Nappa
Gaining Access
$ nmap -p- --min-rate 3000 -Pn 192.168.201.114
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-15 12:08 +08
Warning: 192.168.201.114 giving up on port because retransmission cap hit (10).
Nmap scan report for 192.168.201.114
Host is up (0.17s latency).
Not shown: 65524 closed tcp ports (conn-refused)
PORT STATE SERVICE
21/tcp open ftp
3306/tcp open mysql
8080/tcp open http-proxy
28080/tcp open thor-engine
60022/tcp open unknownFTP Anonymous Creds
$ ftp 192.168.201.114
Connected to 192.168.201.114.
220 (vsFTPd 3.0.3)
Name (192.168.201.114:kali): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||59327|)
150 Here comes the directory listing.
drwxr-xr-x 14 14 11 4096 Nov 06 2020 forum
226 Directory send OK.
ftp> cd forum
l250 Directory successfully changed.
ftp> ls
229 Entering Extended Passive Mode (|||33106|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 1965 Nov 06 2020 Gemfile
-rw-r--r-- 1 0 0 5512 Nov 06 2020 Gemfile.lock
-rw-r--r-- 1 0 0 374 Nov 06 2020 README.md
-rw-r--r-- 1 0 0 227 Nov 06 2020 Rakefile
drwxr-xr-x 11 0 0 4096 Nov 06 2020 app
drwxr-xr-x 2 0 0 4096 Nov 06 2020 bin
drwxr-xr-x 5 0 0 4096 Nov 06 2020 config
-rw-r--r-- 1 0 0 130 Nov 06 2020 config.ru
drwxr-xr-x 2 0 0 4096 Nov 06 2020 db
drwxr-xr-x 4 0 0 4096 Nov 06 2020 lib
drwxr-xr-x 2 0 0 4096 Nov 06 2020 log
-rw-r--r-- 1 0 0 217 Nov 06 2020 package.json
drwxr-xr-x 2 0 0 4096 Nov 06 2020 public
drwxr-xr-x 2 0 0 4096 Nov 06 2020 storage
drwxr-xr-x 10 0 0 4096 Nov 06 2020 test
drwxr-xr-x 5 0 0 4096 Nov 06 2020 tmp
drwxr-xr-x 2 0 0 4096 Nov 06 2020 vendor
226 Directory send OK.Web Enumeration -> Password



More Page Source Reading -> RCE





Privilege Escalation
Base32Key -> Root

Last updated