Posts

Showing posts with the label lfi

Kioptrix 1.1 (Level 2) Walkthrough

Image
Introduction Today we're going to do a boot2root pentest walkthrough of Kioptrix 1.1 (Level 2).  We will be utilizing two virtual machines for this pentest: a Kali Linux VM which we will be using as the attacking machine, and the target machine, Kioptrix 1.1 (Level 2), created by Kioptrix, and hosted at https://www.vulnhub.com/entry/kioptrix-level-11-2,23/ . Discovering the Target The first thing we do after booting up both VMs is attempt to locate the target machine from the Kali machine with netdiscover . It looks like the machine at 10.0.2.13 is the one we're looking for. Scanning and Enumeration Next, we do a quick scan with Nmap to discover open ports on the target machine. We'l also do a quick UDP scan. From here, we can run a more in-depth Nmap scan on the ports we have identified as open.      We'll also run a Nikto scan against the target's web server, but it doesn't seem to reveal much. The next scan we perform is with Nessus : The result...