Cap

Ports scan

Dir scan

Web exploitation

IDOR

On homepage if we click on Security Snapshot... we are redirected to: http://10.10.10.245/capturearrow-up-right

The redirection sends: http://10.10.10.245/data/5arrow-up-right

We can change data from /5 to /0

We get a 0.pcap file (packets)

If we follow the TCP stream of FTP packets, we get FTP username and password

User

Through FTP, we get access to user's home directory

SSH into the box to get user shell.

Root

As per the machine name, I search for linux capabilities and found the following article

_________heapbytes' still pwning

Last updated