TryHackMe 'Adventure Time' CTF Box Walkthrough: Steganography to Root Shell
The 'Adventure Time' room on TryHackMe is a hard-rated capture-the-flag challenge themed around the popular cartoon series. The attack path starts with an anonymous FTP login that retrieves six JPEG images containing binary-encoded hint fragments hidden in their EXIF metadata. Players must then work through a chain of encoding puzzles — including Morse code, AES decryption, a Vigenère cipher, and an esoteric language called Spoon — to progressively unlock multiple user accounts. Privilege escalation to root is achieved by exploiting a known vulnerability, CVE-2019-10149, in a SUID-root exim4 binary. The final flag, a BMO reset code, is found hidden in a user's home directory after obtaining the root shell.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in