Beep

# Nmap 7.93 scan initiated Wed Aug  9 05:15:48 2023 as: nmap -p25,22,111,80,143,110,443,879,993,995,3306,4190,4445,4559,5038,10000 -sV -sC -T4 -Pn -oN beep-nmap beep.htb
Nmap scan report for beep.htb (10.10.10.7)
Host is up (0.012s latency).

PORT      STATE SERVICE    VERSION
22/tcp    open  ssh        OpenSSH 4.3 (protocol 2.0)
| ssh-hostkey: 
|   1024 adee5abb6937fb27afb83072a0f96f53 (DSA)
|_  2048 bcc6735913a18a4b550750f6651d6d0d (RSA)
25/tcp    open  smtp       Postfix smtpd
|_smtp-commands: beep.localdomain, PIPELINING, SIZE 10240000, VRFY, ETRN, ENHANCEDSTATUSCODES, 8BITMIME, DSN
80/tcp    open  http       Apache httpd 2.2.3
|_http-title: Did not follow redirect to https://beep.htb/
|_http-server-header: Apache/2.2.3 (CentOS)
110/tcp   open  pop3       Cyrus pop3d 2.3.7-Invoca-RPM-2.3.7-7.el5_6.4
|_pop3-capabilities: STLS APOP TOP RESP-CODES PIPELINING UIDL AUTH-RESP-CODE USER IMPLEMENTATION(Cyrus POP3 server v2) LOGIN-DELAY(0) EXPIRE(NEVER)
111/tcp   open  rpcbind    2 (RPC #100000)
| rpcinfo: 
|   program version    port/proto  service
|   100000  2            111/tcp   rpcbind
|   100000  2            111/udp   rpcbind
|   100024  1            876/udp   status
|_  100024  1            879/tcp   status
143/tcp   open  imap       Cyrus imapd 2.3.7-Invoca-RPM-2.3.7-7.el5_6.4
|_imap-capabilities: ATOMIC IMAP4rev1 ID UIDPLUS NAMESPACE MAILBOX-REFERRALS OK MULTIAPPEND X-NETSCAPE LIST-SUBSCRIBED RIGHTS=kxte LITERAL+ NO IDLE CONDSTORE CATENATE IMAP4 ANNOTATEMORE SORT THREAD=ORDEREDSUBJECT SORT=MODSEQ RENAME THREAD=REFERENCES BINARY URLAUTHA0001 Completed STARTTLS QUOTA UNSELECT ACL LISTEXT CHILDREN
443/tcp   open  ssl/http   Apache httpd 2.2.3 ((CentOS))
| http-robots.txt: 1 disallowed entry 
|_/
|_http-title: Elastix - Login page
|_ssl-date: 2023-08-08T21:19:13+00:00; -3s from scanner time.
|_http-server-header: Apache/2.2.3 (CentOS)
| ssl-cert: Subject: commonName=localhost.localdomain/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
| Not valid before: 2017-04-07T08:22:08
|_Not valid after:  2018-04-07T08:22:08
879/tcp   open  status     1 (RPC #100024)
993/tcp   open  ssl/imap   Cyrus imapd
|_imap-capabilities: CAPABILITY
995/tcp   open  pop3       Cyrus pop3d
3306/tcp  open  mysql      MySQL (unauthorized)
4190/tcp  open  sieve      Cyrus timsieved 2.3.7-Invoca-RPM-2.3.7-7.el5_6.4 (included w/cyrus imap)
4445/tcp  open  upnotifyp?
4559/tcp  open  hylafax    HylaFAX 4.3.10
5038/tcp  open  asterisk   Asterisk Call Manager 1.1
10000/tcp open  http       MiniServ 1.570 (Webmin httpd)
|_http-title: Site doesn't have a title (text/html; Charset=iso-8859-1).
|_http-server-header: MiniServ/1.570
Service Info: Hosts:  beep.localdomain, 127.0.0.1, example.com, localhost; OS: Unix

Host script results:
|_clock-skew: -3s

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Wed Aug  9 05:22:20 2023 -- 1 IP address (1 host up) scanned in 391.20 seconds

From the nmap reesult , we have 3 web ports:

Searchsploit

Google

Foothold

amportal.conf

Extracted info :

SSH attempt blocked (Machine didn't configure ssh)

port 80 : admin : administrator Success (no foothold found) port 443 : same as port 80 port 10000 : root : jEhdIekWmdjE Success

Locate Command Shell under Others

Last updated