The challenge provides SSH access to the server challenge02.root-me.org on port 2222. The connection is made with the credentials provided in the statement:
ssh -p 2222 [email protected]Once connected, we observe that the user's home directory points directly to the challenge folder: /challenge/app-script/ch11/. A detailed listing reveals the challenge structure:
ls -la /challenge/app-script/ch11/
-rwsr-xr-x 1 app-script-ch11-cracked app-script-ch11 ... ch11
-r-------- 1 app-script-ch11-cracked app-script-ch11 ... .passwdTwo elements immediately catch the eye. The ch11 binary has the SUID bit set (the s in -rws), meaning it executes with the rights of its owner app-script-ch11-cracked, regardless of who launches it. The .passwd file, the target of the attack, is read-only for its owner only (-r--------): it is inaccessible directly from our account.
The challenge statement also provides the C source code for the ch11 binary, which is a valuable aid in understanding exactly what it does before attempting anything.