
User Roots TryHackMe's 'Watcher' Box Entirely from Android Using Termux
cybersecurityTryHackMeTermuxAndroidCTFLFIreverse_shellprivilege_escalationSSH
The user completed the 'Watcher' room on TryHackMe entirely using Termux on an Android phone, without a laptop. The attack chain involved exploiting an LFI vulnerability to obtain FTP credentials, uploading a reverse shell, and escalating privileges through passwordless sudo, a writable cron job, and a hijacked Python script. The final step involved decoding a base64-encoded SSH private key from a group-writable backup directory to gain root access. Challenges included input lag, small screen limitations, and clipboard issues while working on mobile.