
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up
Exploit • Writeup • CTF Challenge
A comprehensive repository containing a custom exploit and detailed writeup for the TryHack3M: Bricks Heist challenge
Quick Start • Repository Structure • The Exploit • The Writeup • Disclaimer
This repository documents the TryHack3M: Bricks Heist challenge — a medium-difficulty CTF room involving:
| Phase | Description |
|---|---|
| Reconnaissance | Discovering a vulnerable WordPress site with Bricks Builder |
| Exploitation | Leveraging CVE-2024-25600 for unauthenticated RCE |
| Investigation | Uncovering a hidden crypto miner linked to LockBit ransomware |
| Attribution | Tracing Bitcoin transactions to sanctioned threat actors |
TryHack3M-Bricks-Heist/
│
├── README.md ← You are here
│
├── Exploit/
│ ├── README.md ← Detailed exploit documentation
│ ├── brickbreaker.py ← The exploit tool
│ └── requirements.txt ← Python dependencies
│
└── WriteUp/
└── WRITEUP.md ← Full challenge walkthrough
| Directory | Contents | Link |
|---|---|---|
| Exploit/ | BrickBreaker v2.2 — Custom CVE-2024-25600 exploit with interactive shell | Read More |
| WriteUp/ | Complete step-by-step walkthrough with screenshots and answers | Read More |
# Clone the repository
git clone https://github.com/h0w1tzxr/TryHack3M-Bricks-Heist.git
cd TryHack3M-Bricks-Heist/Exploit
# Set up environment
python3 -m venv brickbreaker && source brickbreaker/bin/activate
pip install -r requirements.txt
# Launch exploit
python3 brickbreaker.py https://target.com
Jump straight to the Complete Writeup to see how the challenge was solved from start to finish.
Unauthenticated Remote Code Execution for WordPress Bricks Builder
| Feature | Description |
|---|---|
| Auto-exploitation | Extracts nonce and exploits automatically |
| Interactive Shell | Full PTY-like experience with history |
| File Transfer | Upload/download files via base64 |
| Reverse Shells | 5 payload types (bash, python, nc, php, perl) |
| Batch Scanner | Mass vulnerability scanning |
| Beautiful TUI | Rich terminal interface |
██████╗ ██████╗ ██╗ ██████╗██╗ ██╗ ██████╗ ██████╗ ███████╗ █████╗ ██╗ ██╗███████╗██████╗
██╔══██╗██╔══██╗██║██╔════╝██║ ██╔╝ ██╔══██╗██╔══██╗██╔════╝██╔══██╗██║ ██╔╝██╔════╝██╔══██╗
██████╔╝██████╔╝██║██║ █████╔╝ ██████╔╝██████╔╝█████╗ ███████║█████╔╝ █████╗ ██████╔╝
██╔══██╗██╔══██╗██║██║ ██╔═██╗ ██╔══██╗██╔══██╗██╔══╝ ██╔══██║██╔═██╗ ██╔══╝ ██╔══██╗
██████╔╝██║ ██║██║╚██████╗██║ ██╗ ██████╔╝██║ ██║███████╗██║ ██║██║ ██╗███████╗██║ ██║
╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═════╝╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
From exploitation to threat actor attribution
The writeup covers the entire attack chain and investigation:
| Phase | What You'll Learn |
|---|---|
| Reconnaissance | Port scanning, WordPress enumeration, identifying Bricks Builder |
| Exploitation | Using BrickBreaker to gain initial access via CVE-2024-25600 |
| Forensics | Discovering hidden files, malicious services, and crypto miners |
| Blockchain | Decoding obfuscated wallet addresses and tracing transactions |
| Attribution | Linking activity to the LockBit ransomware group via OFAC |
| # | Question | Hint |
|---|---|---|
| 1 | Hidden .txt file content | THM{...} |
| 2 | Suspicious process name | nm-****-****** |
| 3 | Service name | ******.service |
| 4 | Miner log file | ****.**** |
| 5 | Wallet address | bc1q... |
| 6 | Threat group | 7 characters |
| Tool | Purpose |
|---|---|
| Exploit development | |
| Port scanning | |
| Data decoding | |
| Transaction tracing |
╔══════════════════════════════════════════════════════════════════════════════╗
║ WARNING ║
╠══════════════════════════════════════════════════════════════════════════════╣
║ ║
║ This repository is for EDUCATIONAL and AUTHORIZED SECURITY TESTING only. ║
║ ║
║ • Only use on systems you OWN or have EXPLICIT WRITTEN PERMISSION to test ║
║ • Unauthorized access to computer systems is ILLEGAL ║
║ • The authors are NOT responsible for any misuse or damage caused ║
║ • Always follow RESPONSIBLE DISCLOSURE practices ║
║ ║
╚══════════════════════════════════════════════════════════════════════════════╝
| Resource | Link |
|---|---|
| CVE-2024-25600 (NVD) | nvd.nist.gov |
| Original Disclosure | Snicco Security |
| OFAC Sanctions | Treasury.gov |
| LockBit Advisory | CISA |
| TryHackMe Room | TryHackMe |