Bounty Hacker is a Cowboy Bebop-themed machine that teaches FTP enumeration, password cracking with Hydra, and tar sudo privilege escalation. Simple but teaches core skills.
Walkthrough
Attack Path
1
FTPAnonymous login reveals credentials
2
Brute ForceHydra with found password list
3
SSHLogin as lin
4
Privesctar sudo escape via GTFOBins
GTFOBins
GTFOBins (gtfobins.github.io) lists ways to escape restricted environments using common Unix binaries. Essential for privilege escalation!
Knowledge Check
Key Takeaways
- Always check for anonymous FTP access
- Downloaded files may contain usernames and passwords
- Custom wordlists often work better than generic ones
- GTFOBins is essential for sudo escape techniques