📌 Description
In this video, I walk through the Agent Sudo CTF room on TryHackMe step-by-step. This is an easy-level CTF challenge that’s great for beginners who want to practice Linux enumeration, web exploitation, SSH, privilege escalation, and CTF methodology.
🔎 What you'll learn:
Reconnaissance & Enumeration (0:00 - 3:00): The host initiates an Nmap scan to identify open ports, finding services on ports 21 (FTP), 22 (SSH), and 80 (HTTP).
Web Exploitation (3:00 - 8:00): After discovering a clue about the user agent, the host uses Burp Suite to manipulate HTTP headers, leading to a redirect to agency.php.
Credential Cracking (8:00 - 14:00): Through FTP enumeration and using tools like Hydra and John the Ripper, the host cracks passwords to access hidden files.
File Analysis & Steganography (14:00 - 22:00): The host retrieves and inspects images and binary files, extracting hidden data and further credentials.
Privilege Escalation (22:00 - 32:00): After gaining an initial SSH session, the host performs local enumeration using `sudo -l`, ultimately identifying a way to escalate privileges to root by abusing a specific binary permission.
Practical TryHackMe CTF methodology
⚠️ This video is for educational purposes and authorized security testing only.
🔔 Subscribe to follow my cybersecurity & tech journey: @pretzelpeteyt5
📩 Business Inquiries: pretzelpetepp@gmail.com
📌 Description
In this video, I walk through the Agent Sudo CTF room on TryHackMe step-by-step. This is an easy-level CTF challenge that’s great for beginners who want to practice Linux enumeration, web exploitation, SSH, privilege escalation, and CTF methodology.
🔎 What you'll learn:
Reconnaissance & Enumeration (0:00 - 3:00): The host initiates an Nmap scan to identify open ports, finding services on ports 21 (FTP), 22 (SSH), and 80 (HTTP).
Web Exploitation (3:00 - 8:00): After discovering a clue about the user agent, the host uses Burp Suite to manipulate HTTP headers, leading to a redirect to agency.php.
Credential Cracking (8:00 - 14:00): Through FTP enumeration and using tools like Hydra and John the Ripper, the host cracks passwords to access hidden files.
File Analysis & Steganography (14:00 - 22:00): The host retrieves and inspects images and binary files, extracting hidden data and further credentials.
Privilege Escalation (22:00 - 32:00): After gaining an initial SSH session, the host performs local enumeration using `sudo -l`, ultimately identifying a way to escalate privileges to root by abusing a specific binary permission.
Practical TryHackMe CTF methodology
⚠️ This video is for educational purposes and authorized security testing only.
🔔 Subscribe to follow my cybersecurity & tech journey: @pretzelpeteyt5
📩 Business Inquiries: pretzelpetepp@gmail.com