eJPT Solution
eJPT Solution
Nmap Scan:
# Nmap 7.92 scan initiated Fri Nov 1 17:35:37 2024 as: nmap -p- -A -oN nmap_result.txt
192.168.100.0/24
TRACEROUTE
| fingerprint-strings:
| NULL:
| rdp-ntlm-info:
| Target_Name: WINSERVER-01
| NetBIOS_Domain_Name: WINSERVER-01
| NetBIOS_Computer_Name: WINSERVER-01
| DNS_Domain_Name: WINSERVER-01
| DNS_Computer_Name: WINSERVER-01
| Product_Version: 6.3.9600
|_ System_Time: 2024-11-01T12:07:55+00:00
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-server-header: Microsoft-HTTPAPI/2.0
SF-Port3307-TCP:V=7.92%I=7%D=11/1%Time=6724C44D%P=x86_64-pc-linux-gnu%r(NU
SF:LL,6D,"i\0\0\x01\xffj\x04Host\x20'ip-192-168-100-5\.eu-central-1\.compu
SF:te\.internal'\x20is\x20not\x20allowed\x20to\x20connect\x20to\x20this\x2
SF:0MariaDB\x20server");
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=11/1%OT=80%CT=1%CU=32862%PV=Y%DS=1%DC=D%G=Y%M=024CB2%T
OS:M=6724C4A3%P=x86_64-pc-linux-gnu)SEQ(SP=101%GCD=1%ISR=109%TI=I%CI=I%II=I
OS:%SS=S%TS=7)OPS(O1=M2301NW8ST11%O2=M2301NW8ST11%O3=M2301NW8NNT11%O4=M2301
OS:NW8ST11%O5=M2301NW8ST11%O6=M2301ST11)WIN(W1=2000%W2=2000%W3=2000%W4=2000
OS:%W5=2000%W6=2000)ECN(R=Y%DF=Y%T=80%W=2000%O=M2301NW8NNS%CC=Y%Q=)T1(R=Y%D
OS:F=Y%T=80%S=O%A=S+%F=AS%RD=0%Q=)T2(R=Y%DF=Y%T=80%W=0%S=Z%A=S%F=AR%O=%RD=0
OS:%Q=)T3(R=Y%DF=Y%T=80%W=0%S=Z%A=O%F=AR%O=%RD=0%Q=)T4(R=Y%DF=Y%T=80%W=0%S=
OS:A%A=O%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=
OS:Y%DF=Y%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=A
OS:R%O=%RD=0%Q=)U1(R=Y%DF=N%T=80%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%R
OS:UD=G)IE(R=Y%DFI=N%T=80%CD=Z)
Service Info: OSs: Windows, Windows Server 2008 R2 - 2012; CPE: cpe:/o:microsoft:windows
| smb2-time:
| date: 2024-11-01T12:07:56
|_ start_date: 2024-11-01T10:58:45
| smb-os-discovery:
| OS: Windows Server 2012 R2 Standard 9600 (Windows Server 2012 R2 Standard 6.3)
| OS CPE: cpe:/o:microsoft:windows_server_2012::-
| Workgroup: WORKGROUP\x00
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
| smb2-security-mode:
| 3.0.2:
|_nbstat: NetBIOS name: WINSERVER-01, NetBIOS user: <unknown>, NetBIOS MAC: 02:4c:b2:b9:e1:c5
(unknown)
TRACEROUTE
| ftp-syst:
|_ SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_http-server-header: Microsoft-IIS/8.5
| http-methods:
|_ Potentially risky methods: TRACE COPY PROPFIND DELETE MOVE PROPPATCH MKCOL LOCK UNLOCK
PUT
| http-webdav-scan:
| Public Options: OPTIONS, TRACE, GET, HEAD, POST, PROPFIND, PROPPATCH, MKCOL, PUT, DELETE,
COPY, MOVE, LOCK, UNLOCK
| Allowed Methods: OPTIONS, TRACE, GET, HEAD, POST, COPY, PROPFIND, DELETE, MOVE, PROPPATCH,
MKCOL, LOCK, UNLOCK
| Directory Listing:
| http://ip-192-168-100-51.eu-central-1.compute.internal/
| http://ip-192-168-100-51.eu-central-1.compute.internal/aspnet_client/
| http://ip-192-168-100-51.eu-central-1.compute.internal/cmdasp.aspx
| http://ip-192-168-100-51.eu-central-1.compute.internal/iis-85.png
| http://ip-192-168-100-51.eu-central-1.compute.internal/iisstart.htm
|_ http://ip-192-168-100-51.eu-central-1.compute.internal/robots.txt.txt
| rdp-ntlm-info:
| Target_Name: WINSERVER-02
| NetBIOS_Domain_Name: WINSERVER-02
| NetBIOS_Computer_Name: WINSERVER-02
| DNS_Domain_Name: WINSERVER-02
| DNS_Computer_Name: WINSERVER-02
