HackTheBox Devel:writeup
嘖嘖嘖...試著用cherrytree寫writeup,超煩。 還是比較喜歡hackmd 這台的思路跟我去年打下第一台現實世界的伺服器是差不多的。 提權的部分學到新招:metasploit local exploit suggester! 雖然目前一直用metasploit打起來很爽,但之後考OSCP禁用。 HackTheBox Devel writeup - HackMD HackTheBox Devel writeup HackTheBox Devel writeup Port Scan ┌──(kali㉿kali)-[~/Devel] └─$ nmap 10.10.10.5 -T4 -A -o nmao.txt Starting Nmap 7.92 ( https://nmap.org ) at 2023-01-18 23:02 EST Nmap scan report for 10.10.10.5 Host is up (0.27s latency). Not shown: 998 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 21/tcp open ftp Microsoft ftpd | ftp-syst: |_ SYST: Windows_NT | ftp-anon: Anonymous FTP login allowed (FTP code 230) | 03-18-17 01:06AM <DIR> aspnet_client | 03-17-17 04:37PM 689 iisstart.htm |_03-17-17 04:37PM 184946 welcome.png 80/tcp open http ...