October 9, 2026
Mr. Robot CTF โ From Web Enumeration to Root Access | Full Walkthrough
1. Introduction
By 0xDarsh
6 min read
1. Introduction
This write-up documents a penetration testing assessment of the Mr. Robot CTF machine, an intentionally vulnerable Linux system hosted in a local VMware lab environment.
The objective is to identify exposed services, discover security weaknesses, and retrieve three hidden keys through systematic enumeration, exploitation, and privilege escalation.
The assessment follows a black-box approach, beginning with limited knowledge of the target.
2. Lab Environment
- Assessment Type: Black-box Penetration Testing
- Attacker Machine: Kali Linux
- Target Machine: Mr. Robot CTF
- Target IP: 192.168.42.164
- Environment: VMware Local Lab
- Objective: Retrieve all three CTF keys
3. Reconnaissance & Web Enumeration
3.1 Directory and File Discovery
Web content enumeration was performed using Gobuster to identify accessible directories and files on the target web server.
gobuster dir -u http://192.168.42.164 -w /usr/share/wordlists/dirb/common.txtgobuster dir -u http://192.168.42.164 -w /usr/share/wordlists/dirb/common.txtThe enumeration identified a publicly accessible robots.txt file, which was selected for further investigation.
4. Key 1 โ Information Disclosure
4.1 Analyzing robots.txt
The discovered file was accessed through the browser:
http://192.168.42.164/robots.txthttp://192.168.42.164/robots.txtThe response contained the following entries:
User-agent: *
fsocity.dic
key-1-of-3.txtUser-agent: *
fsocity.dic
key-1-of-3.txtThe file disclosed two interesting resources:
- fsocity.dic: A dictionary file potentially useful for subsequent security testing.
- key-1-of-3.txt: A file revealing the location of the first CTF key.
Evidence โ Figure 1
Figure 1 โ Publicly accessible robots.txt revealing the first key location and a dictionary file.
4.2 First Key Retrieval
Following the discovery, the identified key file was accessed directly:
http://192.168.42.164/key-1-of-3.txthttp://192.168.42.164/key-1-of-3.txtThe first CTF key was successfully retrieved without authentication.
Result: Key 1 successfully obtained.
4.3 Security Observation
The discovery highlights an information disclosure issue involving publicly accessible web resources.
The robots.txt file is designed to provide crawling instructions to search engines rather than enforce access restrictions.
Although listing a file in robots.txt is not inherently a vulnerability, referencing sensitive resources can expose their locations to unauthorized visitors when appropriate access controls are absent.
Security Recommendation: Protect sensitive resources using server-side authentication and authorization controls rather than relying on hidden file paths.
Assessment Progress: 1 of 3 Keys Retrieved
The next section will cover Key 2 โ Initial Access, followed by Key 3 โ Privilege Escalation. Both sections will be added after their respective findings have been validated.
5. Key 2 โ Initial Access
5.1 Admin Login Page Discovery
During directory enumeration using Gobuster, I discovered an administrative login page on the target web application.
This endpoint provided an opportunity to investigate the application's authentication mechanism.
5.2 Wordlist Preparation
The robots.txt file previously revealed a dictionary named fsocity.dic.
I downloaded the dictionary and prepared it for username enumeration against the discovered login page.
5.3 Username Enumeration โ Burp Suite Intruder
While testing the login functionality, I observed that the application returned verbose error messages explicitly indicating when a submitted username was invalid.
This behavior acted as a Username Enumeration Oracle, allowing me to distinguish valid usernames from invalid ones.
I configured a Sniper attack in Burp Suite Intruder using the prepared wordlist to automate the enumeration process.
The attack revealed two valid username variations:
Elliot
elliotElliot
elliot
Figure 2 โ Username enumeration using Burp Suite Intruder, identifying valid usernames through verbose authentication error messages.
Finding: Username Enumeration via Verbose Authentication Error Messages.
Result: Valid usernames identified, providing a starting point for further authentication testing.
5.4 Password Discovery โ Burp Suite Intruder
After identifying elliot as a valid username, I performed a password attack using Burp Suite Intruder.
I reused the previously discovered fsocity.dic wordlist and configured a Sniper attack, keeping the username fixed as elliot while testing different password candidates.
During the attack, I identified an interesting response that differed from the unsuccessful login attempts:
ResponseStatus CodeLengthFailed Login200 OK4025 bytesSuccessful Login302 Found1114 bytes
The HTTP 302 redirect indicated a potential successful authentication attempt.
