Easy Peasy
May 01, 2024
Task 1: Enumeration through Nmap
Starting Nmap 7.94 ( https://nmap.org ) at 2024-05-02 18:41 PST
Nmap scan report for 10.10.95.207
Host is up (0.32s latency).
PORT STATE SERVICE
80/tcp open http
Nmap done: 1 IP address (1 host up) scanned in 0.72 seconds
# Nmap 7.94 scan initiated Thu May 2 18:10:21 2024 as: nmap -T4 -p- -oN nmap-all -vv 10.10.95.207
Increasing send delay for 10.10.95.207 from 0 to 5 due to 89 out of 222 dropped probes since last increase.
Warning: 10.10.95.207 giving up on port because retransmission cap hit (6).
Nmap scan report for 10.10.95.207
Host is up, received conn-refused (0.32s latency).
Scanned at 2024-05-02 18:10:21 PST for 1530s
Not shown: 65532 closed tcp ports (conn-refused)
PORT STATE SERVICE REASON
6498/tcp open unknown syn-ack
61760/tcp filtered unknown no-response
65524/tcp open unknown syn-ack
Read data files from: /usr/bin/../share/nmap
# Nmap done at Thu May 2 18:35:51 2024 -- 1 IP address (1 host up) scanned in 1529.78 seconds
whatweb http://10.10.184.116/
Just download the txt file from the box
gobuster dir -u http://10.10.184.116/ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -o gobuster
ffuf -u http://10.10.184.116/hidden/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt
its encoded with ba....:ObsJmP173N2X6dOrAgEAL0Vu
User-Agent:a18672860d0510e5ab6699730763b250
ffuf -u http://10.10.95.207:65524/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt
940d71e8655ac41efb5f8ab850668505b86dd64186a66e57d1483e7f5fe6fd81
mypasswordforthatjob
steghide extract -sf binarycodepixabay.jpg
passphrase - mypasswordforthatjob
username - boring
01101001 01100011 01101111 01101110 01110110 01100101 01110010 01110100 01100101 01100100 01101101 01111001 01110000 01100001 01110011 01110011 01110111 01101111 01110010 01100100 01110100 01101111 01100010 01101001 01101110 01100001 01110010 01111001
iconvertedmypasswordtobinary
ssh boring@10.10.10.150 -p 6498
Last updated