VulnNet: Internal
Room Link: https://tryhackme.com/room/vulnnetinternal
Initial Scan
Kali
nmap -A $VICTIM

Scan all ports
Kali

TCP/139 - NetBIOS

TCP/445 - SMB
In SMB there is the first flag.
Kali

TCP/2049 - NFS
Kali

TCP/6379 - Redis

Kali

Kali

Kali

TCP/873 - RSYNC
We are able to transfer out key to allow us to login to as the sys-internal user.
Kali
TCP/22 - SSH
Kali
Victim

Kali


Add the token in the Authentication token. There was multiple listed, it was the last one
Victim







Kali
Custom script



Last updated