Drive
Gaining Access
$ nmap -p- --min-rate 3000 10.129.51.107
Starting Nmap 7.93 ( https://nmap.org ) at 2023-10-18 01:24 +08
Nmap scan report for 10.129.51.107
Host is up (0.0072s latency).
Not shown: 65532 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
3000/tcp filtered ppp$ nmap -p 80,3000 -sC -sV --min-rate 3000 10.129.51.107
Starting Nmap 7.93 ( https://nmap.org ) at 2023-10-18 01:25 +08
Nmap scan report for 10.129.51.107
Host is up (0.0071s latency).
PORT STATE SERVICE VERSION
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to http://drive.htb/
3000/tcp filtered ppp
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelWeb Enumeration -> User Password






Privilege Escalation
Gitea -> DB -> Tom Password




Format String Vulnerability -> Stack Canary (unused)

Ghidra -> SQL Injection







Last updated