Sida loo Hacking Gareeyo Thoth-Tech: 1 VulnHub
Thoth-Tech: 1 – Full Exploitation Write-up (Detailed Version)
Disclaimer
Labkan waxaa lagu sameeyay VulnHub virtual machine (isolated environment) oo kaliya ujeeddo waxbarasho iyo tijaabo ah. Looma adeegsan karo systems aan oggolaansho lahayn.
Overview
Thoth-Tech: 1 waa machine Easy ah oo loogu talagalay in lagu barto fundamentals-ka penetration testing:
Network reconnaissance
Service enumeration
Information disclosure exploitation
Password brute forcing
Privilege escalation (sudo misconfiguration)
Waxa muhiimka ah ee machine-kan laga fahmayo waa attack chain thinking: hal weakness ayaa horseedi kara full system compromise haddii la isku xiro.
Step 1: Network Discovery
Command:
netdiscover -r 192.168.1.0/24
Sharaxaad (What & Why):
netdiscover waa tool ARP-based ah oo lagu ogaado devices ku jira local network-ka. Marka aad penetration testing sameyneyso:
Haddii aadan aqoon IP-ga target-ka
Waa inaad first sameysaa host discovery
ARP protocol wuxuu shaqeeyaa layer 2 (Data Link), taasoo ka dhigaysa mid degdeg ah oo reliable ah gudaha LAN.
Natiijo:
Waxaan helnay target IP:
192.168.1.7

Step 2: Service Enumeration (Critical Phase)
Command:
nmap -A -sV 192.168.1.7
Sharaxaad (Very important):
Tani waa mid ka mid ah stages-ka ugu muhiimsan pentesting.
-sV→ waxay ogaataa service versions-A→ waxay isku dartaa:OS detection
Script scanning
Traceroute
Service fingerprinting
Why this matters:
Haddii aad ogaato version-ka service-ka, waxaad:
Raadin kartaa CVEs
Fahmi kartaa misconfigurations
Aqoonsan kartaa attack surface
Natiijo:
Waxaan helnay:
FTP (21)
SSH (22)
Other services
FTP ayaa noqday muhiim sababtoo ah wuxuu bixiyay file hint ah.

Step 3: FTP Anonymous Access (Information Disclosure)
Command:
ftp 192.168.1.7
Sharaxaad:
FTP anonymous login waa misconfiguration caadi ah.
Marka server-ku oggolaado:
username = anonymous
password = empty
Tani waxay keeni kartaa:
File exposure
Internal notes leakage
Credential hints
Waxa aan helnay:
File la yiraahdo:
note.txt
Inside file:
Username:
pwnlabPassword hint: weak password
Security Impact:
Tani waa Information Disclosure vulnerability, sababtoo ah attacker wuxuu helay:
valid username
password strength hint

Step 4: SSH Brute Force Attack
Command:
hydra -l pwnlab -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.7
Sharaxaad (Important concept):
Hydra waa tool brute-force ah oo isku dayo combinations badan.
Process:
Username already known (
pwnlab)Password list (rockyou.txt)
SSH service accepts password authentication
Hydra tries each password sequentially or parallel
Why this works here:
Password weak yahay
No rate limiting
No account lockout
Result:
pwnlab : babygirl1
Security Impact:
Tani waxay muujinaysaa:
weak password policy
lack of brute-force protection

Step 5: Initial Access (SSH Login)
Command:
ssh pwnlab@192.168.1.7
Sharaxaad:
Marka credentials la helo:
attacker wuxuu helaa low-privilege shell
tani waa foothold phase
From here attacker wuxuu sameyn karaa:
local enumeration
privilege escalation research

Step 6: Privilege Escalation Discovery
Command:
sudo -l
Sharaxaad:
Tani waa mid critical ah.
sudo -l wuxuu muujinayaa:
- waxa user-ku ku ordi karo root privileges
Why this matters:
Haddii binary misconfigured yahay, attacker wuxuu si toos ah u heli karaa root access.
Natiijo:
User waxaa loo oggolaaday:
findas root (without password)
Security Issue:
Misconfigured sudo permissions

Step 7: Privilege Escalation (Root Exploitation)
Command:
sudo find . -exec /bin/sh \; -quit
Sharaxaad (Deep explanation):
find binary wuxuu leeyahay feature:
-exec→ wuxuu run gareeyaa commands
Marka:
sudo → gives root privileges
find → runs as root
-exec /bin/sh → spawns shell as root
Result:
We effectively bypass permissions system.
Why this is dangerous:
GTFOBins shows that many Linux binaries can be abused if misconfigured.

Final Result
whoami
root
Full system compromise achieved.
Lessons Learned (Important Section)
1. Enumeration is the foundation
Haddii scanning la skip gareeyo, attack chain ma bilaabanayo.
2. Information disclosure is powerful
Hal file (note.txt) ayaa bixiyay entire attack direction.
3. Weak passwords = easy compromise
Brute force success depends on:
weak password policy
exposed username
4. sudo misconfiguration is critical
One wrong line in sudoers file = full root access
5. Attack chain thinking is key
Real pentesting is not one exploit—it is chain of weaknesses:
Discovery → Access → Credential leak → Brute force → Privilege escalation → Root
Final Summary
Thoth-Tech: 1 shows how multiple small mistakes combine into a full compromise:
FTP misconfig
Information leakage
Weak authentication
sudo misconfiguration
Was this article helpful?
License
This article is licensed under Creative Commons Attribution–NonCommercial 4.0 International (CC BY-NC 4.0). You may share and adapt this content for educational and non-commercial purposes with proper attribution to AlphaSploit.
Continue Reading
Waa maxay Computer Network?
Maalin kasta waxaan isticmaalnaa internet-ka si aan u dirno farriimo, u daawanno muuqaallo, u wadaagno faylal, ama aan u qabanno shirar muuqaal ah. Adeegyadan oo dhan waxay ku shaqeeyaan **Computer Network**. Laakiin waa maxay, sideese u shaqeeyaa, iyo maxaa loo baahan yahay inaad ka fahanto?
Sida loo Hacking Gareyo TryHackMe Ignite CTF
habka ugu dhammaystiran oo ku saabsan TryHackMe Ignite CTF. Baro habka baadhista (enumeration), tallaabooyinka ka faa'iidaysiga (exploitation), kor u qaadista mudnaanta (privilege escalation), iyo sida loo qabto calan (flag) kasta.
Sida Logu shubo Kali Linux VirtualBox
Hagahan wuxuu kuu sharxayaa talaabo kasta oo aad ugu shubi karto Kali Linux VirtualBox adigoo isticmaalaya Windows 11. Bar sida loo sameeyo VM-ka, loo qoondeeyo RAM iyo CPU, loona