Cap

Ports scan

Dir scan

Web exploitation

IDOR

On homepage if we click on Security Snapshot... we are redirected to: http://10.10.10.245/capture

The redirection sends: http://10.10.10.245/data/5

We can change data from /5 to /0

We get a 0.pcap file (packets)

If we follow the TCP stream of FTP packets, we get FTP username and password

User

Through FTP, we get access to user's home directory

SSH into the box to get user shell.

Root

As per the machine name, I search for linux capabilities and found the following article

_________heapbytes' still pwning

Last updated