Kioptrix 1.0 (Level 1) Walkthrough
Introduction Today we're going to do a boot2root pentest walkthrough of the Kioptrix 1.0 (Level 1) machine created by the Kioptrix team and hosted at https://www.vulnhub.com/entry/kioptrix-level-1-1,22/ . For this pentest we'll be using two virtual machines, a Kali Linux machine as our attacking system, and the Kioptrix 1.0 machine as our target system. Locating the Target After booting up both of our machines, the first thing we need to do is locate the target system on our network. We can do that by running netdiscover with our attacking system. netdiscover -r 10.0.2.0/24 Our target system's IP address is 10.0.2.5 . Scanning and Enumeration We can determine open ports on the target with nmap . nmap -T4 -p- 10.0.2.5 There are a lot of open ports here. We'll plug these ports into another nmap scan to get more information about them. nmap -T4 -A -p22,80,111,139,443,32768 10.0.2.5 One notable finding here is that https running on the target on port 443. That's so...