| Product_Version: 6.3.9600
|_ System_Time: 2024-11-01T12:07:55+00:00
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-server-header: Microsoft-HTTPAPI/2.0
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=11/1%OT=21%CT=1%CU=41962%PV=Y%DS=1%DC=D%G=Y%M=021715%T
OS:M=6724C4A3%P=x86_64-pc-linux-gnu)SEQ(SP=105%GCD=1%ISR=10E%TI=I%CI=I%II=I
OS:%SS=S%TS=7)OPS(O1=M2301NW8ST11%O2=M2301NW8ST11%O3=M2301NW8NNT11%O4=M2301
OS:NW8ST11%O5=M2301NW8ST11%O6=M2301ST11)WIN(W1=2000%W2=2000%W3=2000%W4=2000
OS:%W5=2000%W6=2000)ECN(R=Y%DF=Y%T=80%W=2000%O=M2301NW8NNS%CC=Y%Q=)T1(R=Y%D
OS:F=Y%T=80%S=O%A=S+%F=AS%RD=0%Q=)T2(R=Y%DF=Y%T=80%W=0%S=Z%A=S%F=AR%O=%RD=0
OS:%Q=)T3(R=Y%DF=Y%T=80%W=0%S=Z%A=O%F=AR%O=%RD=0%Q=)T4(R=Y%DF=Y%T=80%W=0%S=
OS:A%A=O%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=
OS:Y%DF=Y%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=A
OS:R%O=%RD=0%Q=)U1(R=Y%DF=N%T=80%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%R
OS:UD=G)IE(R=Y%DFI=N%T=80%CD=Z)
Service Info: OSs: Windows, Windows Server 2008 R2 - 2012; CPE: cpe:/o:microsoft:windows
| smb2-time:
| date: 2024-11-01T12:07:56
|_ start_date: 2024-11-01T10:58:44
| smb2-security-mode:
| 3.0.2:
| smb-security-mode:
| authentication_level: user
| challenge_response: supported
|_nbstat: NetBIOS name: WINSERVER-02, NetBIOS user: <unknown>, NetBIOS MAC: 02:17:15:2b:e3:71
(unknown)
TRACEROUTE
| ftp-syst:
| STAT:
| Connected to ::ffff:192.168.100.5
| Logged in as ftp
| TYPE: ASCII
|_End of status
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|_http-title: Index of /
| http-ls: Volume /
|_
| mysql-info:
| Protocol: 10
| Version: 5.5.5-10.3.34-MariaDB-0ubuntu0.20.04.1
| Thread ID: 47
| Status: Autocommit
| Salt: vOc&/\aRU7OjF`/h?Co(
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=11/1%OT=21%CT=1%CU=35398%PV=Y%DS=1%DC=D%G=Y%M=024EEB%T
OS:M=6724C4A3%P=x86_64-pc-linux-gnu)SEQ(SP=105%GCD=1%ISR=10A%TI=Z%CI=Z%II=I
OS:%TS=A)OPS(O1=M2301ST11NW7%O2=M2301ST11NW7%O3=M2301NNT11NW7%O4=M2301ST11N
OS:W7%O5=M2301ST11NW7%O6=M2301ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F
OS:4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M2301NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T
OS:=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R
OS:%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=
OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0
OS:%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R
OS:=Y%DFI=N%T=40%CD=S)
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_nbstat: NetBIOS name: IP-192-168-100-, NetBIOS user: <unknown>, NetBIOS MAC: <unknown>
(unknown)
| smb2-security-mode:
| 3.1.1:
| smb2-time:
| date: 2024-11-01T12:07:55
|_ start_date: N/A
| smb-os-discovery:
| FQDN: ip-192-168-100-52.eu-central-1.compute.internal
TRACEROUTE
|_http-server-header: Microsoft-IIS/10.0
| http-methods:
| rdp-ntlm-info:
| Target_Name: WINSERVER-03
| NetBIOS_Domain_Name: WINSERVER-03
| NetBIOS_Computer_Name: WINSERVER-03
| DNS_Domain_Name: WINSERVER-03
| DNS_Computer_Name: WINSERVER-03
| Product_Version: 10.0.17763
|_ System_Time: 2024-11-01T12:17:58+00:00
| ssl-cert: Subject: commonName=WINSERVER-03
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-server-header: Microsoft-HTTPAPI/2.0
