Level: Easy
Date: April 14, 2026
Target IP: 10.114.184.161
Nmap results:


The webpage on port 80 is just a picture of the squad, let's check the source code for clues.

Aha! Stegonography, could be useful later on. First, I want to check out the FTP on port 21.

I thought I might get some more information by using a more thorough scan. The ftp allows anonymous login, note_to_jake.txt seems interesting.


Maybe something like Hydra could be of use here?

Nice!

Poking around and got the first flag! User flag: ee11cbb19052e40b07aac0ca060c23ee

It's owned by root

Jake is able to run "less", let's go to GTFOBins


Privileges.. Escalated!

And there we go! Root flag: 63a9f0ea7bb98050796b649e85481845
Enumeration revealed FTP with anonymous login enabled, exposing a note hinting at a weak password. Hydra was used to brute-force SSH credentials for the user Jake. Once in, sudo -l showed Jake could run `less` as root — a classic GTFOBins escalation path that dropped a full root shell and exposed both flags.