Hack the Box - Jerry - Walkthrough
Introduction Today we're going to be doing a pentest walkthrough of the Jerry machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Jerry machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.107.214 Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.107.214 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p8080 10.129.107.214 Only one port open, and the web-server on this host seems to be running Apache Tomcat on the default port. Let's take a look at the website in our web browser: http://10.129.107.214:8080 We have an Apache Tomcat version number. When we try to navigate to the manager page at /manager/html we're ask for Basic Auth credentials, so we attempt to brutefo...