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=11/1%OT=80%CT=1%CU=32218%PV=Y%DS=1%DC=D%G=Y%M=02B5AD%T
OS:M=6724C6FB%P=x86_64-pc-linux-gnu)SEQ(SP=103%GCD=1%ISR=10B%TI=I%CI=I%II=I
OS:%SS=S%TS=U)OPS(O1=M2301NW8NNS%O2=M2301NW8NNS%O3=M2301NW8%O4=M2301NW8NN
S%
OS:O5=M2301NW8NNS%O6=M2301NNS)WIN(W1=FFFF%W2=FFFF%W3=FFFF%W4=FFFF%W5=FFFF%W
OS:6=FF70)ECN(R=Y%DF=Y%T=80%W=FFFF%O=M2301NW8NNS%CC=Y%Q=)T1(R=Y%DF=Y%T=80%S
OS:=O%A=S+%F=AS%RD=0%Q=)T2(R=Y%DF=Y%T=80%W=0%S=Z%A=S%F=AR%O=%RD=0%Q=)T3(R=Y
OS:%DF=Y%T=80%W=0%S=Z%A=O%F=AR%O=%RD=0%Q=)T4(R=Y%DF=Y%T=80%W=0%S=A%A=O%F=R%
OS:O=%RD=0%Q=)T5(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=8
OS:0%W=0%S=A%A=O%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%
OS:Q=)U1(R=Y%DF=N%T=80%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=
OS:Y%DFI=N%T=80%CD=Z)
Service Info: OSs: Windows, Windows Server 2008 R2 - 2012; CPE: cpe:/o:microsoft:windows
|_nbstat: NetBIOS name: WINSERVER-03, NetBIOS user: <unknown>, NetBIOS MAC: 02:b5:ad:75:25:79
(unknown)
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
| smb-os-discovery:
| OS: Windows Server 2019 Datacenter 17763 (Windows Server 2019 Datacenter 6.3)
| Workgroup: WORKGROUP\x00
| smb2-time:
| date: 2024-11-01T12:17:58
|_ start_date: N/A
| smb2-security-mode:
| 3.1.1:
| rdp-ntlm-info:
| Target_Name: EC2AMAZ-IK4QFED
| NetBIOS_Domain_Name: EC2AMAZ-IK4QFED
| NetBIOS_Computer_Name: EC2AMAZ-IK4QFED
| DNS_Domain_Name: EC2AMAZ-IK4QFED
| DNS_Computer_Name: EC2AMAZ-IK4QFED
| Product_Version: 10.0.14393
|_ System_Time: 2024-11-01T12:17:57+00:00
|_http-server-header: Microsoft-HTTPAPI/2.0
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS CPE: cpe:/o:freebsd:freebsd:6.2
Aggressive OS guesses: FreeBSD 6.2-RELEASE (85%)
TRACEROUTE
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=11/1%OT=22%CT=1%CU=36199%PV=Y%DS=1%DC=D%G=Y%M=02EAFF%T
OS:M=6724C6FB%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=2%ISR=10D%TI=Z%CI=Z%II=I
OS:%TS=A)OPS(O1=M2301ST11NW6%O2=M2301ST11NW6%O3=M2301NNT11NW6%O4=M2301ST11N
OS:W6%O5=M2301ST11NW6%O6=M2301ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F
OS:4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M2301NNSNW6%CC=Y%Q=)T1(R=Y%DF=Y%T
OS:=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R
OS:%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=
OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0
OS:%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R
OS:=Y%DFI=N%T=40%CD=S)
TRACEROUTE
| ssh-hostkey:
OS CPE: cpe:/o:linux:linux_kernel:2.6.32
| clock-skew:
| 0s:
| 192.168.100.51 (ip-192-168-100-51.eu-central-1.compute.internal)
|_ 192.168.100.63 (ip-192-168-100-63.eu-central-1.compute.internal)
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Fri Nov 1 17:48:17 2024 -- 256 IP addresses (8 hosts up) scanned in 760.38 seconds
SMB & SSH Brute force:
192.168.100.50
192.168.100.51
192.168.100.52
192.168.100.55
Answer Techniques:
WordPress – 192.168.100.50 :
Plugins installed on WordPress site (3)
http://192.168.100.52/drupal/profiles/minimal/
http://192.168.100.52/drupal/CHANGELOG.txt
Password: qwertyuiop
uname -r to check linux version
xfreerdp /u:root /p:hacker123 /v:192.168.100.52 ---- (Misconfiguration, any password will work)
WINSERVER-03 – 192.168.100.55 :
Exam Result: