October 2, 2026
TryHackMe Root Me CTF Walkthrough : Reconnaissance to Privilege Escalation
Introduction
By Soumallya Sarkar
12 min read
RootMe is an Easy-level room on TryHackMe designed to introduce beginners to the basic workflow of a penetration test. The machine is Linux-based and includes a small web component, allowing us to explore several fundamental concepts used during security assessments.
Room_Link: https://tryhackme.com/room/rrootme
What you will Learn
In this walkthrough, we will follow a basic penetration-testing methodology against the RootMe machine. The goal is to understand how information gathered during reconnaissance and enumeration can be used to identify an attack path and eventually gain access to the target.
The walkthrough will cover the following phases:
- Active Reconnaissance : Gathering information directly from the target machine.
- Service Enumeration : Identifying running services and their exposed ports.
- Service Fingerprinting : Determining the versions and technologies behind the discovered services.
- Directory Brute-Forcing : Discovering hidden directories and files within the web application.
- Payload Creation : Preparing a suitable payload based on the identified attack surface.
- Exploitation : Exploiting the identified vulnerability to gain access to the target.
- Initial Foothold : Establishing access to the Linux machine with a low-privileged user.
- Privilege Escalation : Identifying potential misconfigurations or vulnerabilities that can be abused to obtain higher-level privileges.
The walkthrough is primarily intended for complete beginners who have recently started solving CTFs and want to explore the world of penetration testing and cybersecurity. The goal is not just to show the commands, but also to explain why each step is performed, what information we are looking for, and how the results guide us toward the next stage of the attack path.
Lab Setup
Before starting the machine, we need an attack machine that can communicate with the TryHackMe target network. TryHackMe provides two common ways to set this up.
Option 1: Use Your Own Kali Linux Machine
You can use a Kali Linux VM running locally through VirtualBox or another virtualization platform. After starting your Kali machine, you can download the TryHackMe VPN configuration file and connect your machine to the TryHackMe network using OpenVPN.
You can download the VPN configuration file from the Manage Account section of TryHackMe.
Note: Make sure you download the VPN file while using your Kali Linux machine, rather than downloading it from a Windows or macOS system.
The connection can be established with:
sudo openvpn [vpn_file]
#sudo - Runs the command with elevated (administrator/root) privileges. OpenVPN requires these privileges to create and manage the VPN network interface.
#openvpn - Starts the OpenVPN client and initiates a VPN connection.
#vpn_file - Represents the VPN configuration file downloaded from TryHackMe, usually a [.ovpn] file. This file contains the configuration details required to establish the connection.sudo openvpn [vpn_file]
#sudo - Runs the command with elevated (administrator/root) privileges. OpenVPN requires these privileges to create and manage the VPN network interface.
#openvpn - Starts the OpenVPN client and initiates a VPN connection.
#vpn_file - Represents the VPN configuration file downloaded from TryHackMe, usually a [.ovpn] file. This file contains the configuration details required to establish the connection.Press Enter to execute the command. You will be prompted to enter your sudo credentials, after which the VPN initialization process will begin.
Once the VPN connection is successfully established, your Kali Linux machine will be able to communicate with the machines within the TryHackMe lab environment.
Option 2: Use the TryHackMe AttackBox
TryHackMe also provides its own browser-based attack machine called AttackBox. The AttackBox is already configured to communicate with the TryHackMe lab network, so there is no need to configure a VPN connection manually.
For this walkthrough, we will use the TryHackMe AttackBox as our attack machine. This keeps the setup simple and allows us to focus directly on the penetration-testing process.
Note: AttackBox usage limits depend on your current TryHackMe plan and account. Check TryHackMe's current plan details for the exact limits applicable to your account.
Once you have either started the AttackBox or successfully configured and connected the VPN on your Kali Linux machine, you can proceed to start the target machine.
Note: In both scenarios, you must start the target machine before beginning the lab.
Once the target machine has been started, its IP address will be displayed at the top of the room.
Questions and Tasks
Task 1: Deploy the target machine and configure the VPN connection.
Once you have configured the VPN and started the target machine or deployed the AttackBox, simply select the checkbox to proceed.
Task 2: Reconnaissance
Host Discovery
ping -c4 [Target_IP]
#ping - This command is used to check whether the target machine is reachable over the network.
#-c4 - Specifies the number of packet to sent. Here it will be 4 packetsping -c4 [Target_IP]
#ping - This command is used to check whether the target machine is reachable over the network.
