Skip to main content

Posts

Showing posts with the label hackthebox

METASPLOIT

Tʜᴇ Mᴇᴛᴀsᴘʟᴏɪᴛ Pʀᴏᴊᴇᴄᴛ ɪs ᴀ ᴄᴏᴍᴘᴜᴛᴇʀ sᴇᴄᴜʀɪᴛʏ ᴘʀᴏᴊᴇᴄᴛ ᴛʜᴀᴛ ᴘʀᴏᴠɪᴅᴇs ɪɴꜰᴏʀᴍᴀᴛɪᴏɴ ᴀʙᴏᴜᴛ sᴇᴄᴜʀɪᴛʏ ᴠᴜʟɴᴇʀᴀʙɪʟɪᴛɪᴇs ᴀɴᴅ ᴀɪᴅs ɪɴ ᴘᴇɴᴇᴛʀᴀᴛɪᴏɴ ᴛᴇsᴛɪɴɢ ᴀɴᴅ IDS sɪɢɴᴀᴛᴜʀᴇ ᴅᴇᴠᴇʟᴏᴘᴍᴇɴᴛ. Iᴛ ɪs ᴏᴡɴᴇᴅ ʙʏ Bᴏsᴛᴏɴ, Mᴀssᴀᴄʜᴜsᴇᴛᴛs-ʙᴀsᴇᴅ sᴇᴄᴜʀɪᴛʏ ᴄᴏᴍᴘᴀɴʏ Rᴀᴘɪᴅ7. Iᴛs ʙᴇsᴛ-ᴋɴᴏᴡɴ sᴜʙ-ᴘʀᴏᴊᴇᴄᴛ ɪs ᴛʜᴇ ᴏᴘᴇɴ-sᴏᴜʀᴄᴇ Mᴇᴛᴀsᴘʟᴏɪᴛ Fʀᴀᴍᴇᴡᴏʀᴋ, ᴀ ᴛᴏᴏʟ ꜰᴏʀ ᴅᴇᴠᴇʟᴏᴘɪɴɢ ᴀɴᴅ ᴇxᴇᴄᴜᴛɪɴɢ ᴇxᴘʟᴏɪᴛ ᴄᴏᴅᴇ ᴀɢᴀɪɴsᴛ ᴀ ʀᴇᴍᴏᴛᴇ ᴛᴀʀɢᴇᴛ ᴍᴀᴄʜɪɴᴇ. Oᴛʜᴇʀ ɪᴍᴘᴏʀᴛᴀɴᴛ sᴜʙ-ᴘʀᴏᴊᴇᴄᴛs ɪɴᴄʟᴜᴅᴇ ᴛʜᴇ Oᴘᴄᴏᴅᴇ Dᴀᴛᴀʙᴀsᴇ, sʜᴇʟʟᴄᴏᴅᴇ ᴀʀᴄʜɪᴠᴇ ᴀɴᴅ ʀᴇʟᴀᴛᴇᴅ ʀᴇsᴇᴀʀᴄʜ. Tʜᴇ Mᴇᴛᴀsᴘʟᴏɪᴛ Pʀᴏᴊᴇᴄᴛ ɪɴᴄʟᴜᴅᴇs ᴀɴᴛɪ-ꜰᴏʀᴇɴsɪᴄ ᴀɴᴅ ᴇᴠᴀsɪᴏɴ ᴛᴏᴏʟs, sᴏᴍᴇ ᴏꜰ ᴡʜɪᴄʜ ᴀʀᴇ ʙᴜɪʟᴛ ɪɴᴛᴏ ᴛʜᴇ Mᴇᴛᴀsᴘʟᴏɪᴛ Fʀᴀᴍᴇᴡᴏʀᴋ. Mᴇᴛᴀsᴘʟᴏɪᴛ ɪs ᴘʀᴇ-ɪɴsᴛᴀʟʟᴇᴅ ɪɴ ᴛʜᴇ Kᴀʟɪ Lɪɴᴜx ᴏᴘᴇʀᴀᴛɪɴɢ sʏsᴛᴇᴍ.  Tʜᴇ ʙᴀsɪᴄ sᴛᴇᴘs ꜰᴏʀ ᴇxᴘʟᴏɪᴛɪɴɢ ᴀ sʏsᴛᴇᴍ ᴜsɪɴɢ ᴛʜᴇ Fʀᴀᴍᴇᴡᴏʀᴋ ɪɴᴄʟᴜᴅᴇ:     Cʜᴏᴏsɪɴɢ ᴀɴᴅ ᴄᴏɴꜰɪɢᴜʀɪɴɢ ᴀɴ ᴇxᴘʟᴏɪᴛ (ᴄᴏᴅᴇ ᴛʜᴀᴛ ᴇɴᴛᴇʀs ᴀ ᴛᴀʀɢᴇᴛ sʏsᴛᴇᴍ ʙʏ ᴛᴀᴋɪɴɢ ᴀᴅᴠᴀɴᴛᴀɢᴇ ᴏꜰ ᴏɴᴇ ᴏꜰ ɪᴛs ʙᴜɢs; ᴀʙᴏᴜᴛ 900 ᴅɪꜰꜰᴇʀᴇɴᴛ ᴇxᴘʟᴏɪᴛs ꜰᴏʀ Wɪɴᴅᴏᴡs, Uɴɪx/Lɪɴᴜx ᴀɴᴅ Mᴀᴄ OS X sʏsᴛᴇᴍs ᴀʀᴇ ɪɴᴄʟᴜᴅᴇᴅ);     Oᴘᴛɪᴏɴᴀʟʟʏ ᴄʜᴇᴄᴋɪɴɢ ᴡʜᴇᴛʜᴇʀ ᴛʜᴇ ɪɴᴛᴇɴᴅᴇᴅ ᴛᴀʀɢᴇᴛ s

Hackthebox Luke Walkthrough

LUKE -10.10.10.137 Nmap scan result- nmap -sC -sV 10.10.10.137 Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-18 23:03 IST Nmap scan report for 10.10.10.137 Host is up (0.20s latency). Not shown: 995 closed ports PORT     STATE SERVICE VERSION 21/tcp   open  ftp     vsftpd 3.0.3+ (ext.1) 22/tcp   open  ssh? |_ssh-hostkey: ERROR: Script execution failed (use -d to debug) 80/tcp   open  http    Apache httpd 2.4.38 ((FreeBSD) PHP/7.3.3) |_http-server-header: Apache/2.4.38 (FreeBSD) PHP/7.3.3 3000/tcp open  http    Node.js Express framework 8000/tcp open  http    Ajenti http control panel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 221.94 seconds gobuster- 10.10.10.137- gobuster dir -u http://10.10.10.137 -w '/usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt' -x php =============================================================== Gobuster v3.0.1 by OJ Reeves (@TheColoni