A walkthrough of the Brooklyn Nine-Nine CTF machine on TryHackMe. The process covers enumeration with nmap (discovering FTP, SSH, HTTP), steganography analysis of a web image using steghide and stegcracker to extract credentials, anonymous FTP login to find user hints, SSH brute-forcing with nmap scripts, and two privilege escalation paths using GTFOBins exploits for the 'less' and 'nano' commands running with sudo NOPASSWD.
Table of contents
1. Enumeration2. Play with servicesGet mahyar kermani’s stories in your inbox3. Summary196 Impressions