Posts

HTB: Sightless Walkthrough

Image
Writeup — Sightless By Araiz Naqvi Overview Difficulty: Easy - Operating System: Linux - Objective : Understand potential breaking points in sightless machine. - Tools Used: Nmap , SSH , FTP , Burpsuite , Hashcat , John The Ripper , FoxyProxy , nc , Gobuster , curl , filezilla , keep2john , kpcli , dos2unix If you’re unable to view it fully due to Medium Subscriptions, you can view it at https://araizhacks.blogspot.com/2025/01/htb-cap-walkthrough.html I tend to start enumerating as much basic information as I need before delving deeper. Performing Nmap Scans As usual the very first step is to figure out what ports and hence what services are actually open. This will set the stage for how we will try to break in. Let’s start with a stealth scan with disabled arp pings to figure out what ports are open: It is clear that the following ports are open: - 21 ~ FTP - 22 ~ SSH - 80 ~ HTTP Now, let’s move further and scan for service versions and run the default scripts on these ...

HTB: Cap Walkthrough

Image
  Writeup — Cap By Araiz Naqvi Overview - Difficulty: Easy - Operating System: Linux - Objective: Capture User and Root flag. - Tools Used: nmap , ftp , sshclient , whatweb , gunicorn , wireshark , openvpn , python3 If you’re unable to view it fully due to Medium Subscriptions, you can view it at  Nmap Scanning As in most times the first step is to scan the target IP to check for open ports and service and service versions running on them: Nmap Scan As can be seen the services running are FTP , SSH and HTTP . Also, Linux seems to be running on the target. Trying Logging in FTP and SSH Let’s try to use anonymous login for FTP : FTP Login Attempt Does not allow anonymous login. Similarly, even SSH was not accepting common usernames and passwords. Clearly, I might find credentials somewhere. This is really valuable information, but let’s still get information on other aspects of the target. Let’s continue by Web Fingerprinting . Enumerating Web Fingerprint ...