Tico
Gaining Access
$ nmap -p- --min-rate 4000 -Pn 192.168.240.143
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-07 12:25 +08
Nmap scan report for 192.168.240.143
Host is up (0.17s latency).
Not shown: 65428 filtered tcp ports (no-response), 101 closed tcp ports (conn-refused)
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
80/tcp open http
8080/tcp open http-proxy
11211/tcp open memcache
27017/tcp open mongodFTP Rabbit Hole
ftp> ls
229 Entering Extended Passive Mode (|||40076|)
150 Here comes the directory listing.
drwxr-xr-x 2 ftp ftp 4096 Feb 01 2021 pub
ftp> ls
229 Entering Extended Passive Mode (|||40044|)
150 Here comes the directory listing.
-rw-r--r-- 1 ftp ftp 4603 Feb 01 2021 debug.pcap
Markdown Rabbit Hole

NodeBB -> Admin Takeover




Arbitrary File Write -> Root


Last updated