Stapler Walkthrough
Introduction Today we're doing a boot2root pentest walkthrough of the Stapler machine, created by g0tmi1k and hosted at https://www.vulnhub.com/entry/stapler-1,150/ . For this pentest, I will be using two virtual machines. A Kali Linux machine as the attacking system, and the Stapler machine as the target system. Locating The Target Running nediscover from our attacking machine, we can locate where the target machine is on our network. netdiscover -r 10.0.2.0/24 Our target system is at 10.0.2.26 . Scanning and Enumeration We start our scans with nmap to determine which TCP ports are open on the target. nmap -T4 -p- 10.0.2.26 A good number of open ports on this system. We'll use nmap once more to specifically target these ports and get more information. nmap -T4 -A -p21,22,53,80,139,666,3306,12380 10.0.2.26 There's a lot of different services to enumerate here. Most notably, there seems to be a proxy http service running on port 12380. Let's continue o...