Figure 3 โ Password discovery using Burp Suite Intruder, highlighting the HTTP 302 redirect and response length difference.
5.5 Successful Authentication โ WordPress Dashboard
After identifying the password, I manually tested the discovered credentials against the WordPress login page.
Authentication was successful, granting access to the WordPress Dashboard as elliot.
This confirmed that the HTTP 302 response observed during the Intruder attack corresponded to a successful login.
Figure 4 โ Successful authentication to the WordPress Dashboard using the discovered credentials.
Result: Valid WordPress credentials obtained and authenticated dashboard access achieved.
5.6 Initial Access โ WordPress Web Shell Upload
After successfully authenticating to the WordPress Dashboard, I explored the available administrative features and identified several file upload entry points.
I accessed the WordPress theme upload functionality through:
http://192.168.42.164/wp-admin/theme-install.php?uploadhttp://192.168.42.164/wp-admin/theme-install.php?uploadUsing this functionality, I uploaded a PHP web shell to the target server.
Next, I navigated to the WordPress Media Library:
http://192.168.42.164/wp-admin/upload.phphttp://192.168.42.164/wp-admin/upload.phpFrom there, I identified the location of the uploaded web shell and accessed its URL directly through the browser.
The web shell executed successfully, providing remote command execution on the target system.
Figure 5 โ Uploading the PHP web shell through the WordPress theme upload functionality.
Figure 6 โ Successfully accessing the uploaded web shell on the target server.
Result: Authenticated Remote Code Execution (RCE) achieved through WordPress file upload functionality.
5.7 Local Enumeration โ Robot User Directory
After obtaining remote command execution through the uploaded web shell, I began enumerating the target filesystem.
I inspected the robot user's home directory:
ls -la /home/robotls -la /home/robotThe directory contained two interesting files:
key-2-of-3.txt
password.raw-md5key-2-of-3.txt
password.raw-md5The key-2-of-3.txt file was owned by the robot user and had restrictive permissions, preventing the current web shell user from reading it.
However, the password.raw-md5 file was readable and contained a username and an MD5 password hash:
robot:c3fcd3d76192e4007dfb496cca67e13brobot:c3fcd3d76192e4007dfb496cca67e13bAn attempt to read the second key resulted in:
cat: /home/robot/key-2-of-3.txt: Permission deniedcat: /home/robot/key-2-of-3.txt: Permission denied
Figure 7 โ Discovering the second key and an exposed MD5 password hash in the robot user's home directory.
Finding: Sensitive credential material exposed through a readable file.
Result: Key 2 located, but access was restricted by filesystem permissions.
6. Key 3 โ Linux Privilege Escalation
6.1 Privilege Escalation Enumeration
After obtaining initial access to the target system, I began investigating potential privilege escalation vectors.
I explored several techniques, including:
- Metasploit Local Exploit Suggester โ Identifying potential local privilege escalation vulnerabilities.
- Cron Job Enumeration โ Checking scheduled tasks for possible misconfigurations.
- SUID Binary Enumeration โ Identifying executables with elevated privileges.
During SUID enumeration, I discovered that the nmap binary had the SUID permission enabled.
6.2 Exploiting the Nmap SUID Misconfiguration
The SUID permission allows an executable to run with the privileges of its file owner rather than the user executing it.
Since nmap was configured with SUID permissions, I investigated whether it could be used to execute commands with elevated privileges.
By leveraging the available functionality of the installed Nmap version, I successfully obtained a root shell.
Figure 8 โ Identifying the Nmap binary with SUID permissions enabled.
Figure 9 โ Successful privilege escalation to root through the SUID-enabled Nmap binary.
6.3 Retrieving the Third Key
After gaining root privileges, I accessed the third key, which had previously been inaccessible to the lower-privileged account.
Result: Key 3 Successfully Retrieved.
6.4 Security Finding
Vulnerability: Privilege Escalation via SUID-Enabled Nmap
Root Cause: An executable capable of launching commands was configured with elevated execution privileges.
Impact: A lower-privileged user could escalate privileges to root, resulting in complete system compromise.
Recommendation: Remove unnecessary SUID permissions from executables and regularly audit privileged binaries.
7. Conclusion
The Mr. Robot CTF demonstrated how multiple security weaknesses can be chained together to achieve full system compromise.
The assessment involved web enumeration, information disclosure, username enumeration, password discovery, authenticated file upload, local filesystem enumeration, and Linux privilege escalation.
The final privilege escalation was achieved through a misconfigured SUID-enabled Nmap executable.
Final Result: Root Access Achieved โ Key 3 Retrieved.