figure>

We use the found credentials of `sam-sprinkles` to login via SSH. Here we find the second password part of `chad-cherry`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F4z2hsYk8A0jvok6T4ENV%2Fgrafik.png?alt=media&amp;token=61c0109b-c9a7-4c0d-8855-7ace90f2275d" alt=""><figcaption></figcaption></figure>

## Shell As chad-cherry

We just have to merge the password parts of `molly-milk`+`sam-sprinkles`+`bob-boba`. This way, we can log in as `chad-cherry` via SSH. Here we find the flag of `chad-cherry` and a WAV file with the ominous name `rootPassword.wav`. There is also a note in `Hello.txt` that `rootPassword.wav` contains the root password.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FUvn13uPx9wfi8ZIvyZAC%2Fgrafik.png?alt=media&amp;token=cbbf8f02-40ee-4ed3-bafb-41fbd2caf47f" alt=""><figcaption></figcaption></figure>

## Shell As root

We download the `rootPassword.wav` file for further analysis. This seems to be a stego challenge at the end.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F1K3pfQGW9ypsJ4vdk610%2Fgrafik.png?alt=media&amp;token=68d2778a-4fd0-4652-9f11-c22344aabf8a" alt=""><figcaption></figcaption></figure>

When viewing the audio file in Audacity, we discover a pattern in the spectrogram view that resembles a digital signal. There may be another file, text or image embedded here.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F4yXBx6iqZIk5eJzrZ7ak%2Fgrafik.png?alt=media&amp;token=040e7bfe-306f-4f64-9240-edc162a69267" alt=""><figcaption></figcaption></figure>

After a search we find the following article which has a continuation of a series of techniques for audio steganography.&#x20;

{% embed url="<https://sumit-arora.medium.com/audio-steganography-the-art-of-hiding-secrets-within-earshot-part-2-of-2-c76b1be719b3>" %}

It could be SSTV to add other data to the audio file. We find a script to decode at the following link:

{% embed url="<https://github.com/colaclanth/sstv>" %}

After we have set up the prerequisites, we can run the script and get an image out of the WAV file.

```bash
┌──(0xb0b㉿kali)-[~/Documents/tryhackme/nanocherry]
└─$ git clone https://github.com/colaclanth/sstv.git
                                                                                                                                                                
┌──(0xb0b㉿kali)-[~/Documents/tryhackme/nanocherry]
└─$ cd sstv      

┌──(0xb0b㉿kali)-[~/Documents/tryhackme/nanocherry/sstv]
└─$ python -m venv sstv_venv 
                                                                                                                                                                
┌──(0xb0b㉿kali)-[~/Documents/tryhackme/nanocherry/sstv]
└─$ . ./sstv_venv/bin/activate 
                                                                                                                                                                
┌──(sstv_venv)─(0xb0b㉿kali)-[~/Documents/tryhackme/nanocherry/sstv]
└─$ python setup.py install

```

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2F6SE336joHrlo6spMLYBM%2Fgrafik.png?alt=media&amp;token=cb93b6f5-2fb1-4b04-97c0-11f8ca683e3f" alt=""><figcaption></figcaption></figure>

This shows us a picture of two cherries with a string underneath. Possibly the root password.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FG3dKZTITBo7oo7yA35Ib%2Fgrafik.png?alt=media&amp;token=feabfd23-b591-4737-9f3d-9f03cce2c9ec" alt=""><figcaption></figcaption></figure>

We use it to switch from user `chad-cherry` to `root` and are successful. We are able to switch to `root` and read the final flag in `/root/root-flag.txt`.

<figure><img src="https://2148487935-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FoqaFccsCrwKo1CHmLRKW%2Fuploads%2FSlu3rdUHEnuJwyZl5Trk%2Fgrafik.png?alt=media&amp;token=b3ee5013-1fee-40c1-b10f-2d763d54b384" alt=""><figcaption></figcaption></figure>
