[THM] Year of the Rabbit - Web Enumeration and Privilege Escalation
Summary
This easy-level machine requires basic knowledge of JavaScript, Web request analysis, file forensics, brute force attacks, and privilege escalation.
Reconnaissance
The first recon step was a port scan against the host using Nmap.

Web page
After that, we visited the Web page and landed on the default Apache Server splash screen. A directory brute force attack revealed a few directories and pages.

Browsing the /assets directory on the application, we found the following file listing:

The first one is a video containing the classic Rickroll meme, while the second - style.css - is a stylesheet whose code has a comment pointing to a secret PHP page.

Accessing the page, we noticed a chain of redirects that eventually land on the Rickroll. Among them was an alert stating the browser's JavaScript needed to be disabled to avoid the window.location call.

However, that wasn't actually necessary. Using the browser's network console, we spotted an interesting call to an intermediate page with a parameter pointing to a hidden directory.

Following it, we found another file listing.

Opening Hot_Babe.png gives us the image below.

I saved it locally and, to inspect it, opened its contents as plain text — VSCode, VIM, VI, or even cat on Linux / type on Windows all work. At the end of the file there's a message with an FTP username and a few candidate passwords.
Exploitation
Brute force attack
Exporting all the passwords to a text file lets us brute force the credentials for the file transfer service. I used THC Hydra with the following command:
hydra -l ftpuser -P .exploit/passwords.txt ftp://<IP>:21
After logging into FTP we only see a file named Eli's_Creds.txt.

Remote access
Downloading the file above shows what looks like a strange piece of code, but on a closer look it's easy to recognize the pattern used by the Brainfuck programming language. Running it through an online compiler reveals Eli's credentials for remote access.
Connecting remotely to the server over SSH, we get a banner with a message left by root for the user Gwendoline.

Searching for that secret message we manage to find it and obtain the login credentials for that user.

Logging in as Gwendoline and going to her home directory gets us the user flag.
Privilege escalation
To enumerate privilege escalation vectors I basically used two commands:
sudo -l- to enumerate files that can be executed with root permissions.sudo -v- to enumerate the SUDO version and check for known CVEs.

The output shows we can run the following command as root:
/usr/bin/vi /home/gwendoline/user.txt
And from the version we identify it's vulnerable to CVE-2019-14287, which can be exploited with the following command:
sudo -u#-1
Combining these findings gives us the following privilege escalation vector:
sudo -u#-1 /usr/bin/vi /home/gwendoline/user.txt
On the text editor screen, just type :!sh and hit Enter.

The final flag can be found in the /root folder.