Our first write-up, how exciting. This machine was given to me as a challenge from a friend, so let’s get right into it. Note: This walkthrough was written after I rooted Moria, not during.
The first step for pretty much any challenge I’ve been presented with is to kick off an Nmap scan and look for j00cy services. The results of the scan showed there was a web server running on port 80, as well as FTP and SSH services running on ports 21 & 22 respectively.
Navigating to the web server with firefox, we’re presented with the Gates of Moria. I am not a LOTR fan (Sorry?) so I was already worried that my lack of lore knowledge was going to fuck me over. Thankfully, it did not.
With nothing of use on the page other than an image, and nada in the source; I fired up dirb and started enumerating.
With just the common wordlist, dirb found a index.php page (duh), as well as /cgi-bin/ (maybe some shellshocking involved?) and /w/. Navigating to /w/ led me down a long chain of directories — to w/h/i/s/p/e/r/the_abyss/.
On the page at the end of this chain was some text — Telchar to Thrain:“That human is slow, don’t give up yet” — Huh? After refreshing the page, I was presented with some new text — Nain:”Will the human get the message?”.