Source
Reconnaissance
Initial nmap scan to find open ports , using the flag "treat all hosts as alive" (-Pn)
Detailed Nmap Scan :
Command Breakdown:
(-sV): Service version
(-sC): Default nmap scripts
(-p): Specifying ports 22,10000
(-oN nmap): Saving it into a file called nmap
Enumeration
Lets visit the site on port 10000
Looks like we should go to https//<ip>
, lets do that
Lets go to Advanced and hit Accept Risk and Continue
We have a login page. We do not have credentials so lets go to searchsploit and look for exploits on the application and the specific version we see in the nmap scan. I searched for it on searchsploit and got nothing back
They show how to use it as well, so lets go ahead and use it.
In the end they give us the option of sending a command, we sent id and it worked, lets read the user flag and the root flag.
We have both the flags.
Last updated