Matrix 1 is the original of the series and a clean lesson in clue-following plus restricted-shell escape. A base64 blob in page source points at a file encoded in Brainfuck, which leaks most of an SSH password; crunch and hydra finish the rest. The shell that credential opens is a restricted rbash, escaped through vi, and root is a single permissive sudo rule away.
Attack chain at a glance
- Recon — SSH (22), HTTP (80), and an extra HTTP service on 31337; the pages hint “follow the white rabbit / Cypher.”
- Clue chain — a base64 comment decodes to a reference to
Cypher.matrix; that file is Brainfuck, which decodes to a username (guest) and a partial password (K1ll0r??). - Credential —
crunchgenerates the 8-char candidates,hydrabrute-forces SSH (weak/guessable password) tok1ll0r7n. - Foothold — SSH drops into a restricted
rbash; escape it throughvi's:!/bin/bash. - Root — reset
PATH, thensudo -lallows a direct root shell.
Techniques in play: multi-layer decoding (base64 → Brainfuck), targeted wordlist generation withcrunch+ online/offline brute force withhydra, the classicvirestricted-shell breakout (a GTFOBins staple), and a permissivesudorule.
Matrix 1 is the original of the series. The path: a base64-then-brainfuck clue chain that leaks a partial SSH password, crunch+hydra to finish it, a restricted-shell escape through vi, and a passwordless sudo for root.
Reconnaissance
netdiscover on the Kali host finds the target.
192.168.145.133.nmap shows SSH (22) and HTTP (80), plus an unusual HTTP port 31337. Port 80 greets us with the hint “follow the white rabbit.”
A nikto scan of port 80 finds nothing obviously exploitable.
nikto on port 80 — nothing actionable.The clue chain
Moving to port 31337, the page's only heading is “Cypher.” A dirb scan (and another nikto) looks for anything cipher-related.
nikto pass alongside it.dirb finds an assets directory.
assets directory appears.Inside is a file named port_31337.png.
port_31337.png.
It is a white rabbit — confirming we are on track — and its filename (the port) nudges us back to the page itself.
Revisiting port 31337 and viewing the source reveals a commented-out ciphertext:
<!--p class="service__text">ZWNobyAiVGhlbiB5b3UnbGwgc2VlLCB0aGF0IGl0IGlzIG5vdCB0aGUgc3Bvb24gdGhhdCBiZW5kcywgaXQgaXMgb25seSB5b3Vyc2VsZi4gIiA+IEN5cGhlci5tYXRyaXg=</p-->
Decoding the base64 in CyberChef yields a message ending in Cypher.matrix — which looks like a filename, so the URL is modified to request it.
Cypher.matrix.The server immediately offers a file named Cypher.matrix for download. Its contents are a string of odd characters.
Cypher.matrix — an unfamiliar character soup.The characters are Brainfuck.
An online Brainfuck interpreter reveals the message: the login username is guest, and the password is K1ll0r followed by two unknown characters.
guest; password K1ll0r?? — last two characters unknown.Finishing the password & SSH
crunch generates every 8-character candidate with the known K1ll0r prefix.
crunch.hydra brute-forces SSH against that list.
hydra.It recovers the password: k1ll0r7n.
k1ll0r7n.Restricted-shell escape & root
SSH drops us into a restricted bash. export shows the environment and the current path.
rbash on login.The path /home/guest/prog is readable, so its contents are inspected.
/home/guest/prog.It is vi — a classic restricted-shell escape.
vi is available — a known escape route.From within vi, :!/bin/bash spawns a full shell.
:!/bin/bash breaks out to a real shell.After resetting PATH so standard commands work, sudo -l shows root is available directly.
PATH.
sudo → root; flag.txt waits in /root.Opening it gives the flag, and the box is done.
Matrix 1 is pure clue-following: base64 → Brainfuck → a half-known password finished withcrunch/hydra, then a textbookvibreakout and an opensudorule. Enumeration does all the heavy lifting.
Defender's notes
- Don't hide credentials in client-side encodings — encoding is not encryption; anyone can decode a comment or a served file.
- Enforce strong, non-patterned passwords so a partial leak plus
crunch/hydracan't finish the job (weak password policy). - A restricted shell (
rbash) is not a security boundary when interpreters likevi/vim,less, orawkare reachable — restrictPATHand the available binaries, or don't rely on it. - Review
sudorules for least privilege.