Posts

Showing posts with the label kioptrix

Kioptrix 1.0 (Level 1) Walkthrough

Image
Introduction Today we're going to do a boot2root pentest walkthrough of the Kioptrix 1.0 (Level 1) machine created by the Kioptrix team and hosted at https://www.vulnhub.com/entry/kioptrix-level-1-1,22/ . For this pentest we'll be using two virtual machines, a Kali Linux machine as our attacking system, and the Kioptrix 1.0 machine as our target system. Locating the Target After booting up both of our machines, the first thing we need to do is locate the target system on our network.  We can do that by running netdiscover with our attacking system. netdiscover -r 10.0.2.0/24 Our target system's IP address is 10.0.2.5 . Scanning and Enumeration We can determine open ports on the target with nmap . nmap -T4 -p- 10.0.2.5 There are a lot of open ports here. We'll plug these ports into another nmap scan to get more information about them. nmap -T4 -A -p22,80,111,139,443,32768 10.0.2.5 One notable finding here is that https running on the target on port 443. That's so...

Kioptrix 1.3 (Level 4) Walkthrough

Image
Introduction Today we're going to do a boot2root pentest walkthrough of the Kioptrix 1.3 (Level 4) machine created by the Kioptrix team and hosted at https://www.vulnhub.com/entry/kioptrix-level-13-4,25/ . For our pentest we'll be using two virtual machines, a Kali Linux machine as our attacking system, and the Kioptrix 1.3 machine as our target system. Locating the Target After booting up both of our machines, we need to locate the target system on our network. We do this by running netdiscover from our attacking system. netdiscover -r 10.0.2.0/24 The target is at 10.0.2.25 . Scanning and Enumeration Our scans start with nmap , determining open ports on the target system. nmap -T4 -p- 10.0.2.25 ; nmap -T4 -sU -F 10.0.2.25 There are five ports open. We'll plug these open ports into nmap again and see if we can get more information. nmap -T4 -A -p22,80,139,445 10.0.2.25 Not a lot of usable info here, but we'll continue scanning with dirb . dirb http:/...

Kioptrix 1.2 (Level 3) Walkthrough

Image
Introduction Today we're doing another pentest walkthrough in the Kioptrix series.  Kioptrix 1.2 (Level 3) was created by the Kioptrix team, and is hosted at  https://www.vulnhub.com/entry/kioptrix-level-12-3,24/  . For this pentest walkthrough we will be using two virtual machines, a Kali Linux machine as the attacking system, and the Kioptrix 1.2 machine as the target machine. Locating the Target After booting up both virtual machines, we run netdiscover from our attacking system to find out where the target system is on the network. It looks like our target is at 10.0.2.16 . Additional Configuration The documentation for Kioptrix 1.2 instructs us to edit our attacking system's hosts file after we identify the address of the target system. On Linux, we'll use gedit to edit the file, which is located at /etc/hosts/ on our Kali machine. We simply insert the IP address and kioptrix3.com.  Now where we browse "kioptrix3.com" in our web browser, we'll go dire...

Kioptrix 1.1 (Level 2) Walkthrough

Image
Introduction Today we're going to do a boot2root pentest walkthrough of Kioptrix 1.1 (Level 2).  We will be utilizing two virtual machines for this pentest: a Kali Linux VM which we will be using as the attacking machine, and the target machine, Kioptrix 1.1 (Level 2), created by Kioptrix, and hosted at https://www.vulnhub.com/entry/kioptrix-level-11-2,23/ . Discovering the Target The first thing we do after booting up both VMs is attempt to locate the target machine from the Kali machine with netdiscover . It looks like the machine at 10.0.2.13 is the one we're looking for. Scanning and Enumeration Next, we do a quick scan with Nmap to discover open ports on the target machine. We'l also do a quick UDP scan. From here, we can run a more in-depth Nmap scan on the ports we have identified as open.      We'll also run a Nikto scan against the target's web server, but it doesn't seem to reveal much. The next scan we perform is with Nessus : The result...