#-c4 - Specifies the number of packet to sent. Here it will be 4 packets
The target responds to ICMP requests, confirming that the target is reachable and network connectivity has been established.
Nmap Enumeration
Nmap is used to enumerate open ports and identify the services running on a target.
nmap -sSCV -p- -A -T4 [Target_IP] --min-rate 1000
#nmap - Nmap (Network Mapper) is a tool used to scan a target IP Address for open ports, services, and system information.
#-sS - Performs a TCP SYN scan.
#-sC - Runs Nmap's default scripts.
#-sV - Detects service versions.
#-p- - Scans all 65,535 TCP ports.
#-A - Enables OS detection, version detection, scripts, and traceroute.
#-T4 - Uses an aggressive scan timing template for faster scanning.
#[Target_IP] - The IP address of the target machine.
#--min-rate 1000 - Attempts to send at least 1,000 packets per second.nmap -sSCV -p- -A -T4 [Target_IP] --min-rate 1000
#nmap - Nmap (Network Mapper) is a tool used to scan a target IP Address for open ports, services, and system information.
#-sS - Performs a TCP SYN scan.
#-sC - Runs Nmap's default scripts.
#-sV - Detects service versions.
#-p- - Scans all 65,535 TCP ports.
#-A - Enables OS detection, version detection, scripts, and traceroute.
#-T4 - Uses an aggressive scan timing template for faster scanning.
#[Target_IP] - The IP address of the target machine.
#--min-rate 1000 - Attempts to send at least 1,000 packets per second.
The Nmap scan identified two open ports on the target: port 22 (SSH) and port 80 (HTTP). The web server was identified as Apache 2.4.41.
Additionally, the presence of a PHP session ID indicates that the web application is PHP-based. This may provide a potential avenue for initial access if the application does not properly validate or restrict PHP file execution.
Web enumeration
The process of identifying web technologies, directories, files, and other resources exposed by a web application.
Open a web browser and enter the target machine's IP address in the address bar to access the web application.
Use cURL to retrieve and inspect the web application's page source directly from the terminal:
curl URL
#curl - cURL is a command-line tool used to send requests to and retrieve data from web servers.curl URL
#curl - cURL is a command-line tool used to send requests to and retrieve data from web servers.
Directory Brute-Forcing
A technique used to discover hidden or unlinked directories and files on a web server by testing a list of common paths. Multiple command line utility tools are used for this activity.
Gobuster
FFUF
Dirb
DirBuster
Feroxbuster
Wfuzz
Katana
Kiterunner
dirsearch
gobuster dir -u URL -w path_to_wordlist
#gobuster - Starts Gobuster
#dir - Performs directory/file enumeration.
#-u URL - Specifies the target URL.
#-w path_to_wordlist - Specifies the wordlist to use for discovering directories and files.Gobuster
FFUF
Dirb
DirBuster
Feroxbuster
Wfuzz
Katana
Kiterunner
dirsearch
gobuster dir -u URL -w path_to_wordlist
#gobuster - Starts Gobuster
#dir - Performs directory/file enumeration.
#-u URL - Specifies the target URL.
#-w path_to_wordlist - Specifies the wordlist to use for discovering directories and files.
After running Gobuster for directory enumeration, several endpoints were discovered, including /index.php, /css, /js, /server-status, /panel, and /uploads.
Among these, /panel and /uploads are worth further investigation as they may expose additional functionality or resources. The remaining endpoints appear to serve the application's main page, CSS, JavaScript, or server-status information.
Panel Endpoint
Upon accessing the /panel endpoint, a file upload functionality was identified. Further investigation of this functionality was conducted to understand how the application handles uploaded files.
Uploads Endpoint
Upon accessing the /uploads endpoint, a directory listing was identified, displaying the files uploaded to the web server.
A test file was uploaded to verify whether the upload functionality works correctly and whether the uploaded file can be accessed through the /uploads endpoint.
echo "test" > test.txt
cat test.txt
#cat - Displays the contents of a file.
#test.txt - Specifies the file to read.echo "test" > test.txt
cat test.txt
#cat - Displays the contents of a file.
#test.txt - Specifies the file to read.
Once the test file has been created, upload it through the /panel endpoint. Then, access the /uploads endpoint to verify whether the file was successfully uploaded and can be accessed.
This test confirms that files can be uploaded through the /panel endpoint and subsequently accessed through the /uploads endpoint.
With the upload functionality confirmed, the next step is to prepare a suitable payload for the initial access phase.
Questions Answered in the Reconnaissance Section
Task 3: Exploitation and Initial Access
Initial Access is the phase where you attempt to gain your first foothold on the target system by exploiting an identified vulnerability or weakness.
