Skip to main content

Command Palette

Search for a command to run...

Pickle Rick

Updated
โ€ข5 min readโ€ขView as Markdown

NOTE: My IP address will be different from yours!

This Ricky and Morty themed challenge requires you to exploit a webserver to find three ingredients that will help Rick make his potion to transform himself back into a human from a pickle

Lab Info

Detail Info
Room Name Pickle Rick
Platform TryHackMe
Difficulty Easy โ€” Intermediate
Type CTF / Web Exploitation
Knowledge Required Web, Linux

Tools Used

  • Nmap โ€” Port scanning and service detection

  • Gobuster โ€” Web directory and file enumeration


Mindset & Methodology

Before touching any tool, I follow a structured approach. Jumping straight into exploitation without recon is how you waste hours going in circles. Recon โ†’ Enumeration โ†’ Exploitation โ†’ Privilege Escalation

The first question I always ask: What services are running, and on which ports?


Reconnaissance

1. Port Scanning with Nmap

Here i used the following command

nmap -T4 -Pn -p22,80 -A 10.49.144.2

Two open ports:

  • Port 22 (SSH) โ€” Needs credentials, park it for now

  • Port 80 (HTTP) โ€” Apache web server, this is where we start


2. Directory Enumeration with Gobuster

We are going to be using gobuster to try and locate any directories that may have been hidden from us.

gobuster dir -u http://10.49.144.2 -w /usr/share/seclists/Discovery/Web-Content/common.txt

It looks like GoBuster was able to find a few directories for us

  • assets (Status: 301)

  • index.html (Status: 200)

  • robots.txt (Status: 200)

  • And also a login.php page (Status: 200)

robots.txt is always worth checking โ€” it had a surprise waiting.


3. Web page & Inspecting the Page Source

When i viewed the main page at first, i didn't find anything intresting

But when i viewd the page source

view-source:http://10.49.144.2

i found a hidden HTML comment:

First win: The developer left the username hardcoded in a comment. Classic mistake.


4. Checking robots.txt

Next, I navigated to http://10.49.144.2/robots.txt and found the password sitting there in plaintext

Both credentials found without running a single exploit.


Exploitation

5. Logging In

Went to http://10.49.144.2/login.php and used:

  • Username: R1ckRul3s

  • Password: Wubbalubbadubdub

And here we go!! Landed on the Rick Portal
This page is called the command portal. Lets try and actually enter some commands and see what happens.

If we enter the ls command we can see that some results are being returned. It would seem that we have also found our first ingredient!


6. First Ingredient ๐Ÿฅ’

Tried reading the first ingredient with cat:

cat is blacklisted. A simple workaround is to open the file directly in the browser:

http://10.49.144.2/Sup3rS3cretPickl3Ingred.txt

And here we found the first ingredient!!


8. Second Ingredient

Since cat is blocked, I tried every command that I could think of and each of them always got me right back to the same command disabled page. So I had to reach out to Google to try and find out if there was an alternative command to cat. It took sometime but I was able to find a nice Wikipedia article on the less command.

less clue.txt

The clue pointed to the rick user's home directory.

ls /home/rick second ingredients

less /home/rick/"second ingredients"

Bingo! Second ingredient found!


9. Third Ingredient ๐Ÿฅ’

The third ingredient required root access. First thing I check for privilege escalation:

sudo -l

The current user can run any command as sudo with no password required โ€” a critical misconfiguration.

sudo ls /root

sudo less /root/3rd.txt

And with that, the the third and final ingredient is found!!

Congrats! You have completed the Pickel Rick challenge!


Difficulty Assessment

Easy โ€” Intermediate. The concepts are straightforward but require logical thinking at each step.

The trickiest part was realizing cat was blacklisted and knowing to look for alternatives. That's a good lesson in itself โ€” in pentesting, there's always more than one path to the same goal.


Key Takeaways

  1. Page source is gold. Always check view-source and robots.txt before anything else.

  2. Sensitive info is often hiding in HTML comments or config files that should never be public.

  3. RCE = Game Over. When a Command Panel runs server-side commands without proper validation, the attacker effectively owns the machine. Never expose raw command execution to authenticated (let alone unauthenticated) users.

  4. Blacklists are weak โ€” Blocking cat alone means nothing. I found out that not only less can read files, but also strings, grep, tac, head, tail can also do so just fine.


    Day 1 of 30 โœ… โ€” See you tomorrow.

185 views