Infosec OSCP Prep Walkthrough
Introduction Today we're doing a boot2root walkthrough of the Infosec Prep: OSCP machine, created by FalconSpy, and hosted at https://www.vulnhub.com/entry/infosec-prep-oscp,508/ . For this pentest walkthrough, we'll be using two virtual machines, a Kali Linux machine as our attacking system, and the Infosec machine as the target system. Locating the Target The target system is very convenient, in that the IP address it is assigned by DHCP is displayed at the login screen. We can clearly see that our target is at 10.0.2.17 . Scanning and Enumeration We'll kick off our scans by figuring out which ports are open with nmap . Three TCP ports are open. We'll plug those into nmap again and get more details from the next scan. One finding stands out here: there's a blacklisted entry in the robots.txt file that points to secrets.txt . When we navigate to the target's website, first we see a bunch of information about the contest that was originally being run when ...