Bounty Hacker writeup and attack path
Bounty Hacker is a easy Linux machine on TryHackMe that I solved myself. This page is my short attack path summary and the techniques it trains.
| Platform | TryHackMe |
|---|---|
| Operating system | Linux |
| Difficulty | Easy |
| Time to user | 18m |
| Time to root | 45m |
| User owned | 2026-08-15 |
| Root owned | 2026-08-15 |
Attack path summary
Anonymous FTP reveals task.txt and locks.txt. Brute force SSH user lin with hydra, then abuse tar sudo privileges.
Techniques
FTP-Anonymous Hydra Tar-SUID
Track Bounty Hacker in ZeroBox. Log your progress, notes and flags offline in your browser, and follow the pentest methodology checklist.
Bounty Hacker belongs to TryHackMe. This page contains only my own notes.