Hack the Box - Beep - Walkthrough
Introduction Today we're going to be doing a pentest walkthrough of the Beep machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Beep machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.100.242. Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.100.242 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -T4 -p22,25,80,110,111,143,443,942,993,995,3306,4190,4445,4559,5038,10000 10.129.100.242 There's a lot of output here, but let's take a look at the HTTP service on port 10000: https://10.129.100.242:10000/ Interesting-looking web-app. Let's take a look at the source: view-source:https://10.129.100.242:10000/ The page references a CGI script. Let's check if the script is di...