Mirai
| Release Date | 01 Sep 2017 |
|---|---|
| Retire Date | 10 Feb 2018 |
| Difficulty | Easy - Retired [0] |
| Creator | Arrexel |
| CherryTree File | Mirai.ctb.txt |
Enumeration
Nmap exposed SSH, DNS, and a Lighttpd web service. Gobuster discovered /admin and /versions; the admin page revealed a Pi-hole installation.
22/tcp open ssh
53/tcp open domain
80/tcp open http lighttpd 1.4.35
Initial Access
The target was a Raspberry Pi that still used the default credentials. SSH access succeeded with pi:raspberry.
Privilege Escalation
The pi account had broad sudo rights, allowing a root shell. The root flag had been removed from its expected location, but a note identified the USB device that previously held it. Recovering the deleted data from that device produced the flag.