Payload Generation
As the application was identified as PHP-based, we can prepare a PHP payload to test whether the file upload functionality allows server-side PHP execution.
A reverse shell is a technique where the target system initiates a connection back to the attacker's machine, providing a command-line shell for interacting with the target system.
To generate the reverse shell, we can use the Reverse Shell Generator platform. For this lab, we will generate a PHP-based reverse shell using the Pentest Monkey payload.
Pentest Monkey is a collection of penetration-testing scripts and tools, including commonly used reverse-shell payloads for security testing and lab environments.
Enter your attack machine's IPv4 address in the designated IP field and select an available port. For this lab, we will use port 4488.
Once you enter the IP address and port, the corresponding Netcat command will automatically appear in the Netcat command field.
In the Name field, search for a reverse-shell module such as Pentest Monkey and select it. The corresponding payload will be generated automatically using your specified attack machine IP address and port.
Copy the generated payload and create a new PHP file on your attack machine. Paste the copied code into the file and save it for the next stage of the lab.
nano shell.php
#nano - Opens the Nano text editor.
#shell.php - Creates or opens a file named shell.php.
# Running this command opens a text editor directly in the terminal, where you can enter your desired text.
cat shell.php
#cat - Displays the contents of a file.
#shell.php - Specifies the file to read.nano shell.php
#nano - Opens the Nano text editor.
#shell.php - Creates or opens a file named shell.php.
# Running this command opens a text editor directly in the terminal, where you can enter your desired text.
cat shell.php
#cat - Displays the contents of a file.
#shell.php - Specifies the file to read.
Once shell.php has been created, upload it through the /panel endpoint using the same process as the test file. Then, access the uploaded file through the /uploads endpoint while listening on the configured port with Netcat. If the server executes the PHP payload and the connection succeeds, a reverse shell will be established on your attack machine.
The application blocks the upload of PHP files, indicating that it may have file-type validation or input sanitization in place to prevent PHP files from being uploaded.
Since direct PHP uploads are blocked, the next step is to test whether the application's client-side file-extension validation can be bypassed using an alternative extension that may still be processed as PHP by the server.
We can use other extension such as
.php5
.phtml
.pht
.phtm
.phar
#Alternative extension of PHP.
.php5
.phtml
.pht
.phtm
.phar
#Alternative extension of PHP.We rename the shell.php file to use the .php5 extension while retaining the same PHP payload.
mv shell.php php_bypass_shell.php5
#mv - Moves or renames a file.
#shell.php - Original filename.
#php_bypass_shell.php5 - New filename with a .php5 extension.
cat php_bypass_shell.php5
#cat - Displays the contents of a file.
#php_bypass_shell.php5 - Specifies the file to read.mv shell.php php_bypass_shell.php5
#mv - Moves or renames a file.
#shell.php - Original filename.
#php_bypass_shell.php5 - New filename with a .php5 extension.
cat php_bypass_shell.php5
#cat - Displays the contents of a file.
#php_bypass_shell.php5 - Specifies the file to read.
Now that the file containing the same payload has been renamed with the .php5 extension, proceed to the /panel endpoint and attempt to upload it.
The file was successfully uploaded. Now, access the /uploads endpoint to verify that the file is present and accessible.
Exploitation and Initial Access
Next, access the uploaded .php5 file while running a Netcat listener on the configured port to capture the reverse-shell connection.
nc -lvnp 4488
#nc - Starts Netcat.
#-l - Listen mode.
#-v - Verbose output.
#-n - Disable DNS resolution.
#-p 4488 - Listen on port 4488.nc -lvnp 4488
#nc - Starts Netcat.
#-l - Listen mode.
#-v - Verbose output.
#-n - Disable DNS resolution.
#-p 4488 - Listen on port 4488.
Now, access the uploaded .php5 file through the /uploads endpoint. If the server executes the payload successfully, the reverse-shell connection will be received by the Netcat listener on the attack machine.
