Posts

Showing posts with the label port forwarding

Hack the Box - Chatterbox - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Chatterbox machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Chatterbox machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.81.94 Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.81.94 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p9255,9256 10.129.81.94 There's only one service listed here, so let's see if there's any public exploit for it: searchsploit achat Let's take a look at this Python exploit: searchsploit -x 36025.py We've got a Python buffer overflow exploit, which requires us to supply a payload and the IP address of the target. To execute this, we'll need to: 1) Cop...

Hack the Box - Buff - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Buff machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Buff machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.70.66 Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.70.66   Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p8080 10.129.32.56 Let's check out the webservice on port 8080: http://10.129.70.66:8080/ Taking a quick look at the links on the buttons, it seems like this is a PHP -based website. An interesting piece of info on the contact page, though: http://10.129.70.66:8080/contact.php If this management software is really at version 1.0, that means there's probably an exploit out fo...