Posts

HTB: Cap Walkthrough

Image
  Writeup — Cap By Araiz Naqvi Overview - Difficulty: Easy - Operating System: Linux - Objective: Capture User and Root flag. - Tools Used: nmap , ftp , sshclient , whatweb , gunicorn , wireshark , openvpn , python3 If you’re unable to view it fully due to Medium Subscriptions, you can view it at  Nmap Scanning As in most times the first step is to scan the target IP to check for open ports and service and service versions running on them: Nmap Scan As can be seen the services running are FTP , SSH and HTTP . Also, Linux seems to be running on the target. Trying Logging in FTP and SSH Let’s try to use anonymous login for FTP : FTP Login Attempt Does not allow anonymous login. Similarly, even SSH was not accepting common usernames and passwords. Clearly, I might find credentials somewhere. This is really valuable information, but let’s still get information on other aspects of the target. Let’s continue by Web Fingerprinting . Enumerating Web Fingerprint ...

HTB: Nibbles Walkthrough

Image
  Writeup — Nibbles By Araiz Naqvi Overview Difficulty: Easy - Operating System: Linux - Objective: Understand potential breaking points in nibble machine. - Tools Used: nmap , nc , whatweb , searchsploit , metasploit , gobuster , SecsList , linpeas Prepared by Araiz Naqvi Starting Enumeration with Nmap The very first step is to get an idea of the open ports and services running. To do this we will start with nmap scans: Nmap Scanning for open ports Here, two ports are open, SSH and HTTP which also show that the target is running Linux Ubuntu 2.2 version and an Apache httpd 2.4.18 server. But, before we go deeper into these open ports, let’s run an all ports TCP scan and leave it in the background cause usually it takes forever to happen. Leaving the everlong TCP all port scan in the background I actually did some banner grabbing in the meanwhile, but for consistency sake, I also immediately did a few other nmap scans to try and get as much information as p...