This Root-Me challenge from the App-Script category is classified as Easy difficulty. Access is via SSH to a remote machine:
ssh -p 2222 [email protected]Once connected, we have a restricted shell on the challenge server. The objective is to obtain the content of the .passwd file belonging to the challenge, protected by file system permissions.
By exploring the challenge directory, we find a bash script and a setuid binary:
ls -la /challenge/app-script-ch23/
total 28
drwxr-xr-x 2 root root 4096 ...
-rwsr-xr-x 1 app-script-ch23 root 8704 ch23
-rw-r--r-- 1 root root 312 ch23.sh
-r-------- 1 app-script-ch23 root 32 .passwdThe .passwd file is readable only by the app-script-ch23 user. The ch23 binary runs with the rights of this user (setuid bit), and it's this binary that will allow us to reach the flag.