October 10, 2026
Lookup (THM) Tryhackme Walkthrough
Description : Test your enumeration skills on this boot-to-root machine.

By Lawvye
2 min read
Difficulty : Easy
Note : All of the content and images are from https://tryhackme.com/
Room : https://tryhackme.com/room/lookup
Enjoy.
Port Scanning :
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.9 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 44:5f:26:67:4b:4a:91:9b:59:7a:95:59:c8:4c:2e:04 (RSA)
| 256 0a:4b:b9:b1:77:d2:48:79:fc:2f:8a:3d:64:3a:ad:94 (ECDSA)
|_ 256 d3:3b:97:ea:54:bc:41:4d:03:39:f6:8f:ad:b6:a0:fb (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Did not follow redirect to http://lookup.thm
|_http-server-header: Apache/2.4.41 (UbuntuPORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.9 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 44:5f:26:67:4b:4a:91:9b:59:7a:95:59:c8:4c:2e:04 (RSA)
| 256 0a:4b:b9:b1:77:d2:48:79:fc:2f:8a:3d:64:3a:ad:94 (ECDSA)
|_ 256 d3:3b:97:ea:54:bc:41:4d:03:39:f6:8f:ad:b6:a0:fb (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Did not follow redirect to http://lookup.thm
|_http-server-header: Apache/2.4.41 (UbuntuWalkthrough :
- Reconnaissance (Recon)
- Open Ports: Port 22 (SSH) and Port 80 (HTTP).
- Host Mapping: Add the domain
lookup.thmto your/etc/hostsfile. - Web Enumeration: Using FFUF reveals initial credentials (username:
jose, password:password123).
2. Exploitation (Initial Access)
- Vulnerability:
elFinder 2.1.47is vulnerable toCVE-2019-9194(command injection via the image rotation/renaming feature). - Payload: Upload a PHP payload to establish a reverse shell into the system.
3. Privilege Escalation 1 (User -> Think)
- SUID Binary: A SUID binary file located at
/usr/sbin/pwmis discovered. - Exploitation: Manipulate the
PATHvariable to read the.passwordsfile. - Brute-force: Use Hydra to brute-force the SSH credentials for the user
think.
4. Privilege Escalation 2 (Root)
- Sudo Permissions: The user has sudo permissions for
/usr/bin/look. - Exploitation: Leverage this permission to read the root private key located at
/root/.ssh/id_rsa. - Final Flag: Log in via SSH as
rootusing the retrieved key to capture the root flag.
Task 1 Lookup
Lookup offers a treasure trove of learning opportunities for aspiring hackers. This intriguing machine showcases various real-world vulnerabilities, ranging from web application weaknesses to privilege escalation techniques. By exploring and exploiting these vulnerabilities, hackers can sharpen their skills and gain invaluable experience in ethical hacking. Through "Lookup," hackers can master the art of reconnaissance, scanning, and enumeration to uncover hidden services and subdomains. They will learn how to exploit web application vulnerabilities, such as command injection, and understand the significance of secure coding practices. The machine also challenges hackers to automate tasks, demonstrating the power of scripting in penetration testing.
Note: It is recommended to use your own VM if you'll ever experience problems visualizing the site.
Answer the questions below
Q1.) What is the user flag?
cat user.txt
38375fb4dd8baa2b2039ac03d92b820ecat user.txt
38375fb4dd8baa2b2039ac03d92b820eAnswer : 38375fb4dd8baa2b2039ac03d92b820e
Q1.) What is the root flag?
$ LFILE=/root/root.txt $ sudo /usr/bin/look '' "$LFILE"
5a285a9f257e45c68bb6c9f9f57d18e8$ LFILE=/root/root.txt $ sudo /usr/bin/look '' "$LFILE"
5a285a9f257e45c68bb6c9f9f57d18e8Answer : 5a285a9f257e45c68bb6c9f9f57d18e8
I hope you enjoyed reading this post as much as I enjoyed writing it. Thanks for reading my blog sir ;) Lawvye