TryHackMe Year of the Rabbit Walkthrough Easy CTF Guide for FTP SSH and Privilege Escalation

TryHackMe Year of the Rabbit Walkthrough Easy CTF Guide for FTP SSH and Privilege Escalation

This walkthrough details how to complete the β€œYear of the Rabbit” CTF challenge on TryHackMe, focusing on enumeration, web exploitation, and privilege escalation. It showcases a step-by-step approach to discovering hidden directories, extracting credentials, and escalating privileges to capture flags. #TryHackMe #YearOfTheRabbit

Keypoints

  • Initial enumeration involved Nmap scans revealing open ports 21, 22, and 80.
  • Web fuzzing uncovered a hidden directory β€œ/sup3r_s3c3rt_fl4g.php” and secret files.
  • Hidden image analysis with exiftool and strings helped retrieve FTP credentials and usernames.
  • Credentials were brute-forced with Hydra, allowing FTP login to access sensitive data.
  • Privilege escalation was achieved through Sudo and vi, leading to root access and flag retrieval.

Read More: https://infosecwriteups.com/tryhackme-year-of-the-rabbit-walkthrough-easy-ctf-guide-for-ftp-ssh-and-privilege-escalation-5e3217ccbfcb?source=rssβ€”-7b722bfd1b8dβ€”4