We have successfully obtained a shell and are currently operating as the www-data user. Next, we will run a few basic enumeration commands to assess our current privileges and determine what actions are available from this account.
www-data is a low-privilege system account commonly used by web servers such as Apache on Linux. It typically has limited permissions to access web application files and run web server processes, rather than full administrative privileges.
id
#id - Displays the current user ID, group ID, and group memberships.
whoami
#whoami - Displays the username of the current user.
which python
#which python - Checks whether Python is installed and displays its executable path.
python3 -c 'import pty; pty.spawn("/bin/bash")'
#python3 -c 'import pty; pty.spawn("/bin/bash")' - Uses Python to spawn a Bash shell, providing a more interactive terminal session.id
#id - Displays the current user ID, group ID, and group memberships.
whoami
#whoami - Displays the username of the current user.
which python
#which python - Checks whether Python is installed and displays its executable path.
python3 -c 'import pty; pty.spawn("/bin/bash")'
#python3 -c 'import pty; pty.spawn("/bin/bash")' - Uses Python to spawn a Bash shell, providing a more interactive terminal session.
Now that we have obtained an interactive shell, the next step is to explore the target system and locate our first flag, user.txt.
find / -type f -name 2>/dev/null
#find / โ Searches from the root directory.
#-type f โ Searches for files only.
#-name "user.txt" โ Matches files named user.txt.
#2>/dev/null โ Hides error messages, such as permission-denied errors.
cat /var/www/user.txt
#cat โ Displays the contents of a file.
#/var/www/user.txt โ Specifies the location of the user.txt flag file.find / -type f -name 2>/dev/null
#find / โ Searches from the root directory.
#-type f โ Searches for files only.
#-name "user.txt" โ Matches files named user.txt.
#2>/dev/null โ Hides error messages, such as permission-denied errors.
cat /var/www/user.txt
#cat โ Displays the contents of a file.
#/var/www/user.txt โ Specifies the location of the user.txt flag file.
Questions Answered in the Initial Access section
Task 4: Priviledge Escalation
Privilege Escalation is the process of gaining higher-level permissions on a system, such as moving from a low-privileged user to root/administrator access.
SUID (Set User ID) is a Linux permission that allows a file to execute with the privileges of its owner, rather than the user running it. SUID files owned by root can therefore be important during privilege-escalation enumeration.
find / -perm -4000 -type f 2>/dev/null
#find / - Searches from the root directory.
#-perm -4000 - Finds files with the SUID permission set.
#-type f - Searches for files only.
#2>/dev/null - Hides permission-denied error messages.find / -perm -4000 -type f 2>/dev/null
#find / - Searches from the root directory.
#-perm -4000 - Finds files with the SUID permission set.
#-type f - Searches for files only.
#2>/dev/null - Hides permission-denied error messages.After running the command, we will obtain a list of files with the SUID permission bit enabled. We can then review the list and investigate any unusual or potentially exploitable binaries.
We identified Python as a suspicious SUID-enabled binary. Python normally should not have the SUID bit (4000) enabled because it is an interpreter capable of executing arbitrary code.
If Python runs with SUID privileges, it may execute that code with the file owner's privileges. If the owner is root, this can potentially allow a low-privileged user to execute commands with root-level privileges, resulting in privilege escalation.
To investigate the SUID-enabled Python binary, we can refer to GTFOBins, a resource that documents techniques for abusing Unix binaries in security testing and privilege-escalation scenarios.
Open GTFOBins and search for Python, as it was identified with the SUID permission. Navigate to the SUID section under the shell options to find the relevant technique.
Copy the provided command and execute it within the existing interactive shell to test whether the SUID-enabled Python binary can be used to escalate privileges.
Executing the provided command successfully escalated our privileges. We can verify this by running the id command, which confirms that we are now operating as the root user.
Now that we have obtained root privileges, we can search the system for the root.txt file containing the root flag.
find / -type f -name root.txt
#find / - Searches from the root (/) directory.
#-type f - Searches for files only.
#-name "root.txt" - Searches for a file named root.txt.
pwd
#pwd - Shows the present working directory.
cat /root/root.txt
#cat - Displays the contents of a file.
#/root/root.txt - Specifies the location of the root.txt file.find / -type f -name root.txt
#find / - Searches from the root (/) directory.
#-type f - Searches for files only.
#-name "root.txt" - Searches for a file named root.txt.
pwd
#pwd - Shows the present working directory.
cat /root/root.txt
#cat - Displays the contents of a file.
#/root/root.txt - Specifies the location of the root.txt file.
Questions Answered in the Privilege Escalation section
Key Learnings
- Network Enumeration: Using Nmap to identify open ports and running services.
- Web Enumeration: Discovering hidden directories and endpoints using Gobuster.
- File Upload Testing: Identifying and testing file-upload functionality and validation.
- Initial Access: Understanding how a vulnerable file-upload mechanism can lead to a reverse shell.
- Privilege Escalation: Identifying SUID-enabled binaries and understanding how misconfigured permissions can lead to root access.