Deployer
Gaining Access
$ nmap -p- --min-rate 3000 -Pn 192.168.157.158
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-16 11:41 +08
Nmap scan report for 192.168.157.158
Host is up (0.17s latency).
Not shown: 65462 closed tcp ports (conn-refused), 70 filtered tcp ports (no-response)
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
80/tcp open httpFTP -> Subdomain + Source Code
$ ftp 192.168.157.158
Connected to 192.168.157.158.
220 (vsFTPd 3.0.3)
Name (192.168.157.158:kali): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||42744|)
150 Here comes the directory listing.
drwxr-xr-x 2 0 0 4096 Jul 16 03:41 bak
drwxr-xr-x 2 113 118 4096 May 11 2021 ftp
drwxr-xr-x 4 0 0 4096 May 11 2021 sec
drwxr-xr-x 8 0 0 4096 May 11 2021 site
drwxr-xr-x 5 0 0 4096 May 11 2021 webDeserialisation -> LFI + RCE




Privilege Escalation
Sudo Docker Build -> Root


Last updated