VulnNet: Internal

Room Link: https://tryhackme.com/room/vulnnetinternal

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/139 - NetBIOS

TCP/445 - SMB

In SMB there is the first flag.

Kali

TCP/2049 - NFS

Kali

TCP/6379 - Redis

Kali

Kali

Kali

TCP/873 - RSYNC

We are able to transfer out key to allow us to login to as the sys-internal user.

Kali

TCP/22 - SSH

Kali

Victim

Kali

Add the token in the Authentication token. There was multiple listed, it was the last one

Victim

Kali

Custom script

Last updated