Hack the Box - Bastard - Walkthrough
Introduction Today we're going to be doing a pentest walkthrough of the Bastard machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Bastard machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.100.109. Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.100.109 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p80,135,49154 10.129.100.109 There's a web server on this target, so let's take a quick look before continuing: http://10.129.100.109 We see there's a Drupal CMS installed on this website. Drupal is notorious for its many vulnerabilities over the years. This helps us with directory busting, because we know to include php files when we run Gobuster : gobuster d...