Bank
Nmap
nmap -p22,53,80 -sV -sC -T4 -Pn -oN bank-nmap bank.htb
Starting Nmap 7.93 ( https://nmap.org ) at 2023-08-12 03:56 +08
Nmap scan report for bank.htb (10.10.10.29)
Host is up (0.035s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.8 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 1024 08eed030d545e459db4d54a8dc5cef15 (DSA)
| 2048 b8e015482d0df0f17333b78164084a91 (RSA)
| 256 a04c94d17b6ea8fd07fe11eb88d51665 (ECDSA)
|_ 256 2d794430c8bb5e8f07cf5b72efa16d67 (ED25519)
53/tcp open domain ISC BIND 9.9.5-3ubuntu0.14 (Ubuntu Linux)
| dns-nsid:
|_ bind.version: 9.9.5-3ubuntu0.14-Ubuntu
80/tcp open http Apache httpd 2.4.7 ((Ubuntu))
| http-title: HTB Bank - Login
|_Requested resource was login.php
|_http-server-header: Apache/2.4.7 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Open ports
Check for DNS Zone transfer
Subdomain Found
Web Directory Fuzzing
Using medium dictionary
Directory Discovered
New subdomain fuzzing
Filter by file size
Curl the content
Obtained Credentials
support page (support.htb) have file upload function
Send request in burpsuite
Execute webshell
Put Reverse Shell (Remember to URL encode)
Find SUID files
Running /var/htb/bin/emergency return a # which indicate this is root shell
Last updated