Hey guys!! We will see here how to break in for user and system flag in previse from HTB. Let’s jump in :) .

This box’s methodology is simple , we have a hidden directory from which we will pave our path inside and we will further escalate privileges.

Now let’s see the above process in the practical.

First step is to enumerate the target, so after running the nmap scans, we get the target to be particularly a web application having running services on port 80 and 22 as evident from the below snap of nmap results.

Set up your VPN & let’s dive in ;)

Now let’s run a quick nmap scan for the target machine.

I prefer to run 2 different scans simultaneoulsy which are:

nmap -sC -sV -T4 -p- <IP>

nmap -vv -script vuln -p- <IP>

I won’t go deep to explian but the first command performs the enumeration i.e. tells what services are running on target and which ports are active, while the second one goes to scan for the exploitable vulnerabilities from CVV’s , famous or old exploits like MS17–010 {Eternal Blue}, etc..

So after running these commands i got two outputs…

Rupesh Kumar

