FINISH - Linux Agency

Room Link: https://tryhackme.com/room/linuxagencyarrow-up-right

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/21 - SSH

Kali

Victim

Victim(mission1)

Victim(mission2)

Victim(mission3)

Victim(mission4)

Victim(mission5)

Victim(mission6)

Victim(mission7)

Victim(mission8)

Victim(mission9)

Victim(mission10)

Victim(mission11)

Victim(mission12)

Victim(mission13)

Victim(mission14)

Victim(mission15)

Victim(mission16)

Victim(mission17)

Victim(mission18)

Victim(mission19)

Victim(mission20)

Victim(mission21)

Victim(mission22)

Victim(mission23)

Victim(mission24)

Kali

Victim(mission24)

In Ghidra we can we there is a environment variable called pocket that needs to be set, if it's set to money it will run the if statement to show the flag

Kali

Victim(mission24)

Most commands don't work, I couldn't ls or cat files

Victim(mission25)

Victim(mission26)

Kali

Victim(mission26)

Kali

Victim(mission26)

Victim(mission27)

Victim(mission28)

Victim(mission29)

Victim(mission30)

Victim(viktor)

Kali

Add reverse shell to script, I kept having to check and readd until dalia ran the script as there is another cronjob that resets the script

Victim(viktor)

Victim(dalia)

Get autocomplete

Dalia can run the zip command as silvio

Exploit: https://gtfobins.github.io/gtfobins/zip/arrow-up-right

Victim(dalia)

Victim(silvia)

Exploit:

Victim(silvia)

Last updated