Bank

Nmap

nmap -p22,53,80 -sV -sC -T4 -Pn -oN bank-nmap  bank.htb

Starting Nmap 7.93 ( https://nmap.org ) at 2023-08-12 03:56 +08
Nmap scan report for bank.htb (10.10.10.29)
Host is up (0.035s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.8 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   1024 08eed030d545e459db4d54a8dc5cef15 (DSA)
|   2048 b8e015482d0df0f17333b78164084a91 (RSA)
|   256 a04c94d17b6ea8fd07fe11eb88d51665 (ECDSA)
|_  256 2d794430c8bb5e8f07cf5b72efa16d67 (ED25519)
53/tcp open  domain  ISC BIND 9.9.5-3ubuntu0.14 (Ubuntu Linux)
| dns-nsid: 
|_  bind.version: 9.9.5-3ubuntu0.14-Ubuntu
80/tcp open  http    Apache httpd 2.4.7 ((Ubuntu))
| http-title: HTB Bank - Login
|_Requested resource was login.php
|_http-server-header: Apache/2.4.7 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Open ports

Check for DNS Zone transfer

Subdomain Found

Web Directory Fuzzing

Using medium dictionary

Directory Discovered

New subdomain fuzzing

Filter by file size

Curl the content

Obtained Credentials

support page (support.htb) have file upload function

Send request in burpsuite

Execute webshell

Put Reverse Shell (Remember to URL encode)

Find SUID files

Running /var/htb/bin/emergency return a # which indicate this is root shell

Last updated